Fundamentals of Digital Forensics: Theory, Methods, and Real-Life Applications

Kävrestad, Joakim

  • 出版商: Springer
  • 出版日期: 2020-05-20
  • 售價: $2,100
  • 貴賓價: 9.5$1,995
  • 語言: 英文
  • 頁數: 268
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 3030389537
  • ISBN-13: 9783030389536
  • 相關分類: 資訊安全
  • 立即出貨 (庫存=1)

商品描述

This practical and accessible textbook/reference describes the theory and methodology of digital forensic examinations, presenting examples developed in collaboration with police authorities to ensure relevance to real-world practice. The coverage includes discussions on forensic artifacts and constraints, as well as forensic tools used for law enforcement and in the corporate sector. Emphasis is placed on reinforcing sound forensic thinking, and gaining experience in common tasks through hands-on exercises.

This enhanced second edition has been expanded with new material on incident response tasks and computer memory analysis.

 

Topics and features:

 

 

  • Outlines what computer forensics is, and what it can do, as well as what its limitations are
  • Discusses both the theoretical foundations and the fundamentals of forensic methodology
  • Reviews broad principles that are applicable worldwide
  • Explains how to find and interpret several important artifacts
  • Describes free and open source software tools, along with the AccessData Forensic Toolkit
  • Features exercises and review questions throughout, with solutions provided in the appendices
  • Includes numerous practical examples, and provides supporting video lectures online

 

 

This easy-to-follow primer is an essential resource for students of computer forensics, and will also serve as a valuable reference for practitioners seeking instruction on performing forensic examinations.

Joakim K vrestad is a lecturer and researcher at the University of Sk vde, Sweden, and an AccessData Certified Examiner. He also serves as a forensic consultant, with several years of experience as a forensic expert with the Swedish police.

 

商品描述(中文翻譯)

這本實用且易於理解的教科書/參考書描述了數位鑑識調查的理論和方法,並提供了與警察機構合作開發的實例,以確保與實際應用相關。內容包括對鑑識證據和限制的討論,以及在執法和企業界使用的鑑識工具。強調加強鑑識思維,並通過實際操作練習獲得常見任務的經驗。

這本增強版第二版增加了有關事件回應任務和計算機記憶體分析的新內容。

主題和特點:

- 概述了電腦鑑識的定義、功能以及其限制
- 討論了理論基礎和鑑識方法的基本原則
- 回顧了適用於全球的廣泛原則
- 解釋了如何找到並解讀幾個重要的證據
- 描述了免費和開源軟體工具,以及AccessData鑑識工具包
- 提供了練習和回顧問題,附錄中提供了解答
- 包含了許多實際例子,並提供在線支援的視頻講座

這本易於理解的入門書是電腦鑑識學生的必備資源,也是從事鑑識調查的從業人員尋求指導的寶貴參考資料。

Joakim K vrestad是瑞典斯科夫德大學的講師和研究員,也是AccessData認證鑑識師。他還擔任鑑識顧問,在瑞典警察機構擔任鑑識專家多年。

作者簡介

Joakim Kävrestad is a lecturer and researcher at the University of Skövde, Sweden, and an AccessData Certified Examiner. He also serves as a forensic consultant, with several years of experience as a forensic expert with the Swedish police.

作者簡介(中文翻譯)

Joakim Kävrestad是瑞典斯科夫德大學的講師和研究員,也是一位AccessData認證的鑑識師。他還擔任鑑識顧問,擁有多年在瑞典警察擔任鑑識專家的經驗。