August 2017
Intermediate to advanced
336 pages
11h 39m
English
Examining the firewall should be a fundamental part of any network forensic analysis. Because all external traffic must come through the firewall, it is imperative that the firewall logs be examined carefully. They frequently contain valuable evidence.
A basic working understanding of firewalls is required to do proper firewall forensics. There are several ways to categorize firewalls, but there are two that are more basic than the rest: packet filtering and stateful packet inspection.
This is the most basic type of firewall. It simply filters incoming packets and either allows them entrance or denies them passage based on a set of rules. This is also referred to as a screened firewall. ...
Read now
Unlock full access