
CyberForensics 58
brothke writes "CyberForensics: Understanding Information Security Investigations is a new book written by a cast of industry all-stars. The book takes a broad look at cyberforensics with various case studies. Each of the book's 10 chapters takes a different approach to the topic. The book is meant to be a source guide to the core ideas on cyberforensics." Read on for the rest of Ben's review.
The book notes that there is a cohesive set of concepts that binds cybersecurity investigators to a shared vision, of which is tries to be a source to. But at 150 pages, while all of the chapters are well-written and enlightening, the book does not have the breadth and depth needed to be a single source of all things cyberforensics.CyberForensics: Understanding Information Security | |
author | Jennifer Bayuk (Editor) |
pages | 167 |
publisher | Humana Press |
rating | 8/10 |
reviewer | Ben Rothke |
ISBN | 978-1607617716 |
summary | New book written by a cast of industry all-stars |
Jennifer Bayuk is the books editor, who also wrote the introduction. I reviewed two of Bayuk's books on this site, Stepping Through the InfoSec Program and Enterprise Security For the Executive. Bayuk's introduction provides a historical background to the subject and puts things into context. The chapter uses a fantastic visual tool to explain the complete cyberforensic framework.
Chapter 2 is about the Complex World of Corporate CyberForencisc Investigations, and does a good job of detailing the various elements involved in getting various corporate departments integrated during an investigation. IT in an enterprise setting is fraught with challenges. Performing a forensic investigation in enterprise IT is even more challenging. Often these groups have different agendas and react quite different to a forensic event. The author uses the analogy of a puzzle, which can be complex to put together, but is challenging and necessary nonetheless.
Many of the chapters take a broader view of the topic, while others are quite detailed. Perhaps the best chapter in the book is chapter 6 – Analyzing Malicious Software from Lenny Zeltser. The chapter is an outgrowth of Zeltser's SANS Security 569 course on the topic. The chapter use of a case study to detail the behaviors analysis of malicious code provides an excellent synopsis of how to analyze and debug malicious code.
Chapter 7 on Network Packet Forensics from Eddie Schwartz is another exceptional chapter that provides the reader with a walk-through of using various digital forensic input to solve an incident.
Chapter 10 in Cybercrime and Law Enforcement Cooperation is about how to interface with law enforcement during a cyberforensic investigation. This may be the Achilles heel of forensics is that getting external cooperation is difficult at best, and often impossible. A recent example of this is when a friend of mine who had detailed information about the source of the Stuxnet worm. He attempted to share the information with law enforcement without much success. The various organizations were not receptive to it and didn't to take action on his well-researched claims.
The book is written for an experienced practitioner who wants an overview of current trends. This is not a for dummies type of book. Readers are expected to be comfortable with varied topics such as Wireshark packet capture, code analysis, investigations, and more. Those looking for an introduction to cyberforensics should definitely consider another title such as Computer Forensics for Dummies.
A problem with books of collaborations such as this is that they often lack a consistent stream of thought. This book is suffers from that, but to a limited degree. It is impossible for ten different authors wring about the same subject not to have different styles. An example of that is the use of the spelling of both CyberForensics and Cyberforensics in the book.
At 150 pages, the book is a relatively quick initial read, and covers numerous interesting areas.
The only downside to the book is that it has a prohibitive list price of $189.00 A month after its release, that price may be the reason why it has an Amazon Bestsellers Rank of #1,399,835.
While the book has excellent content, its exorbitant price will simply ensure that its sales will be eclipsed by the Pocket Oxford Latin Dictionary, coming in way ahead with an Amazon Bestsellers Rank of 182,392.
Ben Rothke is the author of Computer Security: 20 Things Every Employee Should Know.
You can purchase CyberForensics: Understanding Information Security from amazon.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page.
CyberPriceGouging (Score:4, Funny)
Re: (Score:2, Informative)
Costs more $ than it has pages, LOL!!
Re: (Score:2)
We now return to the very recent slashdot story about the epic fail of college bookstores trying to charge more per page than the college library charges for photocopying service.
All they need to do is add enough fluff to get the book below 10 cents per page. Aren't editors good for anything anymore? If the dumbest spammers can figure out how to insert nonsense into email spam, how come book editors can't figure it out?
Re: (Score:1)
Re: (Score:2)
nope, inkjet ink! 8000 a gallon!
So they printed it white on black?
Re: (Score:3, Insightful)
Must be a college textbook. They'll really rape you on those.
Re: (Score:2)
this isn't a set of lock picks, an assault rifle or a hazardous chemical, its something that can be digitised and distributed pretty easily, and at 150 pages even in a huge pdf it'd probably take between 5 and 10 seconds on a slow broadband link.
so the idea that the "good" guys are going through training programs the "bad guys" aren't privvy to the informatio
Re: (Score:1)
Well, it did receive the highly coveted and unique 8 out of 10 review score on Slashdot...
I keed, I keed :-)
Re: (Score:3, Informative)
Cyber? Really? (Score:2)
Re: (Score:2)
Re: (Score:2)
Oh, its technology, just 1940s technology. I think laundry "soaps" have been sulfonate detergents since the earliest days of the baby boom at the latest.
Re: (Score:2)
Alkali metal salts of fatty acids were new once. Before that it was just water, maybe with some herbs in it - IIRC lavender gets its name because it's a mild detergent.
So in a way everything's "technology", even a sharpened rock. Therefore nothing is, and the term is meaningless.
Re: (Score:2)
Any term or word tagged with the prefix "cyber" reeks of ignorance and opportunism. So thanks but no thanks, for this book.
That is a disingenuous statement (or perhaps a bit snobbish).
Or perhaps you never heard the adage, "Never judge a book by its cover."
If you had been open-minded and fair, and genuinely interested in the subject matter (rather than making a juvenile comment), you would have taken the time to look at the free preview provided by Amazon, in particular the Foreward, you would have discovered their reasoning (emphasis added):
Cyberforensics is a fairly new word in the technology [of***] our industry, but one that nevertheless has immediately recognizable meaning. Although the word forensics may have its origins in formal debates using evidence, it is now closely associated with investigation into evidence of crime. As the word cyber has become synonymous with the use of electronic technology, the word cyberforensics bears no mystery. It immediately conveys a serious and concentrated endeavor to identify the evidence of crimes or other attacks committed in cyberspace.
*** Oh, for goodness sake, a typo in the first sentence of a $189 book!
Re: (Score:2, Funny)
Use of electronic technology, eh? In that case, I, a cyberuser here on this cyberwebsite, am glad this cyberreview was posted today. I and other cyberusers can make cybercomments in this cyberdiscussion about the cyberreview. We can even benefit from the cybermoderation system that allows cybermoderators to cybermod cyberposts up and down.
Re: (Score:2)
Re: (Score:1)
Re: (Score:2)
Oh, for goodness sake, a typo in the first sentence of a $189 book!
Its only $189 instead of $190 for a reason, you know.
Re: (Score:2)
Re: (Score:2)
Did they call it that, or have you just been hoist with your own petard?
Re: (Score:2)
Re: (Score:2)
I was about to say that the military also use the term, but I guess you have that covered with "ignorance" :)
Re: (Score:2)
Look on the bright side - at least it's not an e-i-nano-mashup, and it doesn't have 2.0 on the end. That'd be so exponentially annoying it would literally make my head explode.
ECONOFORENSICS (Score:2)
Perhaps I will just download a cybercopy with LimeWire. Oh wait.
Re: (Score:2)
A very controversial field (Score:3, Funny)
Re: (Score:1)
At that price, the book hardly can make a contribution to public debate.
Grammar Police (Score:1)
Re: (Score:1)
Re: (Score:2)
The book notes that there is a cohesive set of concepts that binds cybersecurity investigators to a shared vision, of which is tries to be a source to.
(My emphasis...)
Paging David Caruso (Score:4, Funny)
Ah, the Internet... where men are men, women are men...
(puts on glasses)
... and children are FBI agents.
Re: (Score:1)
Ah, the Internet... where men are men, women are men...
(puts on glasses)
... and children are FBI agents.
Well, do not exaggerate! There is also pleasant exceptions.
OmgWtfCamelCase (Score:1, Funny)
iDon't earn enough CyberMoney to e-waste it on this NetBook.
Price due to 13 authors; more of a White Paper (Score:3, Insightful)
Given that the list of contributors includes 13 industry experts in this field, it is grossly unrealistic to expect this book to retail for the normal $34.95 (or whatever the normal price is). I don't know what the net profit is for a $34.95 book, but consider: would you be willing to invest YOUR time for just 1/13 of it? I wouldn't.
In terms of pricing and content, one should thus consider this more of a White Paper.
I for one am delighted at this collaboration -- each expert given an opportunity to write about their specialty.
Otherwise (individually) they could not (or more likely, would not) have written a book on their own.
Re: (Score:3, Insightful)
but consider: would you be willing to invest YOUR time for just 1/13 of it? I wouldn't.
Yet they only did 1/13th of the work... seems fair.
Also, the vanity press market-segment disagrees with your assessment that no "expert" would write a book for free.
In terms of pricing and content, one should thus consider this more of a White Paper.
Isn't marketing spam supposed to be free?
Re: (Score:2)
Yet they only did 1/13th of the work... seems fair.
Yes; I realized that afterward.
I am not familiar with the "vanity press market-segment" so I have no comment.
Isn't marketing spam supposed to be free?
I have not seen the actual content so I can't comment on this. Have you seen the content? And if not, why would you presume it's marketing spam?
Re: (Score:2)
Re: (Score:2)
Forward? Foreward?
Good one! "Forward by Amit Yoran" HA!
Yes, this book is riddled with typos.
You ask and you receive (Score:1)
"A consistent stream of thought" (Score:2)
A problem with this reviews is it lacks a consistent stream of thought. I know that this is
I call "bullshit!" on Amazon! (Score:2)
The original review had the Amazon Bestsellers Rank at #1,399,835.
Earlier today when I looked at the rating it had gone down to #1,6xx,xxx
And just now when I looked at it, it's at #40,592 !
What changed? Well, a review by brothke's was posted at the site (four stars) and /. readers had simply looked at the page.
I call "BULLSHIT!" on Amazon!
Google says 450 pages (Score:2)
I'm not sure where they got their page count info from. Google shows it is 450 pages long:
Google Shopping [google.com].