L’édition demandée n’est plus disponible, nous vous proposons la dernière édition.
Linux Malware Incident Response: A Practitioner's Guide to Forensic Collection and Examination of Volatile Data An Excerpt from Malware Forensic Field Guide for Linux Systems
Auteurs : Casey Eoghan, Malin Cameron H., Aquilina James M.
Malware Incident Response: A Practitioner’s Guide to Volatile Data Collection and Examination on a Live Linux System
Appendix A: Linux Field Guide Tool Box
Appendix B: Selected Readings
Appendix C: Interview Questions
Appendix D: Pitfalls to Avoid
Appendix E: Live Response Field Notes
Eoghan Casey is an internationally recognized expert in data breach investigations and information security forensics. He is founding partner of CASEITE.com, and co-manages the Risk Prevention and Response business unit at DFLabs. Over the past decade, he has consulted with many attorneys, agencies, and police departments in the United States, South America, and Europe on a wide range of digital investigations, including fraud, violent crimes, identity theft, and on-line criminal activity. Eoghan has helped organizations investigate and manage security breaches, including network intrusions with international scope. He has delivered expert testimony in civil and criminal cases, and has submitted expert reports and prepared trial exhibits for computer forensic and cyber-crime cases.
In addition to his casework and writing the foundational book Digital Evidence and Computer Crime, Eoghan has worked as R&D Team Lead in the Defense Cyber Crime Institute (DCCI) at the Department of Defense Cyber Crime Center (DC3) helping enhance their operational capabilities and develop new techniques and tools. He also teaches graduate students at Johns Hopkins University Information Security Institute and created the Mobile Device Forensics course taught worldwide through the SANS Institute. He has delivered keynotes and taught workshops around the globe on various topics related to data breach investigation, digital forensics and cyber security.
Eoghan has performed thousands of forensic acquisitions and examinations, including Windows and UNIX systems, Enterprise servers, smart phones, cell phones, network logs, backup tapes, and database systems. He also has information security experience, as an Information Security Officer at Yale University and in subsequent consulting work. He has performed vulnerability assessments, deployed and maintained intrusion detection systems, firewalls and public key infrastructures, and developed policies, procedures, and educational
- Presented in a succinct outline format with cross-references to included supplemental components and appendices
- Covers volatile data collection methodology as well as non-volatile data collection from a live Linux system
- Addresses malware artifact discovery and extraction from a live Linux system
Date de parution : 03-2013
Ouvrage de 134 p.
15.2x22.8 cm