Sell Back Your Copy
For a $0.38 Gift Card
Trade in
Have one to sell? Sell yours here
Incident Response: Computer Forensics Toolkit
 
 
Tell the Publisher!
I'd like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Incident Response: Computer Forensics Toolkit [Paperback]

Douglas Schweitzer (Author)
4.3 out of 5 stars  See all reviews (9 customer reviews)


Available from these sellers.


Textbook Student FREE Two-Day Shipping for Students. Learn more

Formats

Amazon Price New from Used from
Paperback --  

Book Description

0764526367 978-0764526367 April 11, 2003
* Incident response and forensic investigation are the processes of detecting attacks and properly extracting evidence to report the crime and conduct audits to prevent future attacks
* This much-needed reference covers the methodologies for incident response and computer forensics, Federal Computer Crime law information and evidence requirements, legal issues, and working with law enforcement
* Details how to detect, collect, and eradicate breaches in e-mail and malicious code
* CD-ROM is packed with useful tools that help capture and protect forensic data; search volumes, drives, and servers for evidence; and rebuild systems quickly after evidence has been obtained


Editorial Reviews

From the Back Cover

Your in-depth guide to detecting network breaches, uncovering evidence, and preventing future attacks

Whether it’s from malicious code sent through an e-mail or an unauthorized user accessing company files, your network is vulnerable to attack. Your response to such incidents is critical. With this comprehensive guide, Douglas Schweitzer arms you with the tools to reveal a security breach, gather evidence to report the crime, and conduct audits to prevent future attacks. He also provides you with a firm understanding of the methodologies for incident response and computer forensics, Federal Computer Crime law information and evidence requirements, legal issues, and how to work with law enforcement.

You’ll learn how to:

  • Recognize the telltale signs of an incident and take specific response measures
  • Search for evidence by preparing operating systems, identifying network devices, and collecting data from memory
  • Analyze and detect when malicious code enters the system and quickly locate hidden files
  • Perform keyword searches, review browser history, and examine Web caches to retrieve and analyze clues
  • Create a forensics toolkit to prop-erly collect and preserve evidence
  • Contain an incident by severing network and Internet connections, and then eradicate any vulnerabilities you uncover
  • Anticipate future attacks and monitor your system accordingly
  • Prevent espionage, insider attacks, and inappropriate use of the network
  • Develop policies and procedures to carefully audit the system

CD-ROM includes:

  • Helpful tools to capture and protect forensic data; search volumes, drives, and servers for evidence; and rebuild systems quickly after evidence has been obtained
  • Valuable checklists developed by the author for all aspects of incident response and handling

About the Author

DOUGLAS SCHWEITZER is an Internet security specialist and authority on malicious code and computer forensics. He is a Cisco Certified Network Associate and Certified Internet Webmaster Associate, and holds A+, Network+, and i-Net+ certifications. Schweitzer is also the author of Internet Security Made Easy and Securing the Network from Malicious Code.

Product Details

  • Paperback: 360 pages
  • Publisher: Wiley (April 11, 2003)
  • Language: English
  • ISBN-10: 0764526367
  • ISBN-13: 978-0764526367
  • Product Dimensions: 9.1 x 7.4 x 0.9 inches
  • Shipping Weight: 1.2 pounds
  • Average Customer Review: 4.3 out of 5 stars  See all reviews (9 customer reviews)
  • Amazon Best Sellers Rank: #1,554,747 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

9 Reviews
5 star:
 (5)
4 star:
 (3)
3 star:    (0)
2 star:
 (1)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.3 out of 5 stars (9 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

10 of 11 people found the following review helpful:
4.0 out of 5 stars Readable and relevant - but US-centric, March 26, 2004
This review is from: Incident Response: Computer Forensics Toolkit (Paperback)
The introduction describes this book as a "complete introductory course in basic computer forensics and incident response" and that is indeed the case. It begins with an overview of computer forensics and incident response in Chapter 1 and progresses to legal considerations, obtaining and preserving digital evidence, system internals (mostly Windows although Unix is also discussed) and ends with analysis of real-world attacks and possible defences in Chapter 12. Press references and citations are used to give the big picture. All in all this is a book which I would recommend with two "buts": first, the author is writing from a US perspective for a US reader, presenting and discussing US-specific legislation and legal issues; while this would be of direct interest to our US-based brethren it is of no much use to anyone else. Second, platform-dependent coverage is mostly Windows, and although Linux/Unix get mentioned throughout the book the coverage of UNIX internals and forensics is not on par with Windows counterparts. Having said this, if you are in the US and are using Windows, do get this book - it is a readable and straight introduction to a complex and interesting field which becomes more and more important.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


8 of 9 people found the following review helpful:
2.0 out of 5 stars Fair introductory text, could be much better., January 24, 2004
By 
Tom Grozny (Ottawa, Ontario Canada) - See all my reviews
This review is from: Incident Response: Computer Forensics Toolkit (Paperback)
The author covers different aspects of incident response, but fails to go deeper in the matter.

The author talks briefly about types of attacks, briefly about forensics tools, and briefly about the incident response procedures. Such shallow coverage of the topics makes for a quite dissappointing read.

On the other hand he offers the readers complete text of USA Patriot Act 2001 - with little discussion of its implications, privacy concerns and its impact on the organizational security! Readers also get treated to full texts of Janet Renot(sp?) speeches - also with little explanation. Seems he tried to increase the word count of the book.

Forensics tools are mentioned with instructions to run them starting as "Step 1:Click the Start menu button". Every tool has a half a page description on how to start it with a screenshot taking up the rest of the page.

Forensics techniques are described, but the author presents this quite technical material in the abstract, easy-to-read form that takes away all the usefullness of it - reads like a summary.

Incident response chapters present the reader with the common sense material. Might be useful to get an idea of what is involved in developing a incident response process, but it's hard to find it practical - it's simply too general.

A fair introductory book, could be much better.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
5.0 out of 5 stars Excellent Book on the Subject of Computer Incident Response, July 15, 2003
By 
Tony Bradley (Internet / Network Security) - See all my reviews
This review is from: Incident Response: Computer Forensics Toolkit (Paperback)
Incident Response is a must-read book for anyone who has to handle computer security incidents. It is written in an easy-to-read format that even those new to the subject can follow, while providing enough depth and detail to be valuable as a reference book for experienced professionals. The appendix on the provisions of the USA PATRIOT Act and its impact on information security along with the CD containing many useful freeware and trialware software programs are worth the cost of the book in and of themselves. If you are in a position where you need to know how to respond when a computer incident occurs, or if you just want to learn more about this subject this book is a great place to start.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews







Only search this product's reviews



Inside This Book (learn more)
First Sentence:
THE HI-TECH REVOLUTION SWEEPING THE GLOBE in communications and information technology has truly made the world a smaller place. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
computer security incident response capability, cannot contain hearsay, incident response personnel, memory dump file, computer security personnel, computer forensic investigation, computer security incidents, malicious coders, file slack, federal interest computer, digital evidence, original hard drive, business records exception, wiretap statute, such subsection, centralized logging, null sessions, swap file, protected computer, wiretap order, planning coordinator, deleted data, file recovery, penetration testing, best evidence rule
Key Phrases - Capitalized Phrases (CAPs): (learn more)
United States, Recycle Bin, Fourth Amendment, Department of Justice, Control Panel, Windows Registry, Registry Editor, National Infrastructure Protection Center, System State, Patriot Act, Federal Rules of Evidence, Honeynet Project, Process Explorer, Supreme Court, Task Manager, Administrative Tools, Secret Service, Code Red, Folder Options, Local Policies, Shutdown Procedures, Click Start, Current Version, Event Viewer, Find Next
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:




What Other Items Do Customers Buy After Viewing This Item?


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...



Look for Similar Items by Category


Look for Similar Items by Subject