CDN$ 59.69
  • List Price: CDN$ 62.89
  • You Save: CDN$ 3.20 (5%)
Temporarily out of stock.
Order now and we'll deliver when available. We'll e-mail you with an estimated delivery date as soon as we have more information. Your account will only be charged when we ship the item.
Ships from and sold by Gift-wrap available.
Incident Response: Comput... has been added to your Cart
Have one to sell?
Flip to back Flip to front
Listen Playing... Paused   You're listening to a sample of the Audible audio edition.
Learn more
See this image

Incident Response: Computer Forensics Toolkit Paperback – May 2 2003

4.4 out of 5 stars 8 customer reviews

See all formats and editions Hide other formats and editions
Amazon Price
New from Used from
"Please retry"
CDN$ 59.69
CDN$ 46.11 CDN$ 4.48

Save an Additional 10% on Textbooks When you Join Amazon Student

Special Offers and Product Promotions

  • Amazon Student members save an additional 10% on Textbooks with promo code TEXTBOOK10. Enter code TEXTBOOK10 at checkout. Here's how (restrictions apply)

No Kindle device required. Download one of the Free Kindle apps to start reading Kindle books on your smartphone, tablet, and computer.

  • Apple
  • Android
  • Windows Phone
  • Android

To get the free app, enter your e-mail address or mobile phone number.

Product Details

  • Paperback: 345 pages
  • Publisher: Wiley; 1 edition (May 2 2003)
  • Language: English
  • ISBN-10: 0764526367
  • ISBN-13: 978-0764526367
  • Product Dimensions: 18.9 x 2 x 23.4 cm
  • Shipping Weight: 567 g
  • Average Customer Review: 4.4 out of 5 stars 8 customer reviews
  • Amazon Bestsellers Rank: #3,089,460 in Books (See Top 100 in Books)
  •  Would you like to update product info, give feedback on images, or tell us about a lower price?

  • See Complete Table of Contents

Product Description

From the Back Cover

Your in-depth guide to detecting network breaches, uncovering evidence, and preventing future attacks

Whether it’s from malicious code sent through an e-mail or an unauthorized user accessing company files, your network is vulnerable to attack. Your response to such incidents is critical. With this comprehensive guide, Douglas Schweitzer arms you with the tools to reveal a security breach, gather evidence to report the crime, and conduct audits to prevent future attacks. He also provides you with a firm understanding of the methodologies for incident response and computer forensics, Federal Computer Crime law information and evidence requirements, legal issues, and how to work with law enforcement.

You’ll learn how to:

  • Recognize the telltale signs of an incident and take specific response measures
  • Search for evidence by preparing operating systems, identifying network devices, and collecting data from memory
  • Analyze and detect when malicious code enters the system and quickly locate hidden files
  • Perform keyword searches, review browser history, and examine Web caches to retrieve and analyze clues
  • Create a forensics toolkit to prop-erly collect and preserve evidence
  • Contain an incident by severing network and Internet connections, and then eradicate any vulnerabilities you uncover
  • Anticipate future attacks and monitor your system accordingly
  • Prevent espionage, insider attacks, and inappropriate use of the network
  • Develop policies and procedures to carefully audit the system

CD-ROM includes:

  • Helpful tools to capture and protect forensic data; search volumes, drives, and servers for evidence; and rebuild systems quickly after evidence has been obtained
  • Valuable checklists developed by the author for all aspects of incident response and handling

About the Author

DOUGLAS SCHWEITZER is an Internet security specialist and authority on malicious code and computer forensics. He is a Cisco Certified Network Associate and Certified Internet Webmaster Associate, and holds A+, Network+, and i-Net+ certifications. Schweitzer is also the author of Internet Security Made Easy and Securing the Network from Malicious Code.

Inside This Book

(Learn More)
First Sentence
THE HI-TECH REVOLUTION SWEEPING THE GLOBE in communications and information technology has truly made the world a smaller place. Read the first page
Explore More
Browse Sample Pages
Front Cover | Copyright | Table of Contents | Excerpt | Index | Back Cover
Search inside this book:

Customer Reviews

4.4 out of 5 stars
Share your thoughts with other customers

Top Customer Reviews

Format: Paperback
The introduction describes this book as a "complete introductory course in basic computer forensics and incident response" and that is indeed the case. It begins with an overview of computer forensics and incident response in Chapter 1 and progresses to legal considerations, obtaining and preserving digital evidence, system internals (mostly Windows although Unix is also discussed) and ends with analysis of real-world attacks and possible defences in Chapter 12. Press references and citations are used to give the big picture. All in all this is a book which I would recommend with two "buts": first, the author is writing from a US perspective for a US reader, presenting and discussing US-specific legislation and legal issues; while this would be of direct interest to our US-based brethren it is of no much use to anyone else. Second, platform-dependent coverage is mostly Windows, and although Linux/Unix get mentioned throughout the book the coverage of UNIX internals and forensics is not on par with Windows counterparts. Having said this, if you are in the US and are using Windows, do get this book - it is a readable and straight introduction to a complex and interesting field which becomes more and more important.
Edgar Danielyan, CISSP
Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again.
Report abuse
Format: Paperback
The author covers different aspects of incident response, but fails to go deeper in the matter.
The author talks briefly about types of attacks, briefly about forensics tools, and briefly about the incident response procedures. Such shallow coverage of the topics makes for a quite dissappointing read.
On the other hand he offers the readers complete text of USA Patriot Act 2001 - with little discussion of its implications, privacy concerns and its impact on the organizational security! Readers also get treated to full texts of Janet Renot(sp?) speeches - also with little explanation. Seems he tried to increase the word count of the book.
Forensics tools are mentioned with instructions to run them starting as "Step 1:Click the Start menu button". Every tool has a half a page description on how to start it with a screenshot taking up the rest of the page.
Forensics techniques are described, but the author presents this quite technical material in the abstract, easy-to-read form that takes away all the usefullness of it - reads like a summary.
Incident response chapters present the reader with the common sense material. Might be useful to get an idea of what is involved in developing a incident response process, but it's hard to find it practical - it's simply too general.
A fair introductory book, could be much better.
Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again.
Report abuse
Format: Paperback
This is one of the most recent release (in year 2003) in the topics, and it is imformative in technical, procedure wide, and legal consideration.
There are rooms for improvement in structurinng between paragraph and addition of more detailed information. Jumping in the Chapter 7 - Procedures for Collecting and Preserving Evidence:
First area of improvement - Right after the section in Underestanding Volatility of Evidence is Creating a Real-Mode Forensic Book Disk. Heading of each section can be more clear in using numbering. It is a bit confuse when you talk about volatile information and then in the next section in creating Boot Disk that is for inspecting non-volitale information.
Second area of improvement - Regarding importance of evidence preservation, the book does not teach you HOW - e.g. technically using MD5 and procedure wide asking third party and/or suspect to verify information obtained.
Overall, it is a good reference book in knowing computer forensic.
Final word: One thing about the book I like is the inclusion of software version in the CD which is handy for reading it when need.
Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again.
Report abuse
By A Customer on Jan. 19 2004
Format: Paperback
A well considered and well structured work for the IT professional.
The book is fast paced and wisely does not get dragged down with too much detail and 'how to' guides. It provided the knowledge and check lists to enable the reader to react appropriatly to an IT emergency or situation where a forensic approach is required.
It's clear structure will enable me to use the book as a reference work in the future.
The included CDROM was useful although in the future a PDF guide of each file would have been handy reference. It would have also been nice to have seen the free tools mentioned in the book included on the disk.
Overall an excellent read I will look out for Douglas Schweitzer books again.
Was this review helpful to you? Yes No Sending feedback...
Thank you for your feedback.
Sorry, we failed to record your vote. Please try again.
Report abuse