The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System, 2/e

Bill Blunden

  • 出版商: Jones and Bartlett
  • 出版日期: 2012-03-16
  • 售價: $4,640
  • 貴賓價: 9.5$4,408
  • 語言: 英文
  • 頁數: 784
  • 裝訂: Paperback
  • ISBN: 144962636X
  • ISBN-13: 9781449626365
  • 相關分類: 資訊安全駭客 Hack
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

商品描述

While forensic analysis has proven to be a valuable investigative tool in the field of computer security, utilizing anti-forensic technology makes it possible to maintain a covert operational foothold for extended periods, even in a high-security environment. Adopting an approach that favors full disclosure, the updated Second Edition of The Rootkit Arsenal presents the most accessible, timely, and complete coverage of forensic countermeasures. This book covers more topics, in greater depth, than any other currently available. In doing so the author forges through the murky back alleys of the Internet, shedding light on material that has traditionally been poorly documented, partially documented, or intentionally undocumented. The range of topics presented includes how to: -Evade post-mortem analysis -Frustrate attempts to reverse engineer your command & control modules -Defeat live incident response -Undermine the process of memory analysis -Modify subsystem internals to feed misinformation to the outside -Entrench your code in fortified regions of execution -Design and implement covert channels -Unearth new avenues of attack

商品描述(中文翻譯)

雖然法醫分析在電腦安全領域已被證明是一種有價值的調查工具,但利用反法醫技術可以在高安全環境中長時間保持隱蔽的操作立足點。更新的第二版《Rootkit Arsenal》採用了一種偏向全面披露的方法,提供了最易於理解、及時和完整的法醫對策。這本書涵蓋的主題比目前其他任何書籍都更廣泛、更深入。作者在互聯網的昏暗背街中前行,揭示了傳統上文獻記錄不足、部分記錄或故意未記錄的材料。所介紹的主題範圍包括如何:-逃避事後分析-阻礙反向工程您的命令和控制模塊-擊敗實時事件響應-破壞內存分析過程-修改子系統內部以向外部提供錯誤信息-在執行的堅固區域中鞏固您的代碼-設計和實施隱蔽通道-發現新的攻擊途徑