Brian Carrier File System Forensic Analysis

ISBN 13: 9780321268174

File System Forensic Analysis

4.29 avg rating
( 140 ratings by Goodreads )
 
9780321268174: File System Forensic Analysis

The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques

 

Most digital evidence is stored within the computer's file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed.

 

Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today's most valuable open source file system analysis tools—including tools he personally developed. Coverage includes

  • Preserving the digital crime scene and duplicating hard disks for "dead analysis"
  • Identifying hidden data on a disk's Host Protected Area (HPA)
  • Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more
  • Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques
  • Analyzing the contents of multiple disk volumes, such as RAID and disk spanning
  • Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques
  • Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more
  • Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools

When it comes to file system analysis, no other book offers this much detail or expertise. Whether you're a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use.

"synopsis" may belong to another edition of this title.

About the Author:

Brian Carrier has authored several leading computer forensic tools, including The Sleuth Kit (formerly The @stake Sleuth Kit) and the Autopsy Forensic Browser. He has authored several peer-reviewed conference and journal papers and has created publicly available testing images for forensic tools. Currently pursuing a Ph.D. in Computer Science and Digital Forensics at Purdue University, he is also a research assistant at the Center for Education and Research in Information Assurance and Security (CERIAS) there. He formerly served as a research scientist at @stake and as the lead for the @stake Response Team and Digital Forensic Labs. Carrier has taught forensics, incident response, and file systems at SANS, FIRST, the @stake Academy, and SEARCH.

Brian Carrier's http://www.digital-evidence.org contains book updates and up-to-date URLs from the book's references.


© Copyright Pearson Education. All rights reserved.

Excerpt. Reprinted by permission. All rights reserved.:

Foreword

Foreword

Computer forensics is a relatively new field, and over the years it has been called many things: "computer forensics," "digital forensics," and "media analysis" to name a few. It has only been in the past few years that we have begun to recognize that all of our digital devices leave digital breadcrumbs and that these breadcrumbs are valuable evidence in a wide range of inquiries. While criminal justice professionals were some of the first to take an interest in this digital evidence, the intelligence, information security, and civil law fields have enthusiastically adopted this new source of information.

Digital forensics has joined the mainstream. In 2003, the American Society of Crime Laboratory Directors–Laboratory Accreditation Board (ASCLD–LAB) recognized digital evidence as a full-fledged forensic discipline. Along with this acceptance came increased interest in training and education in this field. The Computer Forensic Educator's Working Group (now known as the Digital Forensic Working Group) was formed to assist educators in developing programs in this field. There are now over three-dozen colleges and universities that have, or are, developing programs in this field. More join their ranks each month.

I have had the pleasure of working with many law enforcement agencies, training organizations, colleges, and universities to develop digital forensic programs. One of first questions that I am asked is if I can recommend a good textbook for their course or courses. There have been many books written about this field. Most take a targeted approach to a particular investigative approach, such as incident response or criminal investigation. Some tend to be how-to manuals for specific tools. It has been hard to find a book that provides a solid technical and process foundation for the field...That is, until now.

This book is the foundational book for file system analysis. It is thorough, complete, and well organized. Brian Carrier has done what needed to be done for this field. This book provides a solid understanding of both the structures that make up different file systems and how these structures work. Carrier has written this book in such a way that the reader can use what they know about one file system to learn another. This book will be invaluable as a textbook and as a reference and needs to be on the shelf of every digital forensic practitioner and educator. It will also provide accessible reading for those who want to understand subjects such as data recovery.

When I was first approached about writing this Foreword, I was excited! I have know Brian Carrier for a number of years and I have always been impressed with his wonderful balance of incredible technical expertise and his ability to clearly explain not just what he knows but, more importantly, what you need to know. Brian's work on Autopsy and The Sleuth Kit (TSK) has demonstrated his command of this field—his name is a household name in the digital forensic community. I have been privileged to work with Brian in his current role at Purdue University, and he is helping to do for the academic community what he did for the commercial sector: He set a high standard.

So, it is without reservation that I recommend this book to you. It will provide you with a solid foundation in digital media.

Mark M. Pollitt
Former Director of the FBI's Regional Computer Forensic Laboratory Program


© Copyright Pearson Education. All rights reserved.

"About this title" may belong to another edition of this title.

Buy New View Book
List Price: US$ 84.99
US$ 32.58

Convert Currency

Shipping: FREE
From United Kingdom to U.S.A.

Destination, Rates & Speeds

Add to Basket

Top Search Results from the AbeBooks Marketplace

1.

Brian Carrier
Published by Pearson Education (US), United States (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Paperback Quantity Available: 1
Seller:
The Book Depository
(London, United Kingdom)
Rating
[?]

Book Description Pearson Education (US), United States, 2005. Paperback. Book Condition: New. Language: English . Brand New Book. The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques Most digital evidence is stored within the computer s file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed. Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today s most valuable open source file system analysis tools-including tools he personally developed. Coverage includes Preserving the digital crime scene and duplicating hard disks for dead analysis Identifying hidden data on a disk s Host Protected Area (HPA) Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques Analyzing the contents of multiple disk volumes, such as RAID and disk spanning Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools When it comes to file system analysis, no other book offers this much detail or expertise. Whether you re a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use. Bookseller Inventory # AAU9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 32.58
Convert Currency

Add to Basket

Shipping: FREE
From United Kingdom to U.S.A.
Destination, Rates & Speeds

2.

Carrier, Brian
Published by Pearson Education (US) (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Softcover First Edition Quantity Available: 5
Rating
[?]

Book Description Pearson Education (US), 2005. Book Condition: New. 2005. 1st Edition. Paperback. Begins with an overview of investigation and computer foundations. This book describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses open source file system analysis tools. It analyzes the contents of multiple disk volumes, such as RAID and disk spanning. Num Pages: 600 pages, illustrations. Category: (U) Tertiary Education (US: College). Dimension: 232 x 178 x 34. Weight in Grams: 920. . . . . . . Bookseller Inventory # V9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 37.45
Convert Currency

Add to Basket

Shipping: FREE
From Ireland to U.S.A.
Destination, Rates & Speeds

3.

Brian Carrier
Published by Pearson Education (US), United States (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Paperback Quantity Available: 1
Seller:
The Book Depository US
(London, United Kingdom)
Rating
[?]

Book Description Pearson Education (US), United States, 2005. Paperback. Book Condition: New. Language: English . Brand New Book. The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques Most digital evidence is stored within the computer s file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed. Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today s most valuable open source file system analysis tools-including tools he personally developed. Coverage includes Preserving the digital crime scene and duplicating hard disks for dead analysis Identifying hidden data on a disk s Host Protected Area (HPA) Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques Analyzing the contents of multiple disk volumes, such as RAID and disk spanning Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools When it comes to file system analysis, no other book offers this much detail or expertise. Whether you re a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use. Bookseller Inventory # AAU9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 37.48
Convert Currency

Add to Basket

Shipping: FREE
From United Kingdom to U.S.A.
Destination, Rates & Speeds

4.

Carrier, Brian
Published by Pearson Education (US)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Softcover Quantity Available: 5
Seller:
Kennys Bookstore
(Olney, MD, U.S.A.)
Rating
[?]

Book Description Pearson Education (US). Book Condition: New. 2005. 1st Edition. Paperback. Begins with an overview of investigation and computer foundations. This book describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses open source file system analysis tools. It analyzes the contents of multiple disk volumes, such as RAID and disk spanning. Num Pages: 600 pages, illustrations. Category: (U) Tertiary Education (US: College). Dimension: 232 x 178 x 34. Weight in Grams: 920. . . . . . Books ship from the US and Ireland. Bookseller Inventory # V9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 37.85
Convert Currency

Add to Basket

Shipping: FREE
Within U.S.A.
Destination, Rates & Speeds

5.

Brian Carrier
Published by Pearson Education (US)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Paperback Quantity Available: 5
Seller:
THE SAINT BOOKSTORE
(Southport, United Kingdom)
Rating
[?]

Book Description Pearson Education (US). Paperback. Book Condition: new. BRAND NEW, File System Forensic Analysis, Brian Carrier, The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques Most digital evidence is stored within the computer's file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed. Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today's most valuable open source file system analysis tools-including tools he personally developed. Coverage includes * Preserving the digital crime scene and duplicating hard disks for "dead analysis" * Identifying hidden data on a disk's Host Protected Area (HPA) * Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more * Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques * Analyzing the contents of multiple disk volumes, such as RAID and disk spanning * Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques * Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more * Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools When it comes to file system analysis, no other book offers this much detail or expertise. Whether you're a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use. Bookseller Inventory # B9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 29.10
Convert Currency

Add to Basket

Shipping: US$ 9.15
From United Kingdom to U.S.A.
Destination, Rates & Speeds

6.

Brian Carrier
Published by Addison Wesley (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Softcover Quantity Available: 5
Seller:
Ria Christie Collections
(Uxbridge, United Kingdom)
Rating
[?]

Book Description Addison Wesley, 2005. Book Condition: New. book. Bookseller Inventory # ria9780321268174_rkm

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 35.01
Convert Currency

Add to Basket

Shipping: US$ 5.10
From United Kingdom to U.S.A.
Destination, Rates & Speeds

7.

Brian Carrier
Published by Pearson Education 2005-04-07, Upper Saddle River, N.J. |London (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New paperback Quantity Available: 5
Seller:
Blackwell's
(Oxford, OX, United Kingdom)
Rating
[?]

Book Description Pearson Education 2005-04-07, Upper Saddle River, N.J. |London, 2005. paperback. Book Condition: New. Bookseller Inventory # 9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 32.59
Convert Currency

Add to Basket

Shipping: US$ 7.91
From United Kingdom to U.S.A.
Destination, Rates & Speeds

8.

Brian Carrier
Published by Addison Wesley (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Softcover Quantity Available: 2
Seller:
Rating
[?]

Book Description Addison Wesley, 2005. Book Condition: New. Bookseller Inventory # EH9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 38.73
Convert Currency

Add to Basket

Shipping: US$ 3.52
From Germany to U.S.A.
Destination, Rates & Speeds

9.

Brian Carrier
Published by Addison-Wesley (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Paperback Quantity Available: 2
Seller:
Revaluation Books
(Exeter, United Kingdom)
Rating
[?]

Book Description Addison-Wesley, 2005. Paperback. Book Condition: Brand New. 1st edition. 569 pages. 8.75x6.75x1.20 inches. In Stock. Bookseller Inventory # __0321268172

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 43.27
Convert Currency

Add to Basket

Shipping: US$ 7.91
From United Kingdom to U.S.A.
Destination, Rates & Speeds

10.

Carrier, Brian
ISBN 10: 0321268172 ISBN 13: 9780321268174
New Quantity Available: 4
Seller:
Paperbackshop-US
(Wood Dale, IL, U.S.A.)
Rating
[?]

Book Description 2005. PAP. Book Condition: New. New Book. Shipped from US within 10 to 14 business days. Established seller since 2000. Bookseller Inventory # KB-9780321268174

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 52.26
Convert Currency

Add to Basket

Shipping: US$ 3.99
Within U.S.A.
Destination, Rates & Speeds

There are more copies of this book

View all search results for this book