Produktinformation
Möchten Sie die Produktinformationen aktualisieren oder Feedback zu den Produktabbildungen geben?
Ist der Verkauf dieses Produkts für Sie nicht akzeptabel? |
Unlike many books about computers, this one deserves to be read cover-to-cover. The authors have points to make, and they generally build on their earlier thoughts as they go. Some material in these pages seems somewhat obvious--the advice to dress nicely for a media interview, for example--but it all fits with the authors' goal of showing their readers how to react (in all respects) to security problems when they happen. Read this, be prepared for trouble, and know how to educate others about incident response. --David Wall
Topics covered: how an organisation should react--organisationally, technically, legally and in terms of public relations--to incidents of unauthorised access (originating both internally and externally) to its computer systems.
Unlike many books about computers, this one deserves to be read cover to cover. The authors have points to make, and they generally build on their earlier thoughts as they go. Some material in these pages seems somewhat obvious--the advice to dress nicely for a media interview, for example--but it all fits with the authors' goal of showing their readers how to react (in all respects) to security problems when they happen. Read this, be prepared for trouble, and know how to educate others about incident response. --David Wall
Topics covered: How an organization should react--organizationally, technically, legally, and in terms of public relations--to incidents of unauthorized access (originating both internally and externally) to its computer systems.
Tags(Was ist das?)Bei einem Tag handelt es sich um ein Schlagwort, das zum Produkt passt.
Tags erleichtern allen Kunden die Suche und die Sortierung ihrer Lieblingsprodukte. |
The books starts with security basics. A risk assessment overview with loss estimates and a summary of digital risks (such as privilege escalation, break-in, denial-of-service, etc) is provided. It appears to be useful mostly for newcomers to the security field. Formal six stage incident response methodology is then presented by the authors. Preparation, Detection, Containment, Eradication Recovery and Follows-Up (PDCERF) process helps create a solid skeleton to support the fluid form of the IR process.
Admittedly, the book is less hands-on oriented than some other IR manuals; the reader will not find things like computer forensics tool command line options and ext2fs filesystem internals there. However, the book shines brightly in the area of human aspect of incident response. Written by a ex-CIA Ph.D. Psychologist, the amazing chapter on social sciences and incident response covers a diverse range of topics. Cybercrime profiling techniques such as victim counseling and victimology, identifying 'modus operandi' and attack pattern recognition, establishment of threat level and communication with attacker are all covered in the chapter, which provides an exciting journey into the mind of a computer criminal, a cyber-sleuth and a cybercrime victim. Also covered are insider attacks, often considered to be the doom of information security. A number of reasons "Why insiders attack?" are analyzed. The author overlays the social methods over the standard procedure of incident response
(detection->containment->eradication->recovery), which helps understand the crucial role the human element plays in any security incident.
Two chapters are devoted to high-level computer forensics overview. Hard disk basics are explained - FAT, cluster, secure deletion are all given an appropriate space. The book then goes to talk about the "guiding principles" of the investigation. The brief overview of forensic software and hardware is also provided. It only serves to familiarize the reader with the names of common packages and utilities. For example, TCT coroner kit is only given about 15 lines of text.
Honeypots also take an honorable place in the book. Their role in IR is studied in detail and is deemed important. Honeypots are also tied to the PDCERF methodology (namely, to detection, eradication and follow-up phases). The value of honeypots is recognized for studying attackers, shielding of IT resources and even gathering evidence for court prosecution. Some common ways of implementing honeypots (such as via virtual environment) are discussed. The authors even digress to touch upon the ethical implication of honeypots.
Another gem is a stimulating chapter on future direction in IR. The ambitious prediction of intelligent automated incident response and attacker tracking tools is made by the authors. While it is known that automated response to security incidents must be viewed with caution, the potential seem to exist for future automated IR "helpers".
Legal issues overview is a must for any IR book. A brief and to-the-point section on US laws and international cybercrime treaties is available.
Last, but not least, a short response and reporting checklist is compiled by the authors. It is based on the six step IR process and will help investigators to structure their efforts and assist with data collection. Also included is a copy of a Site Security Handbook (RFC2196) with an extensive list of references.
Overall, the book is an extremely useful guide for security managers and those tasked with organizing/maintaining incident response teams. It will not reveal any technology secrets to a skilled computer crime investigator. However, he is likely to enjoy the book anyway!
Anton Chuvakin, Ph.D., GCIA, GCIH is a Senior Security Analyst with a major information security company. His areas of infosec expertise include intrusion detection, UNIX security, forensics, honeypots, etc. In his spare time, he maintains his security portal info-secure.org
The book covers all of the main areas required for effective incident response. There are a lot of real world scenarios written to provide the reader with a feel for what is truly required of IR.
The book is geared towards the high level and does not provide much hands on information. Those looking for a heavy hands-on tome for IR will be better served by reading `Incident Response' by Kevin Mandia & Chris Prosise.
The only think I found lacking in the book was an overview of third-party software applications that can be used for a Computer Incident Response Team.
Other than that, Incident Response: A Strategic Guide to Handling System and Network Security Breaches is an excellent read written by two experts in the field.
|
Das Forum zu diesem Produkt
Fragen stellen, Meinungen austauschen, Einblicke gewinnen Aktive Diskussionen in ähnlichen Foren
Kundendiskussionen durchsuchen
|
Ähnliche Foren
|
||||||||||||||||||||||||||||||||||
|