Brian Carrier File System Forensic Analysis

ISBN 13: 9780321268174

File System Forensic Analysis

Valutazione media 4,33
( su 129 valutazioni fornite da GoodReads )
 
9780321268174: File System Forensic Analysis

The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques Most digital evidence is stored within the computer's file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed. Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today's most valuable open source file system analysis tools-including tools he personally developed. Coverage includes * Preserving the digital crime scene and duplicating hard disks for "dead analysis" * Identifying hidden data on a disk's Host Protected Area (HPA) * Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more * Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques * Analyzing the contents of multiple disk volumes, such as RAID and disk spanning * Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques * Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more * Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools When it comes to file system analysis, no other book offers this much detail or expertise. Whether you're a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use.

Le informazioni nella sezione "Riassunto" possono far riferimento a edizioni diverse di questo titolo.

Sinossi:

This is an advanced cookbook and reference guide for digital forensic practitioners. File System Forensic Analysis focuses on the file system and disk. The file system of a computer is where most files are stored and where most evidence is found; it also the most technically challenging part of forensic analysis. This book offers an overview and detailed knowledge of the file system and disc layout. The overview will allow an investigator to more easily find evidence, recover deleted data, and validate his tools. The cookbook section will show how to use the many open source tools for analysis, many of which Brian Carrier has developed himself.

L'autore:

Brian Carrier has authored several leading computer forensic tools, including The Sleuth Kit (formerly The @stake Sleuth Kit) and the Autopsy Forensic Browser. He has authored several peer-reviewed conference and journal papers and has created publicly available testing images for forensic tools. Currently pursuing a Ph.D. in Computer Science and Digital Forensics at Purdue University, he is also a research assistant at the Center for Education and Research in Information Assurance and Security (CERIAS) there. He formerly served as a research scientist at @stake and as the lead for the @stake Response Team and Digital Forensic Labs. Carrier has taught forensics, incident response, and file systems at SANS, FIRST, the @stake Academy, and SEARCH.

Brian Carrier's http://www.digital-evidence.org contains book updates and up-to-date URLs from the book's references.


© Copyright Pearson Education. All rights reserved.

Le informazioni nella sezione "Su questo libro" possono far riferimento a edizioni diverse di questo titolo.

I migliori risultati di ricerca su AbeBooks

1.

Brian Carrier
Editore: Pearson Education (US), United States (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Paperback Quantità: 1
Da
The Book Depository
(London, Regno Unito)
Valutazione libreria
[?]

Descrizione libro Pearson Education (US), United States, 2005. Paperback. Condizione libro: New. 232 x 176 mm. Language: English . Brand New Book. The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques Most digital evidence is stored within the computer s file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed. Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today s most valuable open source file system analysis tools-including tools he personally developed. Coverage includes * Preserving the digital crime scene and duplicating hard disks for dead analysis * Identifying hidden data on a disk s Host Protected Area (HPA) * Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more * Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques * Analyzing the contents of multiple disk volumes, such as RAID and disk spanning * Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques * Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more * Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools When it comes to file system analysis, no other book offers this much detail or expertise. Whether you re a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use. Codice libro della libreria AAU9780321268174

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 30,00
Convertire valuta

Aggiungere al carrello

Spese di spedizione: GRATIS
Da: Regno Unito a: U.S.A.
Destinazione, tempi e costi

2.

Brian Carrier
Editore: Addison Wesley (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Brossura Quantità: 3
Da
Ria Christie Collections
(Uxbridge, Regno Unito)
Valutazione libreria
[?]

Descrizione libro Addison Wesley, 2005. Condizione libro: New. book. Codice libro della libreria ria9780321268174_rkm

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 27,68
Convertire valuta

Aggiungere al carrello

Spese di spedizione: EUR 3,90
Da: Regno Unito a: U.S.A.
Destinazione, tempi e costi

3.

Brian Carrier
Editore: Pearson Education (US), United States (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Paperback Quantità: 1
Da
The Book Depository US
(London, Regno Unito)
Valutazione libreria
[?]

Descrizione libro Pearson Education (US), United States, 2005. Paperback. Condizione libro: New. 232 x 176 mm. Language: English . Brand New Book. The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques Most digital evidence is stored within the computer s file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed. Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today s most valuable open source file system analysis tools-including tools he personally developed. Coverage includes * Preserving the digital crime scene and duplicating hard disks for dead analysis * Identifying hidden data on a disk s Host Protected Area (HPA) * Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more * Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques * Analyzing the contents of multiple disk volumes, such as RAID and disk spanning * Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques * Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more * Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools When it comes to file system analysis, no other book offers this much detail or expertise. Whether you re a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use. Codice libro della libreria AAU9780321268174

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 32,37
Convertire valuta

Aggiungere al carrello

Spese di spedizione: GRATIS
Da: Regno Unito a: U.S.A.
Destinazione, tempi e costi

4.

Carrier, Brian
Editore: Pearson Education (US) (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Brossura Prima edizione Quantità: 3
Valutazione libreria
[?]

Descrizione libro Pearson Education (US), 2005. Condizione libro: New. 2005. 1st Edition. Paperback. Begins with an overview of investigation and computer foundations. This book describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses open source file system analysis tools. It analyzes the contents of multiple disk volumes, such as RAID and disk spanning. Num Pages: 600 pages, illustrations. Category: (U) Tertiary Education (US: College). Dimension: 232 x 178 x 34. Weight in Grams: 920. . . . . . . Codice libro della libreria V9780321268174

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 32,75
Convertire valuta

Aggiungere al carrello

Spese di spedizione: GRATIS
Da: Irlanda a: U.S.A.
Destinazione, tempi e costi

5.

Brian Carrier
Editore: Pearson Education (US)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Paperback Quantità: 3
Da
THE SAINT BOOKSTORE
(Southport, Regno Unito)
Valutazione libreria
[?]

Descrizione libro Pearson Education (US). Paperback. Condizione libro: new. BRAND NEW, File System Forensic Analysis, Brian Carrier, The Definitive Guide to File System Analysis: Key Concepts and Hands-on Techniques Most digital evidence is stored within the computer's file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file system analysis is performed. Carrier begins with an overview of investigation and computer foundations and then gives an authoritative, comprehensive, and illustrated overview of contemporary volume and file systems: Crucial information for discovering hidden evidence, recovering deleted data, and validating your tools. Along the way, he describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses today's most valuable open source file system analysis tools-including tools he personally developed. Coverage includes * Preserving the digital crime scene and duplicating hard disks for "dead analysis" * Identifying hidden data on a disk's Host Protected Area (HPA) * Reading source data: Direct versus BIOS access, dead versus live acquisition, error handling, and more * Analyzing DOS, Apple, and GPT partitions; BSD disk labels; and Sun Volume Table of Contents using key concepts, data structures, and specific techniques * Analyzing the contents of multiple disk volumes, such as RAID and disk spanning * Analyzing FAT, NTFS, Ext2, Ext3, UFS1, and UFS2 file systems using key concepts, data structures, and specific techniques * Finding evidence: File metadata, recovery of deleted files, data hiding locations, and more * Using The Sleuth Kit (TSK), Autopsy Forensic Browser, and related open source tools When it comes to file system analysis, no other book offers this much detail or expertise. Whether you're a digital forensics specialist, incident response team member, law enforcement officer, corporate security specialist, or auditor, this book will become an indispensable resource for forensic investigations, no matter what analysis tools you use. Codice libro della libreria B9780321268174

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 25,90
Convertire valuta

Aggiungere al carrello

Spese di spedizione: EUR 6,97
Da: Regno Unito a: U.S.A.
Destinazione, tempi e costi

6.

Carrier, Brian
Editore: Pearson Education (US)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Brossura Quantità: 3
Da
Kennys Bookstore
(Olney, MD, U.S.A.)
Valutazione libreria
[?]

Descrizione libro Pearson Education (US). Condizione libro: New. 2005. 1st Edition. Paperback. Begins with an overview of investigation and computer foundations. This book describes data structures, analyzes example disk images, provides advanced investigation scenarios, and uses open source file system analysis tools. It analyzes the contents of multiple disk volumes, such as RAID and disk spanning. Num Pages: 600 pages, illustrations. Category: (U) Tertiary Education (US: College). Dimension: 232 x 178 x 34. Weight in Grams: 920. . . . . . Books ship from the US and Ireland. Codice libro della libreria V9780321268174

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 34,47
Convertire valuta

Aggiungere al carrello

Spese di spedizione: GRATIS
In U.S.A.
Destinazione, tempi e costi

7.

Brian Carrier
Editore: Pearson Education (US) 2005-03-17, New Jersey (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi paperback Quantità: 5
Da
Blackwell's
(Oxford, OX, Regno Unito)
Valutazione libreria
[?]

Descrizione libro Pearson Education (US) 2005-03-17, New Jersey, 2005. paperback. Condizione libro: New. Codice libro della libreria 9780321268174

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 29,24
Convertire valuta

Aggiungere al carrello

Spese di spedizione: EUR 5,28
Da: Regno Unito a: U.S.A.
Destinazione, tempi e costi

8.

Brian Carrier
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Quantità: 3
Da
BWB
(Valley Stream, NY, U.S.A.)
Valutazione libreria
[?]

Descrizione libro Condizione libro: New. Depending on your location, this item may ship from the US or UK. Codice libro della libreria 97803212681740000000

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 35,72
Convertire valuta

Aggiungere al carrello

Spese di spedizione: GRATIS
In U.S.A.
Destinazione, tempi e costi

9.

Carrier Brian
Editore: ADDISON WESLEY LONGMAN INC DIV PEARSON SUITE 300 (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Brossura Quantità: 1
Da
Valutazione libreria
[?]

Descrizione libro ADDISON WESLEY LONGMAN INC DIV PEARSON SUITE 300, 2005. Condizione libro: New. Codice libro della libreria EH9780321268174

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 32,30
Convertire valuta

Aggiungere al carrello

Spese di spedizione: EUR 5,55
Da: Germania a: U.S.A.
Destinazione, tempi e costi

10.

Brian Carrier
Editore: Addison-Wesley (2005)
ISBN 10: 0321268172 ISBN 13: 9780321268174
Nuovi Paperback Quantità: 2
Da
Revaluation Books
(Exeter, Regno Unito)
Valutazione libreria
[?]

Descrizione libro Addison-Wesley, 2005. Paperback. Condizione libro: Brand New. 1st edition. 569 pages. 8.75x6.75x1.20 inches. In Stock. Codice libro della libreria __0321268172

Maggiori informazioni su questa libreria | Fare una domanda alla libreria

Compra nuovo
EUR 38,51
Convertire valuta

Aggiungere al carrello

Spese di spedizione: EUR 7,05
Da: Regno Unito a: U.S.A.
Destinazione, tempi e costi

Vedi altre copie di questo libro

Vedi tutti i risultati per questo libro