Cisco Router and Switch Forensics: Investigating and Analyzing Malicious Network Activity

(häftad)

av Dale Liu

Bloggar      
Format:
Häftad (paperback)
Utgiven:
2009-06-08
Språk:
Engelska
Cisco IOS (the software that runs the vast majority of Cisco routers and all Cisco network switches) is the dominant routing platform on the Internet and corporate networks. This widespread distribution, as well as its architectural deficiencies, makes it a valuable target for hackers looking to attack a corporate or private network infrastructure. Compromised devices can disrupt stability, introduce malicious modification, and endanger all communication on the network. For security of the network and investigation of attacks, in-depth analysis and diagnostics are critical, but no book currently covers forensic analysis of Cisco network devices in any detail.

Cisco Router and Switch Forensics is the first book devoted to criminal attacks, incident response, data collection, and legal testimony on the market leader in network devices, including routers, switches, and wireless access points.

Why is this focus on network devices necessary? Because criminals are targeting networks, and network devices require a fundamentally different approach than the process taken with traditional forensics. By hacking a router, an attacker can bypass a network's firewalls, issue a denial of service (DoS) attack to disable the network, monitor and record all outgoing and incoming traffic, or redirect that communication anywhere they like. But capturing this criminal activity cannot be accomplished with the tools and techniques of traditional forensics. While forensic analysis of computers or other traditional media typically involves immediate shut-down of the target machine, creation of a duplicate, and analysis of static data, this process rarely recovers live system data. So, when an investigation focuses on live network activity, this traditional approach obviously fails. Investigators must recover data as it is transferred via the router or switch, because it is destroyed when the network device is powered down. In this case, following the traditional approach outlined in books on general computer forensics techniques is not only insufficient, but also essentially harmful to an investigation.

Jargon buster: A network switch is a small hardware device that joins multiple computers together within one local area network (LAN). A router is a more sophisticated network device that joins multiple wired or wireless networks together.

* The only book devoted to forensic analysis of routers and switches, focusing on the operating system that runs the vast majority of network devices in the enterprise and on the Internet
* Outlines the fundamental differences between router forensics and traditional forensics, a critical distinction for responders in an investigation targeting network activity
* Details where network forensics fits within the entire process of an investigation, end to end, from incident response and data collection to preparing a report and legal testimony

Fler böcker av Dale Liu

Cisco CCNA/CCENT Exam 640-802, 640-822, 640-816 Preparation Kit Book/CD Package (häftad)
Firewall Policies & VPN Configurations (häftad)
Firewall Policies and VPN Configurations (häftad)
Next Generation SSH2 Implementation (häftad)

Cisco CCNA/CCENT Exam 640-802, 640-822, 640-816 Prep...

Dale Liu

Firewall Policies & VPN Configurations

Syngress, Dale Liu, Stephanie Miller, Mark Lucas, Abhishek Singh (häftad)

Firewall Policies and VPN Configurations

Syngress, Dale Liu, Stephanie Miller, Mark Lucas, Abhishek Singh (e-bok)

Next Generation SSH2 Implementation

Dale Liu (e-bok)
340:- Köp
259:- Köp
482:- Visa
342:- Visa

Kundrecensioner

Bli först med att recensera och betygsätt boken Cisco Router and Switch Forensics: Investigating and Analyzing Malicious Network Activity - du kan vinna 200 kr varje månad i tävlingen "Månadens recension".

Bloggat om Cisco Router and Switch Forensics: Investigating and...

Övrig information

Dale Liu, (MCSE Security, CISSP, MCT, IAM/IEM, CCNA) has been working in the computer and networking field for over 20 years. Dale's experience ranges from programming to networking to information security and project management. He currently teaches networking, routing and security classes, while working in the field performing security audits and infrastructure design for medium to large companies.

Innehållsförteckning

Introduction: An Overview of Cisco Router and Switch Forensics
Chapter 1: Digital Forensics and Analyzing Data
Chapter 2: Seizure of Digital Information
Chapter 3: The Basics of Networking
Chapter 4: The Language and Mindset of a Network Administrator
Chapter 5: Subnetting and CIDR
Chapter 6: Arrival on the Scene
Chapter 7: Diagramming the Network Infrastructure
Chapter 8: Cisco IOS Router Basics
Chapter 9: Understanding the Methods and Mindset of the Attacker
Chapter 10: Collecting the Non-Volatile Data from a Router
Chapter 11: Collecting the Volatile Data from a Router
Chapter 12: Cisco IOS Switch Basics
Chapter 13: Virtual LANs
Chapter 14: Collecting the Non-Volatile and Volatile Data from a Switch
Chapter 15: Preparing Your Report
Chapter 16: Preparing to Testify
Appendix A: Cisco Wireless Device Forensics

De som köpt "Cisco Router and Switch Forensics: Investigating and Analyzing Malicious..." har även köpt:

Ljussätt plåta retuscha steg för steg (häftad)

Ljussätt plåta retuscha steg för steg

Scott Kelby (häftad)
269:-
Computer Networking: A Top-Down Approach Pearson International Edition 5th Edition (häftad)

Computer Networking: A Top-Down Approach Pearson Int...

James F Kurose, Keith W Ross (häftad)
626:-
SPSS steg för steg (häftad)

SPSS steg för steg

Lars Wahlgren (häftad)
194:-
Photoshop Elements 9 för digitalfotografer (häftad)

Photoshop Elements 9 för digitalfotografer

Scott Kelby, Matt Kloskowski (häftad)
271:-
Basics of Web Design (häftad)

Basics of Web Design

Terry Felke-Morris (häftad)
429:-
Cisco Router and Switch Forensics: Investigating and Analyzing Malicious Network Activity (häftad)

Fler böcker inom

  • Titel: Cisco Router and Switch Forensics: Investigating and Analyzing Malicious Network Activity
  • ISBN: 9781597494182
  • Förlag: SYNGRESS MEDIA
  • Utgivningsland: USA
  • Utgivningsort: Rockland, MA
  • Illustratör/Fotograf: Approx 130 illustrations
  • Illustrationer: Approx. 130 illustrations
  • Antal sidor: 504
  • Vikt: 890 g
  • Höjd: 235 mm
  • Antal komponenter: 1
  • Format: Häftad (paperback)