Dan Farmer is the author of a variety of security programs and papers.He is currently chief technical officer of Elemental Security,a computer security software company.WAietse Venema has written some of the world's most widely used software,including TCP Wrapper and the Postfix mail system .He is currently a research staff member at IBM Research.Together,Farmer and Venema have written many of the world's leading information-security and forensics packages,including the SATAN network security scanner and the Coroner's Tookit.
【目录】
Preface vii
About the Authors xii
PartⅠ:Basic Concepts
Chapter 1:The Spirit of Forensic Discovery
1.1 Introduction
1.2 Unusual Activity Stands Out
1.3 The Order of Volatility
1.4 Layers and Illusions
1.5 The Trustworthiness of Information
1.6 The Fossilization of Deleted Information
1.7 Archaeology vs.Geology
Chapter 2:Time Machines
2.1 Introduction
2.2 The First Signs of Trouble
2.3 What's Up,MAC?An Introduction to MACtimes
2.4 Limitations of MACtimes
2.5 Argus:Shedding Additional Light on the Situation
2.6 Panning for Gold:Looking for Time in Unusual Places
2.7 DNS and Time
2.8 Journaling File Systems and MACtimes
2.9 The Foibles of Time
2.10 Conclusion
PartⅡ:Exploring System Abstractions
Chapter 3:File System Basics
3.1 Introduction
3.2 An Alphabet Soup of File Sytems
3.3 UNIX File Organization
3.4 UNIX File Names
3.5 UNIX Pathnames
3.6 UNIX File Types
3.7 A First Look Under the Hood:File System Internals
以下为对购买帮助不大的评价