Hands-On Network Forensics
暫譯: 實作網路取證

Nipun Jaswa

  • 出版商: Packt Publishing
  • 出版日期: 2019-03-30
  • 售價: $1,840
  • 貴賓價: 9.5$1,748
  • 語言: 英文
  • 頁數: 358
  • 裝訂: Paperback
  • ISBN: 1789344522
  • ISBN-13: 9781789344523
  • 相關分類: Computer-networks
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

商品描述

Key Features

  • Investigate network threats with ease
  • Practice forensics tasks such as intrusion detection, network analysis, and scanning
  • Learn forensics investigation at the network level

Book Description

Network forensics is a subset of digital forensics that deals with network attacks and their investigation. In the era of network attacks and malware threat, it's now more important than ever to have skills to investigate network attacks and vulnerabilities.

Hands-On Network Forensics starts with the core concepts within network forensics, including coding, networking, forensics tools, and methodologies for forensic investigations. You'll then explore the tools used for network forensics, followed by understanding how to apply those tools to a PCAP file and write the accompanying report. In addition to this, you will understand how statistical flow analysis, network enumeration, tunneling and encryption, and malware detection can be used to investigate your network. Towards the end of this book, you will discover how network correlation works and how to bring all the information from different types of network devices together.

By the end of this book, you will have gained hands-on experience of performing forensics analysis tasks.

What you will learn

  • Discover and interpret encrypted traffic
  • Learn about various protocols
  • Understand the malware language over wire
  • Gain insights into the most widely used malware
  • Correlate data collected from attacks
  • Develop tools and custom scripts for network forensics automation

商品描述(中文翻譯)

#### 主要特點

- 輕鬆調查網路威脅
- 實踐取證任務,如入侵偵測、網路分析和掃描
- 學習網路層級的取證調查

#### 書籍描述

網路取證是數位取證的一個子集,專注於網路攻擊及其調查。在網路攻擊和惡意軟體威脅的時代,具備調查網路攻擊和漏洞的技能比以往任何時候都更為重要。

《實作網路取證》從網路取證的核心概念開始,包括編碼、網路、取證工具和取證調查的方法論。接著,您將探索用於網路取證的工具,然後了解如何將這些工具應用於 PCAP 檔案並撰寫相關報告。此外,您將了解如何使用統計流量分析、網路枚舉、隧道和加密以及惡意軟體檢測來調查您的網路。在本書的最後,您將發現網路關聯的運作方式,以及如何將來自不同類型網路設備的所有資訊整合在一起。

在本書結束時,您將獲得執行取證分析任務的實作經驗。

#### 您將學到的內容

- 發現並解讀加密流量
- 了解各種協議
- 理解網路上的惡意軟體語言
- 獲得對最廣泛使用的惡意軟體的見解
- 關聯從攻擊中收集的數據
- 開發工具和自訂腳本以自動化網路取證

作者簡介

Nipun Jaswal is an International Cyber Security Author and an award-winning IT security researcher with a decade of experience in penetration testing, vulnerability research, surveillance and monitoring solutions, and RF and wireless hacking. He is currently working as an Associate Partner in Lucideus where he is leading services such as red teaming and vulnerability research along with other enterprise customer services. He has authored Metasploit Bootcamp and Mastering Metasploit, and co-authored the Metasploit Revealed set of books. In addition to this, he has authored numerous articles and exploits that can be found on popular security databases, such as Packet Storm and Exploit-DB. Please feel free to contact him at @nipunjaswal.

作者簡介(中文翻譯)

Nipun Jaswal 是一位國際網路安全作家及獲獎的IT安全研究員,擁有十年的滲透測試、漏洞研究、監控解決方案以及射頻和無線駭客的經驗。他目前在Lucideus擔任副合夥人,負責紅隊測試和漏洞研究等服務,以及其他企業客戶服務。他是《Metasploit Bootcamp》和《Mastering Metasploit》的作者,並共同撰寫了《Metasploit Revealed》系列書籍。此外,他還撰寫了許多文章和漏洞,這些內容可以在知名的安全數據庫中找到,如Packet Storm和Exploit-DB。如有需要,請隨時通過 @nipunjaswal 聯繫他。

目錄大綱

  1. Introduction to Network Forensics
  2. Technical Concepts and Acquiring Evidence
  3. Deep Packet Inspection
  4. Statistical flow analysis
  5. Combating Tunneling and Encryption
  6. Investigating Good, Known and the Ugly Malware
  7. Investigating C2 Servers
  8. Investigating and Analyzing Logs
  9. WLAN Forensics
  10. Evidence Segregation

目錄大綱(中文翻譯)


  1. Introduction to Network Forensics

  2. Technical Concepts and Acquiring Evidence

  3. Deep Packet Inspection

  4. Statistical flow analysis

  5. Combating Tunneling and Encryption

  6. Investigating Good, Known and the Ugly Malware

  7. Investigating C2 Servers

  8. Investigating and Analyzing Logs

  9. WLAN Forensics

  10. Evidence Segregation

最後瀏覽商品 (1)