Forensic Examination of Windows-Supported File Systems
暫譯: Windows 支援檔案系統的取證檢查
Doug Elrick, Drew Elrick
- 出版商: CreateSpace Independ
- 出版日期: 2014-04-07
- 售價: $4,290
- 貴賓價: 9.5 折 $4,076
- 語言: 英文
- 頁數: 392
- 裝訂: Paperback
- ISBN: 1497358353
- ISBN-13: 9781497358355
海外代購書籍(需單獨結帳)
相關主題
商品描述
Understanding the underlying system of how files are stored, what happens when they are deleted, and how to potentially recover them is essential to the digital forensic examiner. Today’s computer forensic tools automate the process of file recovery, but understanding what those tools are accomplishing and knowing whether they are providing accurate results requires an understanding of the information provided in this text. The FAT and NTFS file systems are the most commonly utilized information storage methods and while there are many other methods available, concentrating on these two lays the foundation for learning the others in the future. A brief introduction of ExFAT is included, as it is a relatively new file system used with larger flash drives. Forensic Examination of Windows-Supported File Systems will provide the basis for this knowledge and the practical expertise to begin the journey of becoming a digital forensic scientist.
商品描述(中文翻譯)
了解檔案儲存的底層系統、檔案被刪除時發生的事情以及如何潛在地恢復檔案,對於數位鑑識檢查員來說是至關重要的。當今的電腦鑑識工具自動化了檔案恢復的過程,但理解這些工具所完成的工作以及知道它們是否提供準確的結果,需要對本書中提供的信息有一定的了解。FAT 和 NTFS 檔案系統是最常用的信息儲存方法,雖然還有許多其他可用的方法,但專注於這兩者為未來學習其他方法奠定了基礎。這裡還簡要介紹了 ExFAT,因為它是一種相對較新的檔案系統,通常用於較大的隨身碟。對於 Windows 支援的檔案系統的鑑識檢查將為這些知識提供基礎,並提供實踐專業知識,以開始成為數位鑑識科學家的旅程。