Mastering Mobile Forensics
暫譯: 掌握行動取證技術
Soufiane Tahiri
- 出版商: Packt Publishing
- 出版日期: 2016-05-31
- 售價: $2,000
- 貴賓價: 9.5 折 $1,900
- 語言: 英文
- 頁數: 318
- 裝訂: Paperback
- ISBN: 1785287818
- ISBN-13: 9781785287817
海外代購書籍(需單獨結帳)
相關主題
商品描述
Key Features
- A mastering guide to help you overcome the roadblocks you face when dealing with mobile forensics
- Excel at the art of extracting data, recovering deleted data, bypassing screen locks, and much more
- Get best practices to how to collect and analyze mobile device data and accurately document your investigations
Book Description
Mobile forensics presents a real challenge to the forensic community due to the fast and unstoppable changes in technology. This book aims to provide the forensic community an in-depth insight into mobile forensic techniques when it comes to deal with recent smartphones operating systems
Starting with a brief overview of forensic strategies and investigation procedures, you will understand the concepts of file carving, GPS analysis, and string analyzing. You will also see the difference between encryption, encoding, and hashing methods and get to grips with the fundamentals of reverse code engineering. Next, the book will walk you through the iOS, Android and Windows Phone architectures and filesystem, followed by showing you various forensic approaches and data gathering techniques.
You will also explore advanced forensic techniques and find out how to deal with third-applications using case studies. The book will help you master data acquisition on Windows Phone 8. By the end of this book, you will be acquainted with best practices and the different models used in mobile forensics.
What you will learn
- Understand the mobile forensics process model and get guidelines on mobile device forensics
- Acquire in-depth knowledge about smartphone acquisition and acquisition methods
- Gain a solid understanding of the architecture of operating systems, file formats, and mobile phone internal memory
- Explore the topics of of mobile security, data leak, and evidence recovery
- Dive into advanced topics such as GPS analysis, file carving, encryption, encoding, unpacking, and decompiling mobile application processes
About the Author
Soufiane Tahiri is an independent computer security researcher and science enthusiast from Morocco, who specializes in .NET reverse code engineering and software security. He has an interest in low-level techniques and in recent years he has developed an interest in computer and smartphone forensics. He has been involved in IT security for more than 10 years and has dozen of publications and a lot of research in different computer security fields under his name.
Table of Contents
- Mobile Forensics and the Investigation Process Model
- Do It Yourself – Low-Level Techniques
- iDevices from a Forensic Point of View
- Android Forensics
- Windows Phone 8 Forensics
- Mobile Forensics – Best Practices
- Preparing a Mobile Forensic Workstation
商品描述(中文翻譯)
#### 主要特點
- 一本幫助您克服在移動取證過程中遇到的障礙的精通指南
- 精通數據提取、恢復已刪除數據、繞過屏幕鎖定等技術
- 獲得最佳實踐,了解如何收集和分析移動設備數據並準確記錄您的調查
#### 書籍描述
移動取證對於取證社群來說是一個真正的挑戰,因為技術的快速和不可阻擋的變化。本書旨在為取證社群提供深入的見解,幫助他們應對最新智能手機操作系統的移動取證技術。
本書從取證策略和調查程序的簡要概述開始,您將了解文件雕刻(file carving)、GPS 分析和字符串分析的概念。您還將看到加密、編碼和哈希方法之間的區別,並掌握逆向代碼工程的基本原理。接下來,本書將帶您了解 iOS、Android 和 Windows Phone 的架構及其檔案系統,並展示各種取證方法和數據收集技術。
您還將探索先進的取證技術,並通過案例研究了解如何處理第三方應用程序。本書將幫助您掌握 Windows Phone 8 的數據獲取。到本書結束時,您將熟悉移動取證中的最佳實踐和不同模型。
#### 您將學到什麼
- 理解移動取證過程模型並獲得移動設備取證的指導
- 獲得有關智能手機獲取和獲取方法的深入知識
- 鞏固對操作系統架構、檔案格式和手機內部記憶體的理解
- 探索移動安全、數據洩漏和證據恢復的主題
- 深入了解 GPS 分析、文件雕刻、加密、編碼、解包和反編譯移動應用程序過程等先進主題
#### 關於作者
**Soufiane Tahiri** 是來自摩洛哥的獨立計算機安全研究員和科學愛好者,專注於 .NET 逆向代碼工程和軟體安全。他對低層技術感興趣,近年來對計算機和智能手機取證產生了興趣。他在 IT 安全領域工作超過 10 年,擁有數十篇出版物和大量不同計算機安全領域的研究成果。
#### 目錄
1. 移動取證與調查過程模型
2. 自己動手 - 低層技術
3. 從取證的角度看 iDevices
4. Android 取證
5. Windows Phone 8 取證
6. 移動取證 - 最佳實踐
7. 準備移動取證工作站