- Digital Forensics and Incident Response
- Gerard Johansen
- 187字
- 2021-07-02 18:49:42
The role of digital forensics
There is a misconception that is often held by people unfamiliar with the realm of incident response. This misconception is that incident response is merely a digital forensics issue. As a result, they will often conflate the two terms. While digital forensics is a critical component to incident response (and this is why we have included a number of chapters in this book to address digital forensics), there is more to addressing an incident than examining hard drives. It is best to think of forensics as a supporting function of the overall incident response process. For example, some incidents such as Denial of Service attacks will require little to no forensic work. On the other hand, a network intrusion involving the compromise of an internal server and Command and Control (C2) traffic leaving the network will require extensive examination of logs, traffic analysis, and examination of memory. From this analysis may be derived the root cause. In both cases, the impacted organization would be able to connect with the incident, but forensics played a much more important role in the latter case.
- Java逍遙游記
- 多媒體CAI課件設計與制作導論(第二版)
- Oracle 11g從入門到精通(第2版) (軟件開發視頻大講堂)
- 從0到1:HTML+CSS快速上手
- Magento 2 Development Cookbook
- INSTANT CakePHP Starter
- Java編程技術與項目實戰(第2版)
- Learning Unreal Engine Android Game Development
- PHP+Ajax+jQuery網站開發項目式教程
- Procedural Content Generation for C++ Game Development
- Managing Microsoft Hybrid Clouds
- Penetration Testing with the Bash shell
- iOS開發項目化入門教程
- Java程序設計實用教程(第2版)
- 軟件工程基礎