Davidoff, Sherri

Network forensics : tracking hackers through cyberspace / Sherri Davidoff and Jonathan Ham - Upper Saddle River, NJ : Prentice Hall, c2012. - xxvii, 545 pages : illustrations ; 24 cm.

Includes bibliographical references and index.

Part I: Foundation --
Practical investigative strategies --
Technical fundamentals --
Evidence acquisition --
Part II: Traffic analysis --
Packet analysis --
Statistical flow analysis --
Wireless : network forensics unplugged --
Network intrusion detection and analysis --
Part III: Network devices and servers --
Event log aggregation, correlation, and analysis --
Web proxies --
Part IV: Advanced topics --
Network tunneling --
Malware forensics.

"Learn to recognize hackers’ tracks and uncover network-based evidence in Network Forensics: Tracking Hackers through Cyberspace.Carve suspicious email attachments from packet captures. Use flow records to track an intruder as he pivots through the network. Analyze a real-world wireless encryption-cracking attack (and then crack the key yourself). Reconstruct a suspect’s web surfing history–and cached web pages, too–from a web proxy. Uncover DNS-tunneled traffic. Dissect the Operation Aurora exploit, caught on the wire. Throughout the text, step-by-step case studies guide you through the analysis of network-based evidence. You can download the evidence files from the authors’ web site (lmgsecurity.com), and follow along to gain hands-on experience."--From Publisher.

9780132564717


COMPUTER CRIMES -- INVESTIGATION.
HACKERS.
FORENSIC SCIENCES.
COMPUTER CRIMES -- INVESTIGATION -- CASE STUDIES.

HV 8079.C65 .D38 2012