Another utility compares file extensions to the data content in order to determine if files have been camouflaged with phony file extensions. For example, an image file might be renamed as a text document and vice versa.
Network Forensics
In order to identify attacks, "network forensics" deals with the capture and inspection of packets passing through a selected node in the network. Packets can be inspected on the fly or stored on disk for later analysis. See forensically clean, slack space, write blocker, file wipe, IDS and security event management software.
NIST Phases
The National Institute of Standards and Technology "Guide to Integrating Forensic Techniques into Incident Responses" covers four phases, which are briefly summarized below. For the complete 121-page NIST publication, download draft SP 800-86 at http://csrc.nist.gov/publications/nistpubs.
1 - Collection: Identify, label, record and acquire data from possible sources, while preserving the integrity of the data.
2 - Examination: Use manual and automated methods to assess and extract data of particular interest, while preserving the integrity of the data.
3 - Analysis: Use legally justifiable methods and techniques to derive useful information.
4 - Reporting: Describe actions used, explain how tools and procedures were selected, determine what other actions need to be performed, including forensic examination of additional data sources, securing identified vulnerabilities and improving existing security controls. Recommend improvements to policies, guidelines, procedures, tools and other aspects of the forensic process.
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2008 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- Microsoft Student Technology Day UK
- Note Wednesday 1st October 2008, a little over 3 weeks away from today in your diary. Steve Ballmer, CEO of Microsoft and a whole load of influential partners and companies will be in London for the Microsoft Student Technology Day. It's a day about and for students,...
- Blog posts 2008-09-04
- What can we do better?
- I'm collecting data from teachers across my district (using a Google Form, of course), trying to get a handle on issues we still haven't addressed, ways we can use technology more effectively, and what their wishlists might be for the coming year. Here's the questionnaire that went...
- Blog posts 2008-09-04
- How plants grow under the ground
- An intercontinental team of 30 researchers composed of mathematicians, engineers, computer scientists and plant sciences researchers has developed new explanations about how root plants grow and develop. As roots provide the crops we eat with water and nutrients, it is essential to learn how they grow -- laterally. 'Lateral roots,...
- Blog posts 2008-09-04
- Wireless Access: What Price Speed
- Is Verizon missing a trick in its trench warfare with Cablevision? Or has the maverick cable operator found an Achilles heel in the telephone operator's methods of providing TV, phone and particularly Internet access to customers in the New York area – and possibly nationwide? One...
- Blog posts 2008-09-04
- Ten key differences between Linux and Windows
- Before debating the relative merits and shortcomings of Linux and Windows, it helps to understand the real distinctions between them. Before debating the relative merits and shortcomings of Linux and Windows, it helps to understand the real distinctions between them. Here are the key differences distilled into one list....
- News items 2008-09-04
- GSA L-Backup (zip)
- This backup software will guarantee that you never lose any of your important data. With its user friendly interface, the software is easy to use, yet its complexity in data handling gives it very sophisticated functionality. For added reliability, the software has a wizard which verifies each part of the...
- Software downloads 2008-09-04
- CPUOff Lite (zip)
- CPUOff Lite monitors average CPU load and initiates computer power off if the CPU load has been below 15% for 60 seconds. It can be started manually or automatically via the windows task scheduler. The program parameters are not configurable. The program normally runs in the system tray. Requires a...
- Software downloads 2008-09-04
- Certero PCMigrator (zip)
- Certero PCMigrator is a Personal, PC File Migration and Backup Tool. PCMigrator, scans your computer for different file types by extension e.g. *.doc, *.exe etc. The discovered files are then automatically compressed into a zip file and saved to a location of your choice. This version is the first release...
- Software downloads 2008-09-04
- SysReturn (zip)
- SysReturn is a software to manage publicly accessible computers, such as those in computer labs, libraries, Internet cafes, biz centers and even KIOSK machines, such as ATM in banks, home automations, unmanned advertising computers, etc. The program allows you to restore data and system automatically after a system crash, software...
- Software downloads 2008-09-04
- TechTool (exe)
- Tech Tool is a lightweight tool for Techs to get simple information about a users computer. It is a standalone EXE, so you don't have to install it. Just download and run it. It produces a log that is easy to post to a forum for a user. It is...
- Software downloads 2008-09-04
- The Virtual Filing Cabinet (msi)
- By storing your computer files with the same categories, headings & indexes as your paper files, retrieving information on your computer network can now be as organized and simple as retrieving files from your filing cabinet. The Virtual Filing Cabinet includes an Easy Print Wizard for color coded tabs, labels...
- Software downloads 2008-09-04
- Logitech tries to take network music player mainstream with Squeezebox Boom
- In the press release announcing the new Squeezebox Boom, Robin Selden, vice president and general manager of Logitech's Streaming Media business unit, says that "[t]he network music player will be the CD player of the 21st century." That may be trueeventuallybut at $299.99, the Boom probably...
- Blog posts 2008-09-03
- HP ditches the box for Walmart notebook promotion
- Which notebook would you rather buy as a consumer, one that comes home with oodles of styrofoam and cardboard and plastic. Or one that ditches the cardboard altogether and even comes with its own messenger bag for you to carry it home in? Both Hewlett-Packard and...
- Blog posts 2008-09-03
- Can Drop.io coexist with the FRCP?
- Can Drop.io coexist with the FRCP?We use moodleWe have a Moodle server setup for this very reason. We create a Moodle course for each teacher course and give the teacher the ability to administer their own course. Students can log in from home and download assignments, syllabus, etc...
- Discussion threads 2008-09-03
- Anyone bothering with client-side AV anymore?
- Anyone bothering with client-side AV anymore?God help your state’s taxpayers.God help your state’s taxpayers. Anyone who would take your view of client side protection in a school is incompetent.Since I use Linux for servers and clients...I only use ClamAV to scan inbound email.RE: Anyone bothering with client-side AV anymore?Do...
- Discussion threads 2008-09-03
- Five reasons Chrome will take over the world
- Five reasons Chrome will take over the worldFive reasons Chrome will take over the worldYou know what ZDNet needs? More articles about Chrome! 12 over the last 24 hours just isn't enough so why not add to that number.Chrome isn't taking over anything because its terribly broken. It doesn't render...
- Discussion threads 2008-09-03
- Five reasons why Chrome will crash and burn
- Google dipped its mighty toe into the increasingly crowded world of internet browsers today with the announcement of its open source offering, Chrome. After all the polished promises of a streamlined new way to tame the web, the blogosphere was ready to predict Chrome would inspire everything from the...
- News items 2008-09-03
- Windows 7: Can Microsoft get boot time to under 15 seconds?
- Windows 7: Can Microsoft get boot time to under 15 seconds?Where has this been?Oh, hello, MS, is that you? Did you remember that little OS side-project that you've had going on for a couple decades now? I'm so glad to see a renewed interest, please stick around to...
- Discussion threads 2008-09-03
- Monster power strips have monster price tags
- The makers of famously overpriced audiophile cables the wallet still pains at the sight of one, Monster has ventured into the power strip arena, and it's keeping the family reputation alive. First, the Digital Life Power Center Green Power lineup is intended for connecting your computer gear....
- Blog posts 2008-09-03
- DoS vulnerability hits Google's Chrome, crashes with all tabs
- DoS vulnerability hits Google's Chrome, crashes with all tabsChrome will have security problems, and they will NOT all of a sudden gainshare. That said, the Google brand is very powerful, and people use it every day to search, and there will be lest resistance to trying Chrome than there was...
- Discussion threads 2008-09-03
Neighboring Terms
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Access the latest Intel and industry best practices
-
Designed specifically to address the concerns of senior IT managers at organizations with more than 100 employees, the Intel Premier IT Professional Program provides best practices via local and e-Seminars and a members-only Web site.
- View the Intel Premier IT Professional web-site tour >>
- BNET Industries
- Check out BNET's newest resource for managers and executives. Need to do research on your competitors? Don't have time to read every trade pub? BNET Industries is the new source for daily news, insights, and research on 11 major industries and 9,000 public companies.
-
- The technology industry from a different angle
-
- See what's hot in the auto industry
-
- Stay on top of the energy industry




