* Incident response and forensic investigation are the processes of detecting attacks and properly extracting evidence to report the crime and conduct audits to prevent future attacks * This much-needed reference covers the methodologies for incident response and computer forensics, Federal Computer Crime law information and evidence requirements, legal issues, and working with law enforcement * Details how to detect, collect, and eradicate breaches in e-mail and malicious code * CD-ROM is packed with useful tools that help capture and protect forensic data; search volumes, drives, and servers for evidence; and rebuild systems quickly after evidence has been obtained |
Average Customer Review:
( 9 customer reviews )
Write an online review and share your thoughts with other customers.
Most Helpful Customer Reviews
10 of 11 found the following review helpful:
Readable and relevant - but US-centricMar 26, 2004
By E. Danielyan The introduction describes this book as a "complete introductory course in basic computer forensics and incident response" and that is indeed the case. It begins with an overview of computer forensics and incident response in Chapter 1 and progresses to legal considerations, obtaining and preserving digital evidence, system internals (mostly Windows although Unix is also discussed) and ends with analysis of real-world attacks and possible defences in Chapter 12. Press references and citations are used to give the big picture. All in all this is a book which I would recommend with two "buts": first, the author is writing from a US perspective for a US reader, presenting and discussing US-specific legislation and legal issues; while this would be of direct interest to our US-based brethren it is of no much use to anyone else. Second, platform-dependent coverage is mostly Windows, and although Linux/Unix get mentioned throughout the book the coverage of UNIX internals and forensics is not on par with Windows counterparts. Having said this, if you are in the US and are using Windows, do get this book - it is a readable and straight introduction to a complex and interesting field which becomes more and more important.
8 of 9 found the following review helpful:
Fair introductory text, could be much better.Jan 24, 2004
By Tom Grozny The author covers different aspects of incident response, but fails to go deeper in the matter.The author talks briefly about types of attacks, briefly about forensics tools, and briefly about the incident response procedures. Such shallow coverage of the topics makes for a quite dissappointing read. On the other hand he offers the readers complete text of USA Patriot Act 2001 - with little discussion of its implications, privacy concerns and its impact on the organizational security! Readers also get treated to full texts of Janet Renot(sp?) speeches - also with little explanation. Seems he tried to increase the word count of the book. Forensics tools are mentioned with instructions to run them starting as "Step 1:Click the Start menu button". Every tool has a half a page description on how to start it with a screenshot taking up the rest of the page. Forensics techniques are described, but the author presents this quite technical material in the abstract, easy-to-read form that takes away all the usefullness of it - reads like a summary. Incident response chapters present the reader with the common sense material. Might be useful to get an idea of what is involved in developing a incident response process, but it's hard to find it practical - it's simply too general. A fair introductory book, could be much better.
4 of 4 found the following review helpful:
Excellent Book on the Subject of Computer Incident ResponseJul 15, 2003
By Tony Bradley Incident Response is a must-read book for anyone who has to handle computer security incidents. It is written in an easy-to-read format that even those new to the subject can follow, while providing enough depth and detail to be valuable as a reference book for experienced professionals. The appendix on the provisions of the USA PATRIOT Act and its impact on information security along with the CD containing many useful freeware and trialware software programs are worth the cost of the book in and of themselves. If you are in a position where you need to know how to respond when a computer incident occurs, or if you just want to learn more about this subject this book is a great place to start.
3 of 4 found the following review helpful:
Necessary, timely, and on the mark. A must have book.Jun 05, 2003
By Angel Gomez, Ph.D. Once again, author Douglas Schweitzer takes his candid no-nonsense approach to security issues. Intrusion is at an all time high and finding the right answers can be elusive. That is what gives significant value to this book. It is Concise and pertinent to the issue at hand.
3 of 4 found the following review helpful:
AWESOME WORK...ONCE AGAINMay 27, 2003
By hollie brostek Mr Schweitzer has hit the nail on the head once again! The subject matter is extremely timely and accurate. This book is a must have for any network administrator as well as a small business with stand alone PCs. You never know what your employees are doing with their computers. I found the book extremely helpful and easy to read. It provides the technical guidance without being too over technical. Also, the added free resources that are provided pay for the book.
See all 9 customer reviews on Amazon.com
|