• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% studentrabatt med kod TERM26

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Samhälle och politik
    2. Social välfärd och brottslighet
    3. Brottslighet och kriminologi
    4. Brottsutredning och kriminalteknik
    • -10% student

    Digital Forensics

    AvAndré Årnes,André Årnes

    Häftad, Engelska, 2017

    925 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Beskrivning

    The definitive text for students of digital forensics, as well as professionals looking to deepen their understanding of an increasingly critical fieldWritten by faculty members and associates of the world-renowned Norwegian Information Security Laboratory (NisLab) at the Norwegian University of Science and Technology (NTNU), this textbook takes a scientific approach to digital forensics ideally suited for university courses in digital forensics and information security. Each chapter was written by an accomplished expert in his or her field, many of them with extensive experience in law enforcement and industry. The author team comprises experts in digital forensics, cybercrime law, information security and related areas.  Digital forensics is a key competency in meeting the growing risks of cybercrime, as well as for criminal investigation generally. Considering the astonishing pace at which new information technology – and new ways of exploiting information technology – is brought on line, researchers and practitioners regularly face new technical challenges, forcing them to continuously upgrade their investigatory skills. Designed to prepare the next generation to rise to those challenges, the material contained in Digital Forensics has been tested and refined by use in both graduate and undergraduate programs and subjected to formal evaluations for more than ten years. Encompasses all aspects of the field, including methodological, scientific, technical and legal mattersBased on the latest research, it provides novel insights for students, including an informed look at the future of digital forensicsIncludes test questions from actual exam sets, multiple choice questions suitable for online use and numerous visuals, illustrations and case example imagesFeatures real-word examples and scenarios, including court cases and technical problems, as well as a rich library of academic references and references to online mediaDigital Forensics is an excellent introductory text for programs in computer science and computer engineering and for master degree programs in military and police education. It is also a valuable reference for legal practitioners, police officers, investigators, and forensic practitioners seeking to gain a deeper understanding of digital forensics and cybercrime.

    Produktinformation

    • Utgivningsdatum:2017-07-21
    • Mått:168 x 241 x 20 mm
    • Vikt:658 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:384
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781119262381

    Ingår i kampanjer

    -10% student

    Utforska kategorier

    • Brottsutredning och kriminalteknik inom Samhälle och politik
    • IT-säkerhet inom Data och IT

    Mer om författaren

    ANDRÉ ÅRNES, PhD is Senior Vice President and Chief Security Office of Telenor Group and an Associate Professor on the faculty of the Norwegian Information Security Laboratory (NisLab) at the Norwegian University of Technology and Science (NTNU). An experienced cyber security expert, Dr. Årnes has extensive experience both as a security leader in a global corporation and as a computer crime special investigator in law enforcement.

    Innehållsförteckning

    • Preface xvList of Contributors xviiList of Figures xxiList of Tables xxvList of Examples xxviiList of Definitions xxixList of Abbreviations xxxi1 Introduction 1André Årnes1.1 Forensic Science 11.1.1 History of Forensic Science 21.1.2 Locard’s Exchange Principle 21.1.3 Crime Reconstruction 31.1.4 Investigations 31.1.5 Evidence Dynamics 41.2 Digital Forensics 41.2.1 Crimes and Incidents 51.2.2 Digital Devices, Media, and Objects 51.2.3 Forensic Soundness and Fundamental Principles 51.2.4 Crime Reconstruction in Digital Forensics 61.3 Digital Evidence 71.3.1 Layers of Abstraction 71.3.2 Metadata 71.3.3 Error, Uncertainty, and Loss 71.3.4 Online Bank Fraud – A Real-World Example 81.3.4.1 Modus Operandi 81.3.4.2 The SpyEye Case 81.4 Further Reading 91.5 Chapter Overview 101.6 Comments on Citation and Notation 102 The Digital Forensics Process 13Anders O. Flaglien2.1 Introduction 132.1.1 Why Do We Need a Process? 142.1.2 Principles of a Forensics Process 152.1.3 Finding the Digital Evidence 152.1.4 Introducing the Digital Forensics Process 162.2 The Identification Phase 172.2.1 Preparations and Deployment of Tools and Resources 182.2.2 The First Responder 192.2.3 At the Scene of the Incident 212.2.3.1 Preservation Tasks 222.2.4 Dealing with Live and Dead Systems 222.2.5 Chain of Custody 232.3 The Collection Phase 242.3.1 Sources of Digital Evidence 262.3.2 Systems Physically Tied to a Location 282.3.3 Multiple Evidence Sources 282.3.4 Reconstruction 282.3.5 Evidence Integrity and Cryptographic Hashes 292.3.6 Order of Volatility 302.3.7 Dual-Tool Verification 322.3.8 Remote Acquisition 322.3.9 External Competency and Forensics Cooperation 332.4 The Examination Phase 332.4.1 Initial Data Source Examination and Preprocessing 342.4.2 Forensic File Formats and Structures 352.4.3 Data Recovery 352.4.4 Data Reduction and Filtering 362.4.5 Timestamps 372.4.6 Compression, Encryption and Obfuscation 372.4.7 Data and File Carving 382.4.8 Automation 392.5 The Analysis Phase 392.5.1 Layers of Abstraction 402.5.2 Evidence Types 402.5.3 String and Keyword Searches 412.5.4 Anti-Forensics 422.5.4.1 Computer Media Wiping 422.5.4.2 Analysis of Encrypted and Obfuscated Data 422.5.5 Automated Analysis 432.5.6 Timelining of Events 432.5.7 Graphs and Visual Representations 432.5.8 Link Analysis 442.6 The Presentation Phase 452.6.1 The Final Reports 462.6.2 Presentation of Evidence and Work Conducted 462.6.3 The Chain of Custody Circle Closes 472.7 Summary 472.8 Exercises 483 Cybercrime Law 51Inger Marie Sunde3.1 Introduction 513.2 The International Legal Framework of Cybercrime Law 543.2.1 The Individuals Involved in Criminal Activity and in CrimePreventing Initiatives 543.2.2 The National Legal System versus the International Legal Framework 553.2.3 Fundamental Rights Relating to Cybercrime Law – The ECHR 563.2.3.1 The ECtHR as a Driving Force for Development of Human Rights 573.2.3.2 The Right to Bring a Case before the ECtHR 573.2.3.3 A Special Note on Transborder Search and Surveillance 583.2.3.4 The Connection between Fundamental Rights and the Rule of Law 603.2.3.5 The Principle of Legality in the Context of Crime 603.2.3.6 The Principle of Legality in the Context of a Criminal Investigation 613.2.3.7 The Positive Obligation of the Nation State 633.2.3.8 The Right to Fair Trial 643.2.3.9 A Special Note on Evidence Rules in Different Legal Systems 683.2.3.10 Possible Outcomes of a Violation of Fundamental Rights 693.2.4 Special Legal Framework: The Cybercrime Convention 693.2.5 Interpretation of Cybercrime Law 723.2.5.1 Interpretation of Substantive Criminal Law 723.2.5.2 Application of Old Criminal Provisions to New Modes of Conduct 743.2.5.3 Interpretation of Procedural Provisions Authorizing Coercive Measures 753.3 Digital Crime – Substantive Criminal Law 763.3.1 General Conditions for Criminal Liability 773.3.2 Real-Life Modus Operandi 803.3.3 Offenses against the Confidentiality, Integrity, and Availability of Computer Data and Systems 813.3.3.1 Illegal Access and Illegal Interception 823.3.3.2 Data and System Interference 853.3.3.3 Misuse of Devices 883.3.4 Computer-Related Offenses 893.3.5 Content-Related Offenses 913.3.6 Offenses Related to Infringements of Copyright and Related Rights 933.3.7 Racist and Xenophobic Speech 943.4 Investigation Methods for Collecting Digital Evidence 953.4.1 The Digital Forensic Process in the Context of Criminal Procedure 953.4.2 Computer Data That Are Publicly Available 973.4.2.1 Transborder Access to Stored Computer Data Where Publicly Available 983.4.2.2 Online Undercover Operations 983.4.3 Scope and Safeguards of the Investigation Methods 993.4.3.1 Suspicion-Based Investigation Methods 993.4.3.2 The Scope of the Investigation Methods (Article 14) 993.4.3.3 Conditions and Safeguards (Article 15) 1003.4.3.4 Considerations Relating to Third Parties 1023.4.4 Search and Seizure (Article 19) 1033.4.4.1 Main Rules 1033.4.4.2 Special Issues 1043.4.5 Production Order 1063.4.6 Expedited Preservation and Partial Disclosure of Traffic Data 1073.4.6.1 Real-Time Investigation Methods (Articles 20 and 21) 1073.5 International Cooperation in Order to Collect Digital Evidence 1093.5.1 Narrowing the Focus 1093.5.2 A Special Note on Transborder Access to Digital Evidence 1103.5.3 Mutual Legal Assistance 1113.5.3.1 Basic Principles and Formal Steps of the Procedure 1113.5.3.2 International Conventions Concerning Mutual Legal Assistance 1123.5.4 International Police Cooperation and Joint Investigation Teams 1143.6 Summary 1153.7 Exercises 1154 Digital Forensic Readiness 117Ausra Dilijonaite4.1 Introduction 1174.2 Definition 1174.3 Law Enforcement versus Enterprise Digital Forensic Readiness 1184.4 Why? A Rationale for Digital Forensic Readiness 1194.4.1 Cost 1194.4.2 Usefulness of Digital Evidence 1204.4.2.1 Existence of Digital Evidence 1214.4.2.2 Evidentiary Weight of Digital Evidence 1214.5 Frameworks, Standards, and Methodologies 1234.5.1 Standards 1244.5.1.1 ISO/IEC 27037 1244.5.1.2 ISO/IEC 17025 1244.5.1.3 NIST SP 800-86 1244.5.2 Guidelines 1244.5.2.1 IOCE Guidelines 1244.5.2.2 Scientific Working Group on Digital Evidence (SWGDE) 1254.5.2.3 ENFSI Guidelines 1254.5.3 Research 1254.5.3.1 Rowlingson’s Ten-Step Process 1254.5.3.2 Grobler et al.’s Forensic Readiness Framework 1254.5.3.3 Endicott-Popovsky et al.’s Forensic Readiness Framework 1264.6 Becoming “Digital Forensic” Ready 1264.7 Enterprise Digital Forensic Readiness 1274.7.1 Legal Aspects 1274.7.2 Policy, Processes, and Procedures 1284.7.2.1 Risk-Based Approach 1284.7.2.2 Incident Response versus Digital Forensics 1304.7.2.3 Policy 1304.7.2.4 Processes and Procedures 1314.7.3 People 1324.7.3.1 Roles and Responsibilities 1324.7.3.2 Skills, Competencies, and Training 1344.7.3.3 Awareness Training 1344.7.4 Technology: Digital Forensic Laboratory 1354.7.4.1 Accreditation and Certification 1354.7.4.2 Organizational Framework 1364.7.4.3 Security Policy or Framework 1364.7.4.4 Control of Records 1364.7.4.5 Processes, Procedures, and Lab Routines 1374.7.4.6 Methodology and Methods 1384.7.4.7 Personnel 1384.7.4.8 Code of Conduct 1384.7.4.9 Tools 1384.7.5 Technology: Tools and Infrastructure 1394.7.5.1 Sources of the Digital Evidence 1394.7.5.2 Validation and Verification of Digital Forensic Tools 1404.7.5.3 Preparation of Infrastructure 1414.7.6 Outsourcing Digital Forensic Capabilities 1424.7.6.1 Continuous Improvement 1434.8 Considerations for Law Enforcement 1444.9 Summary 1454.10 Exercises 1455 Computer Forensics 147Jeff Hamm5.1 Introduction 1475.2 Evidence Collection 1485.2.1 Data Acquisition 1495.2.1.1 Live Data (Including Memory) 1505.2.1.2 Forensic Image 1525.2.2 Forensic Copy 1525.3 Examination 1525.3.1 Disk Structures 1535.3.1.1 Physical Disk Structures 1535.3.1.2 Logical Disk Structures 1565.3.2 File Systems 1595.3.2.1 NTFS (New Technology File System) 1635.3.2.2 INDX (Index) 1735.3.2.3 Orphan Files 1745.3.2.4 EXT2/3/4 (Second, Third, and Fourth Extended Filesystems) 1765.3.2.5 Operating System Artifacts 1775.3.2.6 Linux Distributions 1835.4 Analysis 1855.4.1 Analysis Tools 1855.4.2 Timeline Analysis 1865.4.3 File Hashing 1875.4.4 Filtering 1875.4.5 Data Carving 1885.4.5.1 Files 1885.4.5.2 Records 1885.4.5.3 Index Search 1895.4.6 Memory Analysis 1895.5 Summary 1895.6 Exercises 1906 Mobile and Embedded Forensics 191Jens-Petter Sandvik6.1 Introduction 1926.1.1 Embedded Systems and Consumer Electronics 1926.1.2 Mobile Phones 1946.1.2.1 UICC (Formerly Known as a SIM Card) 1956.1.3 Telecommunication Networks 1966.1.3.1 GSM Network 1966.1.3.2 UMTS Networks 1986.1.3.3 Evolved Packet System (EPS)–Long-Term Evolution (LTE) Networks 1986.1.3.4 Evidence in the Mobile Network 1996.1.4 Mobile Devices and Embedded Systems as Evidence 2006.1.5 Malware and Security Considerations 2016.1.6 Ontologies for Mobile and Embedded Forensics 2026.1.6.1 An Acquisition Method Ontology 2026.1.6.2 Technical Qualities 2076.1.6.3 Tools Used for Acquisition 2076.1.6.4 Data Acquisition Methods 2086.2 Collection Phase 2086.2.1 Special Considerations for Embedded Systems and Mobile Devices 2096.2.1.1 Functionality 2106.2.1.2 Stored Data 2106.2.1.3 Storage Media 2106.2.1.4 Security Measures 2106.2.1.5 Communication Ports and Protocols 2106.2.2 Handling Electronics – ESD 2106.2.3 First Contact 2126.2.3.1 Hazards 2126.2.3.2 Preservation of Other Traces 2136.2.3.3 Damages and Unique Characteristics 2136.2.3.4 State and Information 2136.2.3.5 Clock Setting 2136.2.3.6 Investigative Value of Information 2136.2.4 Physical Acquisition 2146.2.4.1 Two Approaches to Physical Acquisition 2156.2.4.2 Chip-Off/In Vitro Acquisition 2166.2.4.3 JTAG/In-System Acquisition 2226.2.5 Logical Acquisition of Data 2256.2.5.1 Manual Inspection 2256.2.5.2 SIM Acquisition 2256.2.5.3 SIM Replacement 2286.2.5.4 Device Backup 2286.2.5.5 USB Mass Storage 2296.2.5.6 Media Transfer Protocol 2306.2.5.7 OBEX 2306.2.5.8 AT Commands 2316.2.5.9 Vendor-Specific Protocols 2336.2.5.10 Android Debug Bridge (ADB) 2336.2.6 Somewhere between Physical and Logical 2346.2.6.1 Root Access 2356.2.6.2 Boot Access 2356.2.6.3 Encryption Keys 2376.2.6.4 Flasher Tools 2376.2.6.5 Chip-Off Continued 2386.2.7 Commercial Forensic Products 2406.2.8 What about RAM? 2416.2.9 Damaged Devices 2416.2.9.1 External Force 2426.2.9.2 Water, Liquids, and Blood 2436.2.10 Wrapping It Up 2436.2.10.1 Matrix of Information Availability 2436.2.10.2 Cheat Sheet 2456.2.10.3 On or Off? 2456.3 Examination Phase 2476.3.1 Top-Down: Flash Translation Layer (FTL) 2476.3.2 Top-Down: Flash File Systems 2496.3.3 Bottom-Up: Carving 2506.3.4 Bottom-Up: Keyword Search 2506.3.5 Technical Deep-Dive: FTL from Nokia 7610 Supernova 2516.3.6 Technical Deep-Dive: Flash File System – YAFFS 2526.3.7 Technical Deep-Dive: Structure – SMS PDU 2556.3.8 Technical Deep-Dive: Structure – SQLite3 Database 2616.3.9 Technical Deep-Dive: Timestamps 2656.4 Reverse Engineering and Analysis of Applications 2676.4.1 Methods 2676.4.1.1 Black Box Testing 2676.4.1.2 Static Code Analysis 2686.4.1.3 Runtime Analysis 2686.4.2 Targets 2696.4.2.1 Program Functionality 2696.4.2.2 Data Structures 2696.4.2.3 Protocols 2696.4.2.4 Encryption 2696.5 Summary 2706.6 Exercises 2717 Internet Forensics 275Petter Christian Bjelland7.1 Introduction 2757.2 Computer Networking 2767.3 Layers of Network Abstraction 2777.3.1 The Physical Layer 2777.3.2 The Data Link, Network, and Transport Layers 2777.3.2.1 IP Addresses 2787.3.3 The Session, Presentation, and Application Layers 2787.4 The Internet 2797.4.1 Internet Backbone 2797.4.1.1 Autonomous System (AS) 2797.4.1.2 Border Gateway Protocol (BGP) 2807.4.1.3 Internet Service Providers (ISPs) 2817.4.2 Common Applications 2817.4.2.1 Domain Name System (DNS) 2817.4.2.2 Email 2837.4.2.3 World Wide Web (WWW) 2847.4.2.4 Peer-to-Peer Networks 2857.4.2.5 Other Media 2857.4.3 Caveats 2867.4.3.1 Network Address Translation (NAT) 2867.4.3.2 Onion Routing 2877.4.3.3 Web Shells 2887.5 Tracing Information on the Internet 2897.5.1 DNS and Reverse DNS 2897.5.2 Whois and Reverse Whois 2907.5.3 Ping and Port Scan 2907.5.4 Traceroute 2917.5.5 IP Geolocation 2917.5.6 Tracing BitTorrent Peers 2927.5.7 Bitcoin Unconfirmed Transaction Tracing 2937.6 Collection Phase – Local Acquisition 2947.6.1 Browser History 2957.6.2 Browser Cache 2957.6.3 Browser Cookies 2967.6.4 Email 2977.6.5 Messaging and Chats 2977.6.6 Internet of Things 2977.7 Collection Phase – Network Acquisition 2987.7.1 tcpdump and pcap 2987.7.1.1 Netflow 2997.7.2 DHCP Logs 2997.8 Collection Phase – Remote Acquisition 3007.8.1 Server 3007.8.1.1 Web Server Logs 3007.8.1.2 Web Application Logs 3007.8.1.3 Virtual Hosts 3017.8.2 Cloud Services 3017.8.3 Open Sources 3027.8.3.1 Personal Information 3027.8.3.2 User Accounts 3037.8.3.3 Contact Lists 3037.8.3.4 Publication of Content 3037.8.3.5 Interaction with Content 3037.8.3.6 Public Interaction 3047.8.3.7 Association with Groups and Communities 3047.9 Other Considerations 3047.9.1 Application Programming Interfaces (APIs) 3047.9.1.1 Accessing User Accounts 3047.9.2 Integrity of Remote Artifacts 3057.10 The Examination and Analysis Phases 3067.10.1 Finding Interesting Nodes in Large Networks 3067.10.2 Divide and Conquer Large Networks 3077.10.2.1 Clustering 3077.10.2.2 Community Detection 3077.10.3 Making Sense of Millions of Events 3087.10.3.1 Aggregated Timelines 3087.10.3.2 Temporal Networks 3097.10.3.3 Heat Maps 3107.11 Summary 3117.12 Exercises 3128 Challenges in Digital Forensics 313Katrin Franke and André Årnes8.1 Computational Forensics 3138.1.1 The Objectives of Computational Forensics 3148.1.1.1 Large-Scale Investigations 3148.1.1.2 Automation 3148.1.1.3 Analysis 3158.1.1.4 Forensic Soundness 3158.1.2 Disciplines of Computational Forensics 3168.2 Automation and Standardization 3168.3 Research Agenda 3178.4 Summary 3179 Educational Guide 319Stefan Axelsson9.1 Teacher’s Guide 3199.2 Student’s Guide 3209.2.1 Journals 3209.2.2 Conferences and Organizations 3219.2.3 Professional and Training Organizations 3229.2.4 Tools 3239.2.5 Corpuses 3239.3 Summary 324References 325Index 333