官术网_书友最值得收藏!

The role of digital forensics

There is a misconception that is often held by people unfamiliar with the realm of incident response. This misconception is that incident response is merely a digital forensics issue. As a result, they will often conflate the two terms. While digital forensics is a critical component to incident response (and this is why we have included a number of chapters in this book to address digital forensics), there is more to addressing an incident than examining hard drives. It is best to think of forensics as a supporting function of the overall incident response process. For example, some incidents such as Denial of Service attacks will require little to no forensic work. On the other hand, a network intrusion involving the compromise of an internal server and Command and Control (C2) traffic leaving the network will require extensive examination of logs, traffic analysis, and examination of memory. From this analysis may be derived the root cause. In both cases, the impacted organization would be able to connect with the incident, but forensics played a much more important role in the latter case.

主站蜘蛛池模板: 阿鲁科尔沁旗| 闻喜县| 沅陵县| 涟源市| 米泉市| 吴川市| 德令哈市| 海盐县| 海口市| 皮山县| 额敏县| 察哈| 临安市| 土默特右旗| 仙桃市| 新丰县| 巩义市| 浮山县| 保山市| 新兴县| 咸宁市| 长葛市| 兰考县| 平舆县| 常山县| 安平县| 庆阳市| 罗定市| 建平县| 正蓝旗| 徐水县| 昆明市| 桐城市| 木兰县| 香格里拉县| 望江县| 萨嘎县| 太谷县| 南川市| 富锦市| 津市市|