Advances in Digital Forensics (eBook)
333 Seiten
Springer US (Verlag)
978-0-387-31163-0 (ISBN)
Digital forensics deals with the acquisition, preservation, examination, analysis and presentation of electronic evidence. Networked computing, wireless communications and portable electronic devices have expanded the role of digital forensics beyond traditional computer crime investigations. Practically every crime now involves some aspect of digital evidence; digital forensics provides the techniques and tools to articulate this evidence. Digital forensics also has myriad intelligence applications. Furthermore, it has a vital role in information assurance - investigations of security breaches yield valuable information that can be used to design more secure systems. "Advances in Digital Forensics" describes original research results and innovative applications in the emerging discipline of digital forensics.
In addition, it highlights some of the major technical and legal issues related to digital evidence and electronic crime investigations. The areas of coverage include: themes and issues in digital forensics, investigative techniques, network forensics, portable electronic device forensics, linux and file system forensics, and applications and techniques.
Digital forensics deals with the acquisition, preservation, examination, analysis and presentation of electronic evidence. Networked computing, wireless communications and portable electronic devices have expanded the role of digital forensics beyond traditional computer crime investigations. Practically every crime now involves some aspect of digital evidence; digital forensics provides the techniques and tools to articulate this evidence. Digital forensics also has myriad intelligence applications. Furthermore, it has a vital role in information assurance - investigations of security breaches yield valuable information that can be used to design more secure systems.Advances in Digital Forensics describes original research results and innovative applications in the emerging discipline of digital forensics. In addition, it highlights some of the major technical and legal issues related to digital evidence and electronic crime investigations. The areas of coverage include:Themes and Issues in Digital ForensicsInvestigative TechniquesNetwork ForensicsPortable Electronic Device ForensicsLinux and File System ForensicsApplications and TechniquesThis book is the first volume of a new series produced by the International Federation for Information Processing (IFIP) Working Group 11.9 on Digital Forensics, an international community of scientists, engineers and practitioners dedicated to advancing the state of the art of research and practice in digital forensics. The book contains a selection of twenty-five edited papers from the First Annual IFIP WG 11.9 Conference on Digital Forensics, held at the National Center for Forensic Science, Orlando, Florida, USA in February 2005.Advances in Digital Forensics is an important resource for researchers,faculty members and graduate students, as well as for practitioners and individuals engaged in research and development efforts for the law enforcement and intelligence communities.Mark Pollitt is President of Digital Evidence Professional Services, Inc., Ellicott City, Maryland, USA. Mr. Pollitt, who is retired from the Federal Bureau of Investigation (FBI), served as the Chief of the FBI's Computer Analysis Response Team, and Director of the Regional Computer Forensic Laboratory National Program.Sujeet Shenoi is the F.P. Walter Professor of Computer Science and a principal with the Center for Information Security at the University of Tulsa, Tulsa, Oklahoma, USA.For more information about the 300 other books in the IFIP series, please visit www.springeronline.com.For more information about IFIP, please visit www.ifip.org.
Contents 7
Contributing Authors 11
Preface 19
I THEMES AND ISSUES 22
Chapter 1 DEALING WITH TERABYTE DATA SETS IN DIGITAL INVESTIGATIONS 23
Chapter 2 FORENSICS AND PRIVACY-ENHANCING TECHNOLOGIES 37
Chapter 3 A NETWORK- BASED ARCHITECTURE FOR STORING DIGITAL EVIDENCE 53
Chapter 4 DIGITAL FORENSICS: MEETING THE CHALLENGES OF SCIENTIFIC EVIDENCE 63
II INVESTIGATIVE TECHNIQUES 85
Chapter 6 DETECTING SOCIAL ENGINEERING 87
Chapter 7 A FRAMEWORK FOR EMAIL INVESTIGATIONS 99
Chapter 8 THE MITNICK CASE: HOW BAYES COULD HAVE HELPED 111
Chapter 9 APPLYING FORENSIC PRINCIPLES TO COMPUTER-BASED ASSESSMENT 125
Chapter 10 EXPLORING FORENSIC DATA WITH SELF-ORGANIZING MAPS 133
III NETWORK FORENSICS 145
Chapter 11 INTEGRATING DIGITAL FORENSICS IN NETWORK INFRASTRUCTURES 147
Chapter 12 USING PEER-TO-PEER TECHNOLOGY FOR NETWORK FORENSICS 161
Chapter 13 FORENSIC PROFILING SYSTEM 173
Chapter 14 GLOBAL INTERNET ROUTING FORENSICS 185
Chapter 15 USING SIGNALING INFORMATION IN TELECOM NETWORK FORENSICS 197
IV PORTABLE ELECTRONIC DEVICE FORENSICS 210
Chapter 16 FORENSIC ANALYSIS OF MOBILE PHONE INTERNAL MEMORY 211
Chapter 17 IMAGING AND ANALYSIS OF GSM SIM CARDS 225
Chapter 18 EXTRACTING CONCEALED DATA FROM BIOS CHIPS 237
V LINUX AND FILE SYSTEM FORENSICS 252
Chapter 19 RECOVERING DIGITAL EVIDENCE FROM LINUX SYSTEMS 253
Chapter 20 DETECTING HIDDEN DATA IN EXT2/EXT3 FILE SYSTEMS 265
VI APPLICATIONS AND TECHNIQUES 278
Chapter 21 FORENSIC ANALYSIS OF DIGITAL IMAGE TAMPERING 279
Chapter 22 CONTENT- BASED IMAGE RETRIEVAL FOR DIGITAL FORENSICS 291
Chapter 23 MAKING DECISIONS ABOUT LEGAL RESPONSES TO CYBER ATTACKS 303
Chapter 24 APPLYING FILTER CLUSTERS TO REDUCE SEARCH STATE SPACE 315
Chapter 25 IN- KERNEL CRYPTOGRAPHIC EXECUTABLE VERIFICATION 323
More eBook at www.ciando.com 0
Erscheint lt. Verlag | 28.3.2006 |
---|---|
Sprache | englisch |
Themenwelt | Informatik ► Datenbanken ► Data Warehouse / Data Mining |
Informatik ► Netzwerke ► Sicherheit / Firewall | |
Informatik ► Theorie / Studium ► Algorithmen | |
Informatik ► Theorie / Studium ► Kryptologie | |
Informatik ► Weitere Themen ► Hardware | |
Naturwissenschaften | |
ISBN-10 | 0-387-31163-7 / 0387311637 |
ISBN-13 | 978-0-387-31163-0 / 9780387311630 |
Haben Sie eine Frage zum Produkt? |
Größe: 37,8 MB
DRM: Digitales Wasserzeichen
Dieses eBook enthält ein digitales Wasserzeichen und ist damit für Sie personalisiert. Bei einer missbräuchlichen Weitergabe des eBooks an Dritte ist eine Rückverfolgung an die Quelle möglich.
Dateiformat: PDF (Portable Document Format)
Mit einem festen Seitenlayout eignet sich die PDF besonders für Fachbücher mit Spalten, Tabellen und Abbildungen. Eine PDF kann auf fast allen Geräten angezeigt werden, ist aber für kleine Displays (Smartphone, eReader) nur eingeschränkt geeignet.
Systemvoraussetzungen:
PC/Mac: Mit einem PC oder Mac können Sie dieses eBook lesen. Sie benötigen dafür einen PDF-Viewer - z.B. den Adobe Reader oder Adobe Digital Editions.
eReader: Dieses eBook kann mit (fast) allen eBook-Readern gelesen werden. Mit dem amazon-Kindle ist es aber nicht kompatibel.
Smartphone/Tablet: Egal ob Apple oder Android, dieses eBook können Sie lesen. Sie benötigen dafür einen PDF-Viewer - z.B. die kostenlose Adobe Digital Editions-App.
Zusätzliches Feature: Online Lesen
Dieses eBook können Sie zusätzlich zum Download auch online im Webbrowser lesen.
Buying eBooks from abroad
For tax law reasons we can sell eBooks just within Germany and Switzerland. Regrettably we cannot fulfill eBook-orders from other countries.
Kopierschutz: Adobe-DRM
Adobe-DRM ist ein Kopierschutz, der das eBook vor Mißbrauch schützen soll. Dabei wird das eBook bereits beim Download auf Ihre persönliche Adobe-ID autorisiert. Lesen können Sie das eBook dann nur auf den Geräten, welche ebenfalls auf Ihre Adobe-ID registriert sind.
Details zum Adobe-DRM
Dateiformat: PDF (Portable Document Format)
Mit einem festen Seitenlayout eignet sich die PDF besonders für Fachbücher mit Spalten, Tabellen und Abbildungen. Eine PDF kann auf fast allen Geräten angezeigt werden, ist aber für kleine Displays (Smartphone, eReader) nur eingeschränkt geeignet.
Systemvoraussetzungen:
PC/Mac: Mit einem PC oder Mac können Sie dieses eBook lesen. Sie benötigen eine
eReader: Dieses eBook kann mit (fast) allen eBook-Readern gelesen werden. Mit dem amazon-Kindle ist es aber nicht kompatibel.
Smartphone/Tablet: Egal ob Apple oder Android, dieses eBook können Sie lesen. Sie benötigen eine
Geräteliste und zusätzliche Hinweise
Buying eBooks from abroad
For tax law reasons we can sell eBooks just within Germany and Switzerland. Regrettably we cannot fulfill eBook-orders from other countries.
aus dem Bereich