Title:
Malware forensics : investigating and analyzing malicious code
Author:
Aquilina, James M.
ISBN:
9781597492683
Personal Author:
Publication Information:
Burlington, MA : Syngress Pub., c2008.
Physical Description:
xxxvi, 674 p. : ill. ; 24 cm.
General Note:
Includes index.
Formerly CIP.
Contents:
Malware Incident Response: Volatile Data Collection and Examination on a Live Windows System -- Malware Incident Response: Volatile Data Collection and Examination on a Live Linux System -- Memory Forensics: Analyzing Physical and Process Memory Dumps for Malware Artifacts -- Post-Mortem Forensics: Discovering and Extracting Malware and Associated Artifacts from Windows Systems -- Post-Mortem Forensics: Discovering and Extracting Malware and Associated Artifacts from Linux Systems -- Legal Considerations -- File Identification and Profiling: Initial Analysis of a Suspect File on a Windows System -- File Identification and Profiling: Initial Analysis of a Suspect File On a Linux System -- Analysis of a Suspect Program: Windows -- Analysis of a Suspect Program: Linux.
Abstract:
"Dissecting the dark side of the Internet - with its infectious worms, botnets, rootkits, and Trojan horse programs (known as malware) - this guide details the complete process of responding to a malicious code incident, from isolating malware and testing it in a forensic lab environment, to pulling apart suspect code and investigating its origin and authors."--BOOK JACKET.