52
DIGITAL FORENSICS EXPLAINED
Determining the source of an infection can be a temporal study checking the
directory entries on files such as modified, accessed, and created times (often called
MAC times). When looking at a network of computers, the goal is to find the earliest
MAC times within the group to locate the potential initial infection location. is
can be a time-consuming and arduous process. Some ways to shorten the investigation
time would be to look for possible e-mail infection sources, shared media, and start
with those that tend to be somewhat loose in the computer practices.
Investigating the virus defense is not as difficult as it would seem. First of all, the
person claiming a virus defense would have to have a virus on his or ...