Practical Forensic Imaging: Securing Digital Evidence with Linux Tools (Paperback)
暫譯: 實用取證影像:使用Linux工具保護數位證據 (平裝本)
Bruce Nikkel
- 出版商: No Starch Press
- 出版日期: 2016-09-01
- 售價: $1,800
- 貴賓價: 9.5 折 $1,710
- 語言: 英文
- 頁數: 320
- 裝訂: Paperback
- ISBN: 1593277938
- ISBN-13: 9781593277932
-
相關分類:
Linux
立即出貨 (庫存 < 4)
買這商品的人也買了...
-
$1,767Threat Modeling: Designing for Security (Paperback)
-
$990Gray Hat Hacking The Ethical Hacker's Handbook, 4/e (Paperback)
-
$500$425 -
$449機器學習算法原理與編程實踐
-
$520$406 -
$403軟件保護及分析技術——原理與實踐
-
$380$323 -
$490$382 -
$490$382 -
$296Rootkit 隱遁攻擊技術及其防範
-
$352基於 Apache Kylin 構建大數據分析平臺
-
$505深入分析 GCC
-
$520$406 -
$500$390 -
$505內網安全攻防 : 滲透測試實戰指南
-
$580$493 -
$354$336 -
$1,008$958 -
$719$683 -
$602深入理解 Linux 網絡: 修煉底層內功,掌握高性能原理
-
$600$468 -
$620$489 -
$713$677 -
$600$474 -
$1,188$1,129
商品描述
Forensic image acquisition is an important part of postmortem incident response and evidence collection. Digital forensic investigators acquire, preserve, and manage digital evidence to support civil and criminal cases; examine organizational policy violations; resolve disputes; and analyze cyber attacks.
Practical Forensic Imaging takes a detailed look at how to secure and manage digital evidence using Linux-based command line tools. This essential guide walks you through the entire forensic acquisition process and covers a wide range of practical scenarios and situations related to the imaging of storage media.
You'll learn how to:
Perform forensic imaging of magnetic hard disks, SSDs and flash drives, optical discs, magnetic tapes, and legacy technologies
Protect attached evidence media from accidental modification
Manage large forensic image files, storage capacity, image format conversion, compression, splitting, duplication, secure transfer and storage, and secure disposal
Preserve and verify evidence integrity with cryptographic and piecewise hashing, public key signatures, and RFC-3161 timestamping
Work with newer drive and interface technologies like NVME, SATA Express, 4K-native sector drives, SSHDs, SAS, UASP/USB3x, and Thunderbolt
Manage drive security such as ATA passwords; encrypted thumb drives; Opal self-encrypting drives; OS-encrypted drives using BitLocker, FileVault, and TrueCrypt; and others
Acquire usable images from more complex or challenging situations such as RAID systems, virtual machine images, and damaged media
With its unique focus on digital forensic acquisition and evidence preservation, Practical Forensic Imaging is a valuable resource for experienced digital forensic investigators wanting to advance their Linux skills and experienced Linux administrators wanting to learn digital forensics. This is a must-have reference for every digital forensics lab.
商品描述(中文翻譯)
法醫影像擷取是事後事件回應和證據收集的重要部分。數位法醫調查員獲取、保存和管理數位證據,以支持民事和刑事案件;檢查組織政策違規;解決爭議;以及分析網路攻擊。
《實用法醫影像》詳細探討如何使用基於 Linux 的命令行工具來保護和管理數位證據。這本必備指南將引導您完成整個法醫擷取過程,並涵蓋與儲存媒體影像相關的各種實用情境和情況。
您將學習如何:
執行磁性硬碟、固態硬碟 (SSD) 和隨身碟、光碟、磁帶及舊技術的法醫影像擷取
保護附加的證據媒體免於意外修改
管理大型法醫影像檔案、儲存容量、影像格式轉換、壓縮、分割、複製、安全傳輸和儲存,以及安全處置
使用加密和分段雜湊、公開金鑰簽名和 RFC-3161 時間戳來保存和驗證證據的完整性
處理較新的驅動器和介面技術,如 NVME、SATA Express、4K 原生扇區驅動器、SSHD、SAS、UASP/USB3x 和 Thunderbolt
管理驅動器安全性,例如 ATA 密碼;加密隨身碟;Opal 自加密驅動器;使用 BitLocker、FileVault 和 TrueCrypt 的作業系統加密驅動器;以及其他
從更複雜或具挑戰性的情況中獲取可用影像,例如 RAID 系統、虛擬機影像和損壞媒體
《實用法醫影像》獨特地專注於數位法醫擷取和證據保存,是希望提升其 Linux 技能的經驗豐富的數位法醫調查員和希望學習數位法醫的經驗豐富的 Linux 管理員的寶貴資源。這是每個數位法醫實驗室必備的參考資料。