SITE MENU

Home
Contact Us
Our Links
Reciprocal Links

BOOK SHELVES

Best Sellers
Biographies & Memoirs
Business & Investing
Children's Books
Comics
Computers & Internet
Cooking, Food & Wine
Health, Mind & Body
History
Home & Garden
Literature & Fiction
Mystery & Thrillers
Nonfiction
Reference
Religion & Spirituality
Romance
Science Fiction & Fantasy
Science & Technology
Sports
Star Trek
Travel

SEARCH
 
Find Books and eBooks:

Incident Response: Investigating Computer Crime - Digital

Buy Used/3rdParty

More product information

Find other editions
(Softback, Hardback, Audio, etc)

Incident Response: Investigating Computer Crime

List Price: $39.99    Our Price: $26.39

You Save: 34%

Digital -
McGraw-Hill

Availability: Available for download now

Author: Chris Prosise

More books by Chris Prosise

Features:

  • Download: Adobe Reader
Don't have the Adobe e-Book Reader? Click here to download it for free.

Some Similar Products:

                      


Customer Reviews

Ground-breaking, timely, engaging, authoritative

I am a senior engineer for network security operations. I am a graduate of the flagship session of the System Administration, Networking, and Security institute's Forensics, Investigations, and Response Education (SANS FIRE) program. "Incident Response" (IR) should have been the textbook for that program. It is the most definitive work I've read on incident response and computer forensics. I highly recommend every security professional take advantage of this book.

IR starts with a revealing case study, and follows through with additional mini-studies and "eye witness reports" based on the authors' experiences. It provides plenty of clear diagrams and charts to reinforce key points, like the innovative "hard drive layers" outlined in chapter five. Most every mention of a command line program is followed by an example of that command in action, either via screenshot or text sample. These examples let readers try similar commands on their own workstations, reinforcing the authors' investigative directions.

Beyond the excellent presentation of technical material, IR frames its discussion of incident response and computer forensics in a practical investigative methodology. My SANS FIRE training repeatedly stressed the importance of documentation, policies, processes, and methodology when performing forensic work worthy of adversarial legal scrutiny. IR's attention to detail helps investigators collect evidence in a professional, repeatable, forensically sound manner.

Having appeared in court to defend their investigations, the authors share their knowledge and emphasize crucial steps to avoid forensic pitfalls. (An example is a DOS boot floppy's interaction with the DRVSPACE.BIN file. IR explains how to avoid this issue in detail.) Falling victim to these pitfalls could give a defense attorney an easy way to clear his client, or at least make certain evidence questionable in court.

The book is not perfect. Several typos indicated somewhat rushed publication, but did not detract from technical accuracy. I would have liked more material in chapter five on file systems; perhaps another appendix would be useful?

Many books and papers describe incident response procedures for UNIX, but few dare to discuss Windows. Given the predominance of compromised Windows hosts, this book thankfully addresses the Windows response task in a complete and clear manner. In many cases UNIX and Windows are compared side-by-side, and commands for one OS are explained using equivalents for the other OS.

IR provides a durable blend of practical investigative techniques and technical insights. I predict that investigators will cite the procedures in this book as examples of "best practices" when they defend their actions in court. I plan to build my company's incident response capability around IR's recommendations.

(Disclaimer: I received my review copy free from Foundstone.)


Excellent guide to Incident Response

In a field where sound methodology and comprehensive knowledge is absolutely critical, this book is an excellent guide for anyone conducting incident response and computer crime investigations. It is suited for a diverse audience ranging from senior managers to network security interns. Individuals trying to enter this field often ask me where they should get started and what resources are available. I highly recommend Incident Response to anyone interested in the field of computer forensics and network security. I am confident that even the most seasoned computer forensic analysts will learn a few new tricks from this material. I am eagerly awaiting the second edition and hoping for even more advanced concepts.


Excellent basic reference

I read the book in about three days and found it to be a good primer for one leaning towards computer forensics. While some of the technology and tools described in the book will undoubtedly change within the next few months, a lot of the basic principles will remain pertinent for a long time to come. I heartily recommend this book for anyone with more than just a casual interest in Computer Security.


Related Areas: Computer Bks - Communications / Networking, Computers, Computers-Internet - Security, Computers-Security, Internet - Security, Security, True Crime-General
 

Amazon.Com prices and availability subject to change.