欢迎来到天天文库
浏览记录
ID:20496410
大小:1.66 MB
页数:53页
时间:2018-10-12
《computer forensics - the investigators persepective》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、ComputerForensics,TheInvestigatorsPersepectivePaulT.MobleySr.(pmobley@jawzinc.com)ComputerForensicsConsultantJawzInc.WhatisComputerForensics?ComputerForensicscanbedefinedsimply,asaprocessofapplyingscientificandanalyticaltechiniquestocomputerOperatingSystemsandFileStructuresindeterminingthepotenti
2、alforLegalEvidence.OverviewofPresentationWhyisEvidenceidentificationandPreservationrequired?WhobenefitsfromComputerForensics?GeneralTypesofForensicExaminationsrequested.ProcessofForensics.Toolsofthetrade.WhatistheExaminerlookingfor?WhyisEvidenceimportant?Inthelegalworld,EvidenceisEVERYTHING.Evidenc
3、eisusedtoestablishfacts.TheForensicExaminerisnotbiased.WhoneedsComputerForensics?TheVicitm!LawEnforcementInsuranceCarriersUltimatelytheLegalSystemWhoaretheVictims?PrivateBusinessGovernmentPrivateIndividualsIDtheperpetrator.IDthemethod/vulnerabilityofthenetworkthatallowedtheperpetratortogainaccessin
4、tothesystem.Conductadamageassessmentofthevictimizednetwork.PreservetheEvidenceforJudicialaction.ReasonsforaForensicAnalysisTypesofForensicRequestsIntrusionAnalysisDamageAssementSuspectExaminationToolAnalysisLogFileAnalysisEvidenceSearchIntrusionAnalysisWhogainedentry?Whatdidtheydo?Whendidthishappen
5、?Wheredidtheygo?Whythechosennetwork?Howdidtheydothis?DamageAssesmentWhatwasavailablefortheintrudertosee?Whatdidhetake?Whatdidheleavebehind?Wheredidhego?FileRecoveryDeletedFilesHiddenFilesSlackSpaceBadBlocksSteganographyX-DrivesNTFSStreamsNTFSStreamsTheForensicToolKit1.4fromNTOBJECTives,Inc.Copyrigh
6、t(c)1998NTOBJECTives,Inc.AllRightsReservedAFind-FileaccesstimefinderSFind-HiddendatastreamsfinderHFind-HiddenfilefinderToolAnalysisWhattoolswereused?Howweretheexecuted?Whatlanguageweretheywrittenin?FileComparisonwithSuspect’sFile.LogFileAnalysisEvents.WhatEventsaremonitored?Whatdotheeventrecordsrev
7、eal?Firewall/Router/Serverlogfiles?TripWireDatabase?Modem/FTP/Telnet/RASEvidenceSearchImageFilesSoftwareapplicationsDeletedFilesHiddenFilesEncryptedFilesHiddenpartitionsKeywordSearchKnownRemoteAccessToolsFo
此文档下载收益归作者所有