UNIX and Linux Forensic Analysis DVD Toolkit
暫譯: UNIX 與 Linux 取證分析 DVD 工具包

Chris Pogue, Cory Altheide, Todd Haverkos

  • 出版商: Syngress Media
  • 出版日期: 2008-06-30
  • 售價: $2,560
  • 貴賓價: 9.5$2,432
  • 語言: 英文
  • 頁數: 248
  • 裝訂: Paperback
  • ISBN: 1597492698
  • ISBN-13: 9781597492690
  • 相關分類: Linux
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

相關主題

商品描述

This book addresses topics in the area of forensic analysis of systems running on variants of the UNIX operating system, which is the choice of hackers for their attack platforms. According to a 2007 IDC report, UNIX servers account for the second-largest segment of spending (behind Windows) in the worldwide server market with $4.2 billion in 2Q07, representing 31.7% of corporate server spending. UNIX systems have not been analyzed to any significant depth largely due to a lack of understanding on the part of the investigator, an understanding and knowledge base that has been achieved by the attacker. The companion DVD provides a simulated or "live" UNIX environment where readers can test the skills they've learned in the book and use custom tools developed by the authors.

The book begins with a chapter to describe why and how the book was written, and for whom, and then immediately begins addressing the issues of live response (volatile) data collection and analysis. The book continues by addressing issues of collecting and analyzing the contents of physical memory (i.e., RAM). The following chapters address /proc analysis, revealing the wealth of significant evidence, and analysis of files created by or on UNIX systems. Then the book addresses the underground world of UNIX hacking and reveals methods and techniques used by hackers, malware coders, and anti-forensic developers. The book then illustrates to the investigator how to analyze these files and extract the information they need to perform a comprehensive forensic analysis. The final chapter includes a detailed discussion of Loadable Kernel Modules and Malware. The companion DVD provides a simulated or "live" UNIX environment where readers can test the skills they've learned in the book and use custom tools developed by the authors.

Throughout the book the author provides a wealth of unique information, providing tools, techniques and information that won't be found anywhere else. Not only are the tools provided, but the author also provides sample files so that after completing a detailed walk-through, the reader can immediately practice the new-found skills.


* The companion DVD for the book contains significant, unique materials (movies, spreadsheet, code, etc.) not available any place else.
* This book contains information about UNIX forensic analysis that is not available anywhere else. Much of the information is a result of the author's own unique research and work.
* The authors have the combined experience of Law Enforcement, Military, and Corporate forensics. This unique perspective makes this book attractive to ALL forensic investigators.

商品描述(中文翻譯)

本書探討運行於各種 UNIX 作業系統變體上的系統的法醫分析主題,這是駭客選擇的攻擊平台。根據 2007 年 IDC 的報告,UNIX 伺服器在全球伺服器市場的支出中佔據第二大部分(僅次於 Windows),在 2007 年第二季的支出達到 42 億美元,佔企業伺服器支出的 31.7%。由於調查者缺乏理解,UNIX 系統尚未被深入分析,而這種理解和知識基礎正是攻擊者所擁有的。隨書附贈的 DVD 提供了一個模擬或「即時」的 UNIX 環境,讀者可以在其中測試他們在書中學到的技能,並使用作者開發的自訂工具。

本書以一章開始,描述為何以及如何撰寫本書,以及其目標讀者,然後立即開始探討即時響應(易失性)數據的收集和分析問題。本書接著討論收集和分析物理記憶體(即 RAM)內容的問題。隨後的章節探討 /proc 分析,揭示大量重要證據,以及對 UNIX 系統上創建的文件的分析。然後本書探討 UNIX 駭客的地下世界,揭示駭客、惡意程式編碼者和反法醫開發者所使用的方法和技術。本書接著向調查者展示如何分析這些文件並提取他們所需的信息,以進行全面的法醫分析。最後一章詳細討論可加載內核模組和惡意程式。隨書附贈的 DVD 提供了一個模擬或「即時」的 UNIX 環境,讀者可以在其中測試他們在書中學到的技能,並使用作者開發的自訂工具。

在整本書中,作者提供了大量獨特的信息,提供的工具、技術和信息在其他地方無法找到。不僅提供了工具,作者還提供了示例文件,以便在完成詳細的步驟後,讀者可以立即練習新學到的技能。

* 本書的隨附 DVD 包含其他地方無法獲得的重要獨特材料(影片、電子表格、代碼等)。
* 本書包含有關 UNIX 法醫分析的信息,這些信息在其他地方無法獲得。許多信息是作者自己獨特研究和工作的結果。
* 作者擁有執法、軍事和企業法醫的綜合經驗。這種獨特的視角使本書對所有法醫調查者都具有吸引力。

最後瀏覽商品 (1)