Computer forensics

——反删除实战系列之一

    作为IT安全方面的从业人员了解一点计算机取证技术还是有必要的!!!???

    本人最近无聊研究了下Computer Forensics(计算机取证)技术,更大家分享下。

    本文是第一篇,之后会有NTFS、ext3的(看情况)

 

 

 

 

 

 

 

 

 

 

下面两个参考用:

 

 

 

参考书籍:

Guide to Computer Forensics and Investigations

http://www.amazon.com/Guide-Computer-Forensics-Investigations-Nelson/dp/1435498836/ref=sr_1_3?ie=UTF8&qid=1298617682&sr=8-3

Computer Forensics: Principles and Practices

http://www.amazon.com/Computer-Forensics-Principles-Linda-Volonino/dp/0131547275/ref=sr_1_5?ie=UTF8&qid=1298617682&sr=8-5

File System Forensic Analysis

http://www.amazon.com/System-Forensic-Analysis-Brian-Carrier/dp/0321268172/ref=sr_1_7?ie=UTF8&qid=1298617682&sr=8-7

EnCase Computer Forensics, includes DVD: The Official EnCE: EnCase Certified Examiner Study Guide

http://www.amazon.com/EnCase-Computer-Forensics-DVD-Certified/dp/0470181451/ref=sr_1_8?ie=UTF8&qid=1298617682&sr=8-8

数据重现:文件系统原理精解

相关认证:

1.GIAC Certified Forensic Analyst (GCFA)

http://www.giac.org/certifications/forensics/gcfa.php

2.Computer Hacking Forensic Investigator (CHFI)

http://www.eccouncil.org/certification/computer_hacking_forensic_investigator.aspx