Practical Forensic Imaging: Securing Digital Evidence with Linux Tools (Paperback)

Bruce Nikkel

  • 出版商: No Starch Press
  • 出版日期: 2016-09-01
  • 定價: $1,800
  • 售價: 9.0$1,620
  • 語言: 英文
  • 頁數: 320
  • 裝訂: Paperback
  • ISBN: 1593277938
  • ISBN-13: 9781593277932
  • 相關分類: Linux
  • 立即出貨

買這商品的人也買了...

商品描述

Forensic image acquisition is an important part of postmortem incident response and evidence collection. Digital forensic investigators acquire, preserve, and manage digital evidence to support civil and criminal cases; examine organizational policy violations; resolve disputes; and analyze cyber attacks.

Practical Forensic Imaging takes a detailed look at how to secure and manage digital evidence using Linux-based command line tools. This essential guide walks you through the entire forensic acquisition process and covers a wide range of practical scenarios and situations related to the imaging of storage media.

You'll learn how to:

Perform forensic imaging of magnetic hard disks, SSDs and flash drives, optical discs, magnetic tapes, and legacy technologies
Protect attached evidence media from accidental modification
Manage large forensic image files, storage capacity, image format conversion, compression, splitting, duplication, secure transfer and storage, and secure disposal
Preserve and verify evidence integrity with cryptographic and piecewise hashing, public key signatures, and RFC-3161 timestamping
Work with newer drive and interface technologies like NVME, SATA Express, 4K-native sector drives, SSHDs, SAS, UASP/USB3x, and Thunderbolt
Manage drive security such as ATA passwords; encrypted thumb drives; Opal self-encrypting drives; OS-encrypted drives using BitLocker, FileVault, and TrueCrypt; and others
Acquire usable images from more complex or challenging situations such as RAID systems, virtual machine images, and damaged media
With its unique focus on digital forensic acquisition and evidence preservation, Practical Forensic Imaging is a valuable resource for experienced digital forensic investigators wanting to advance their Linux skills and experienced Linux administrators wanting to learn digital forensics. This is a must-have reference for every digital forensics lab.

商品描述(中文翻譯)

法醫影像取證是事後事件回應和證據收集的重要部分。數位法醫調查人員獲取、保存和管理數位證據,以支持民事和刑事案件;檢查組織政策違規;解決爭議;並分析網絡攻擊。

《實用法醫影像》詳細介紹了如何使用基於Linux的命令行工具來保護和管理數位證據。這本必備指南將引導您完成整個法醫取證過程,並涵蓋與存儲媒體影像相關的各種實際情境和情況。

您將學習如何:
- 進行磁性硬盤、固態硬盤和閃存驅動器、光盤、磁帶和遺留技術的法醫影像
- 保護附加的證據媒體免受意外修改
- 管理大型法醫影像文件、存儲容量、影像格式轉換、壓縮、分割、複製、安全傳輸和存儲,以及安全處置
- 通過加密和分段哈希、公鑰簽名和RFC-3161時間戳來保護和驗證證據完整性
- 處理新的驅動器和接口技術,如NVME、SATA Express、4K本地扇區驅動器、SSHD、SAS、UASP/USB3x和Thunderbolt
- 管理驅動器安全,如ATA密碼;加密的隨身碟;Opal自加密驅動器;使用BitLocker、FileVault和TrueCrypt的操作系統加密驅動器;以及其他情況
- 從更複雜或具有挑戰性的情況中獲取可用的影像,如RAID系統、虛擬機影像和損壞的媒體

《實用法醫影像》以其獨特的重點在數位法醫取證和證據保存方面,是有經驗的數位法醫調查人員提升Linux技能和有經驗的Linux管理員學習數位法醫的寶貴資源。這是每個數位法醫實驗室必備的參考書。