官术网_书友最值得收藏!

The role of digital forensics

There is a misconception that is often held by people unfamiliar with the realm of incident response. This misconception is that incident response is merely a digital forensics issue. As a result, they will often conflate the two terms. While digital forensics is a critical component to incident response (and this is why we have included a number of chapters in this book to address digital forensics), there is more to addressing an incident than examining hard drives. It is best to think of forensics as a supporting function of the overall incident response process. For example, some incidents such as Denial of Service attacks will require little to no forensic work. On the other hand, a network intrusion involving the compromise of an internal server and Command and Control (C2) traffic leaving the network will require extensive examination of logs, traffic analysis, and examination of memory. From this analysis may be derived the root cause. In both cases, the impacted organization would be able to connect with the incident, but forensics played a much more important role in the latter case.

主站蜘蛛池模板: 独山县| 永登县| 西城区| 赫章县| 罗定市| 鹤庆县| 巨野县| 常山县| 新干县| 含山县| 霸州市| 呈贡县| 根河市| 东平县| 玉田县| 隆回县| 门头沟区| 确山县| 昭觉县| 惠来县| 邻水| 抚宁县| 滦平县| 望江县| 伊川县| 仁布县| 区。| 陆良县| 栖霞市| 疏附县| 温宿县| 巫溪县| 和平县| 新郑市| 黑河市| 镇巴县| 泾阳县| 农安县| 长治市| 连山| 丹棱县|