Zum Hauptinhalt springen Zur Suche springen Zur Hauptnavigation springen
Beschreibung
In the second edition of this very successful book, Tony Sammes and Brian Jenkinson show how the contents of computer systems can be recovered, even when hidden or subverted by criminals. Equally important, they demonstrate how to insure that computer evidence is admissible in court. Updated to meet ACPO 2003 guidelines, Forensic Computing: A Practitioner's Guide offers: methods for recovering evidence information from computer systems; principles of password protection and data encryption; evaluation procedures used in circumventing a system's internal security safeguards, and full search and seizure protocols for experts and police officers. The book discusses file system technologies encountered in such operating platforms as Windows XP and 2000, and considers modern fast drives, new encryption technologies, the practicalities of "live" analysis, and the problems inherent in examining personal organisers. Numerous case studies and worked examples illustrate the text.
In the second edition of this very successful book, Tony Sammes and Brian Jenkinson show how the contents of computer systems can be recovered, even when hidden or subverted by criminals. Equally important, they demonstrate how to insure that computer evidence is admissible in court. Updated to meet ACPO 2003 guidelines, Forensic Computing: A Practitioner's Guide offers: methods for recovering evidence information from computer systems; principles of password protection and data encryption; evaluation procedures used in circumventing a system's internal security safeguards, and full search and seizure protocols for experts and police officers. The book discusses file system technologies encountered in such operating platforms as Windows XP and 2000, and considers modern fast drives, new encryption technologies, the practicalities of "live" analysis, and the problems inherent in examining personal organisers. Numerous case studies and worked examples illustrate the text.
Über den Autor
Until 1984, Professor A. J. Sammes was a serving British Army Officer with the rank of Colonel, late of the Royal Corps of Signals. His present appointment is Professor of Computing Science, in the Faculty of Military Science, Technology and Management at the Defense Academy, Cranfield University, Shrivenham.

His formal qualifications include a Bachelor of Science in Electrical Engineering, a Master of Philosophy in Computer Science and a Doctor of Philosophy in Computer Science, all degrees having been awarded by the University of London. He is also a Fellow of the British Computer Society and a Chartered Engineer.

His department has been more or less solely responsible for training senior police officers in the UK in the art of forensic computing. His testimony as an expert witness has been called in countless cases, of some of great national importance.
Zusammenfassung
In the second edition of this very successful book, Tony Sammes and Brian Jenkinson show how the contents of computer systems can be recovered, even when hidden or subverted by criminals. Equally important, they demonstrate how to insure that computer evidence is admissible in court. Updated to meet ACPO 2003 guidelines, Forensic Computing: A Practitioner's Guide offers: methods for recovering evidence information from computer systems; principles of password protection and data encryption; evaluation procedures used in circumventing a system's internal security safeguards, and full search and seizure protocols for experts and police officers. The book discusses file system technologies encountered in such operating platforms as Windows XP and 2000, and considers modern fast drives, new encryption technologies, the practicalities of "live" analysis, and the problems inherent in examining personal organisers. Numerous case studies and worked examples illustrate the text.
Inhaltsverzeichnis
Forensic Computing
Understanding Information
IT Systems Concepts
PC Hardware and Inside The Box
Disk Geometry
The New Technology File System
The Treatment of PCs
The Treatment of Electronic Organisers
Looking Ahead (Just a little bit more)
Appendices: Common Character Codes; Some Common File Format Signatures; A Typical Set of POST codes; Typical BIOS Beep Codes and Error Messages; Disk Partition Table Types; Ezxtended Partitions; Registers and Order Code for the INtel 8086; NFTS Boot Sector and BIOS Parameter Block; MFT Header and Attribute Maps; The Relationship Between CHS and LBA Addressing; Alternate Data Streams - a Brief Explanation
Details
Erscheinungsjahr: 2010
Genre: Importe, Informatik
Rubrik: Naturwissenschaften & Technik
Medium: Taschenbuch
Inhalt: x
470 S.
196 s/w Illustr.
470 p. 196 illus.
ISBN-13: 9781849965965
ISBN-10: 184996596X
Sprache: Englisch
Einband: Kartoniert / Broschiert
Autor: Sammes, Anthony
Jenkinson, Brian
Auflage: Second Edition 2007
Hersteller: Springer
Springer-Verlag London Ltd.
Verantwortliche Person für die EU: Springer Verlag GmbH, Tiergartenstr. 17, D-69121 Heidelberg, juergen.hartmann@springer.com
Maße: 235 x 155 x 26 mm
Von/Mit: Anthony Sammes (u. a.)
Erscheinungsdatum: 13.10.2010
Gewicht: 0,715 kg
Artikel-ID: 107145540