It may be getting a bit long in the tooth now, published over four years ago, and things in the security world move pretty fast, so you might be wondering why you would buy such an old book. The thing is - the world of Unix security doesn't really move all that fast. Just have a read through this online version of the book, and you'll see that pretty much all of it is still just as relevant today. They discuss SATAN, which is 14 years old and counting from the date this post was published, but when you take a look at what it did, you can see that this would still be useful today. The file system basics they cover in good detail will probably always be relevant - this hasn't changed much since the dawn of Unix. Even the principles of malware analysis will stay relevant, although you will need to keep adding to your knowledge of them. After all, we've seen new viruses and trojans emerge that fool the latest scanners by employing by now age-old techniques that had been forgotten about.
This is a solid book, and a solid online resource. As the authors request - if you are thinking of printing the book out from their website, maybe you should just buy the book instead. At $32/£24, it won't break the bank, and these guys deserve your cash. It's well worth it, as it's about as condensed as such a book can be, and provides a perfect introduction to security for students - I'm astonished it wasn't on our security course reading list, so I'll certainly be recommending it to my former lecturers.
There are a few other resources listed on their site, such as the TCT, the leading toolkit for forensics analysis on *nix systems - even available as a Gentoo package, which is where I first ran into it, adding it to my short-lived Gentoo installation.
I hope you'll find this useful, interesting or both. The return on the investment of time (and possibly money) for the chapter on file system basics alone makes the effort worthwhile.
Resources:
- http://www.porcupine.org/forensics/
- Forensic Discovery (Amazon)
- Forensic Discovery (online)
0 comments:
Post a Comment
speak your mind, but keep it clean (the comment, not your mind).
no spam and no trolls please