File System Forensics
暫譯: 檔案系統取證分析

Toolan, Fergus

  • 出版商: Wiley
  • 出版日期: 2025-02-26
  • 售價: $4,780
  • 貴賓價: 9.5$4,541
  • 語言: 英文
  • 頁數: 496
  • 裝訂: Hardcover - also called cloth, retail trade, or trade
  • ISBN: 1394289790
  • ISBN-13: 9781394289790
  • 海外代購書籍(需單獨結帳)

商品描述

Comprehensive forensic reference explaining how file systems function and how forensic tools might work on particular file systems

File System Forensics delivers comprehensive knowledge of how file systems function and, more importantly, how digital forensic tools might function in relation to specific file systems. It provides a step-by-step approach for file content and metadata recovery to allow the reader to manually recreate and validate results from file system forensic tools.

The book includes a supporting website that shares all of the data (i.e. sample file systems) used for demonstration in the text and provides teaching resources such as instructor guides, extra material, and more.

Written by a highly qualified associate professor and consultant in the field, File System Forensics includes information on:

  • Preliminary concepts for necessary studying file system forensics for anyone with basic computing experience but without specific knowledge on digital forensics and file systems
  • File systems specific to Windows, Linux, and macOS, with coverage of FAT, ExFAT, and NTFS
  • Advanced topics such as deleted file recovery, fragmented file recovery, searching for particular files, links, checkpoints, snapshots, and RAID
  • Issues facing file system forensics today and various issues that might evolve in the field in the coming years

File System Forensics is an essential, up-to-date reference on the subject for graduate and senior undergraduate students in digital forensics, as well as digital forensic analysts and other law enforcement professionals.

商品描述(中文翻譯)

全面的法醫參考資料,解釋檔案系統的運作方式以及法醫工具如何在特定檔案系統上運作

檔案系統法醫學 提供了檔案系統運作的全面知識,更重要的是,解釋了數位法醫工具如何與特定檔案系統相關聯。它提供了一個逐步的方法來恢復檔案內容和元數據,讓讀者能夠手動重建和驗證來自檔案系統法醫工具的結果。

本書包括一個支援網站,分享所有用於文本中示範的數據(即範例檔案系統),並提供教學資源,如教師指南、額外材料等。

本書由一位高資歷的副教授及該領域的顧問撰寫,檔案系統法醫學 包含以下資訊:


  • 對於任何具有基本計算經驗但對數位法醫學和檔案系統沒有特定知識的人,必要的檔案系統法醫學初步概念

  • 特定於 Windows、Linux 和 macOS 的檔案系統,涵蓋 FAT、ExFAT 和 NTFS

  • 進階主題,如已刪除檔案恢復、碎片檔案恢復、尋找特定檔案、連結、檢查點、快照和 RAID

  • 當前檔案系統法醫學面臨的問題以及未來幾年可能出現的各種問題

檔案系統法醫學 是數位法醫學研究生和高年級本科生,以及數位法醫分析師和其他執法專業人員的重要、最新參考資料。

作者簡介

Fergus Toolan, PhD, is an Associate Professor in the Norwegian Police University College. He has published over 30 peer-reviewed papers and supervised a number of master's and PhD students throughout his career. Additionally, Dr. Toolan has provided consultancy services to a number of police services and other governmental organizations. He has taught a range of courses from introductory programming to advanced databases, and from computer hardware to discrete mathematics.

作者簡介(中文翻譯)

是挪威警察大學院的副教授。他在職業生涯中發表了超過30篇經過同行評審的論文,並指導了多位碩士和博士生。此外,Toolan博士還為多個警察機構和其他政府組織提供諮詢服務。他教授的課程範圍從入門程式設計到高級資料庫,從計算機硬體到離散數學。