June 2012
Intermediate to advanced
576 pages
19h 10m
English
Chapter 8, “Event Log Aggregation, Correlation, and Analysis,” discusses collection and analysis of logs from various sources, including operating systems of servers and workstations (such as Windows, Linux, and UNIX), applications, network equipment, and physical devices.
Chapter 9, “Switches, Routers, and Firewalls,” studies the evidence that can be gathered from different types of network equipment and strategies for collecting it, depending on available interfaces and level of volatility.
Chapter 10, “Web Proxies,” reviews the explosion of web proxies, and how investigators can leverage these devices to collect web surfing histories and even cached copies of web objects.
Read now
Unlock full access