Investigating the Cyber Breach: The Digital Forensics Guide for the Network Engineer (Paperback)
暫譯: 調查網路安全漏洞:網路工程師的數位鑑識指南 (平裝本)

Joseph Muniz

相關主題

商品描述

Investigating the Cyber Breach

The Digital Forensics Guide for the Network Engineer

 

·         Understand the realities of cybercrime and today’s attacks

·         Build a digital forensics lab to test tools and methods, and gain expertise

·         Take the right actions as soon as you discover a breach

·         Determine the full scope of an investigation and the role you’ll play

·         Properly collect, document, and preserve evidence and data

·         Collect and analyze data from PCs, Macs, IoT devices, and other endpoints

·         Use packet logs, NetFlow, and scanning to build timelines, understand network activity, and collect evidence

·         Analyze iOS and Android devices, and understand encryption-related obstacles to investigation

·         Investigate and trace email, and identify fraud or abuse

·         Use social media to investigate individuals or online identities

·         Gather, extract, and analyze breach data with Cisco tools and techniques

·         Walk through common breaches and responses from start to finish

·         Choose the right tool for each task, and explore alternatives that might also be helpful

 

 

 

 

The professional’s go-to digital forensics resource for countering attacks right now

Today, cybersecurity and networking professionals know they can’t possibly prevent every breach, but they can substantially reduce risk by quickly identifying and blocking breaches as they occur. Investigating the Cyber Breach: The Digital Forensics Guide for the Network Engineer is the first comprehensive guide to doing just that.

 

Writing for working professionals, senior cybersecurity experts Joseph Muniz and Aamir Lakhani present up-to-the-minute techniques for hunting attackers, following their movements within networks, halting exfiltration of data and intellectual property, and collecting evidence for investigation and prosecution. You’ll learn how to make the most of today’s best open source and Cisco tools for cloning, data analytics, network and endpoint breach detection, case management, monitoring, analysis, and more.

 

Unlike digital forensics books focused primarily on post-attack evidence gathering, this one offers complete coverage of tracking threats, improving intelligence, rooting out dormant malware, and responding effectively to breaches underway right now.

 

 

This book is part of the Networking Technology: Security Series from Cisco Press®, which offers networking professionals valuable information for constructing efficient networks, understanding new technologies, and building successful careers.

 

 

商品描述(中文翻譯)

調查網路安全漏洞

網路工程師的數位鑑識指南

了解網路犯罪的現實及當今的攻擊

建立數位鑑識實驗室以測試工具和方法,並獲得專業知識

在發現漏洞後立即採取正確行動

確定調查的完整範圍及您將扮演的角色

正確收集、記錄和保存證據和數據

從PC、Mac、IoT設備及其他端點收集和分析數據

使用封包日誌、NetFlow和掃描來建立時間線、了解網路活動並收集證據

分析iOS和Android設備,並了解與調查相關的加密障礙

調查和追蹤電子郵件,識別詐騙或濫用行為

利用社交媒體調查個人或線上身份

使用Cisco工具和技術收集、提取和分析漏洞數據

從頭到尾走過常見的漏洞和應對措施

為每個任務選擇合適的工具,並探索可能有幫助的替代方案

專業人士應對攻擊的數位鑑識資源

今天,網路安全和網路專業人士知道他們不可能防止每一次漏洞,但他們可以通過快速識別和阻止漏洞來大幅降低風險。《調查網路安全漏洞:網路工程師的數位鑑識指南》是第一本全面指導如何做到這一點的指南。

針對在職專業人士撰寫的這本書,資深網路安全專家Joseph Muniz和Aamir Lakhani提供了最新的技術,用於追蹤攻擊者、跟蹤他們在網路中的行動、阻止數據和知識產權的外洩,以及收集調查和起訴的證據。您將學會如何充分利用當今最佳的開源和Cisco工具進行克隆、數據分析、網路和端點漏洞檢測、案件管理、監控、分析等。

與主要集中於攻擊後證據收集的數位鑑識書籍不同,這本書全面涵蓋了追蹤威脅、改善情報、根除潛伏的惡意軟體,以及有效應對當前正在進行的漏洞。

這本書是Cisco Press®的《網路技術:安全系列》的一部分,為網路專業人士提供有價值的信息,以構建高效的網路、理解新技術並建立成功的職業生涯。