Network Intrusion Analysis: Methodologies, Tools, and Techniques for Incident Analysis and Response

  • 3h 5m
  • Joe Fichera, Steven Bolt
  • Elsevier Science and Technology Books, Inc.
  • 2013

Nearly every business depends on its network to provide information services to carry out essential activities, and network intrusion attacks have been growing increasingly frequent and severe. When network intrusions do occur, it's imperative that a thorough and systematic analysis and investigation of the attack is conducted to determine the nature of the threat and the extent of information lost, stolen, or damaged during the attack. A thorough and timely investigation and response can serve to minimize network downtime and ensure that critical business systems are maintained in full operation.

Network Intrusion Analysis teaches the reader about the various tools and techniques to use during a network intrusion investigation. The book focuses on the methodology of an attack as well as the investigative methodology, challenges, and concerns. This is the first book that provides such a thorough analysis of network intrusion investigation and response.

Network Intrusion Analysis addresses the entire process of investigating a network intrusion by:

  • Providing a step-by-step guide to the tools and techniques used in the analysis and investigation of a network intrusion.
  • Providing real-world examples of network intrusions, along with associated workarounds.
  • Walking you through the methodology and practical steps needed to conduct a thorough intrusion investigation and incident response, including a wealth of practical, hands-on tools for incident assessment and mitigation.

About the Authors

Joe Fichera is a computer forensic leader, instructor and curriculum developer for to the Defense Cyber Investigations Training Academy. He has conducted training and spoken at several conferences, such as the Department of Defense Cyber Crime Conference and the Internet Crimes Against Children conference. He is a Certified Computer Examiner (CCE) and member of the ISFCE. He also holds EnCE, ACE, CTT+, SCNS, A+, Network+, and MCP certifications. He has over 10 years of forensic experience, 20 years of instructor experience and 15 years as a law enforcement officer.

Steven Bolt is currently a Sr. Incident Response and Forensics Team Leader for a global corporation. Previously he worked as a Security Operations Center Manager and as a Computer Forensics Leader, Instructor and course developer at the Defense Cyber Investigations Training Academy. He holds several industry certifications.

In this Book

  • Introduction
  • Intrusion Methodologies and Artifacts
  • Incident Response
  • Volatile Data Analysis
  • Network Analysis
  • Host Analysis
  • Malware Analysis
  • Reporting after Analysis