MTU Cork Library Catalogue

Syndetics cover image
Image from Syndetics

Cisco router and switch forensics [electronic book] : investigating and analyzing malicious network activity / Dale Liu, lead author and technical editor ; James Burton, Tony Fowlie, Paul A. Henry, Jan Kanclirz Jr., Dave Kleiman, Thomas Millar, Kevin O’Shea, James Steele, Scott Sweitzer and Craig Wright.

Contributor(s): Liu, Dale [lead author and technical editor] | Burton, James [contributing author] | Fowlie, Tony [contributing author] | Henry, Paul A [contributing author] | Kanclirz Jr., Jan [contributing author] | Kleiman, Dave [contributing author] | Millar, Thomas [contributing author] | O’Shea, Kevin [contributing author] | Steele, James, 1971- [contributing author] | Sweitzer, Scott [contributing author] | Wright, Craig (Craig Steven) [contributing author].
Material type: materialTypeLabelBookPublisher: Burlington, Massachusetts : Syngress, [2009]Copyright date: ©2009Description: online resource (xi, 504 pages) : illustrations.Content type: text Media type: computer Carrier type: online resourceISBN: 9781597494182 (paperback); 1597494186 (paperback); 9780080953847 (e-book).Subject(s): Computer networks -- Security measures | Routers (Computer networks) | Computer crimes -- InvestigationDDC classification: 005.8 Online resources: E-book Summary: Cisco Router and Switch Forensics is the first book devoted to criminal attacks, incident response, data collection, and legal testimony on the market leader in network devices, including routers, switches, and wireless access points--Resource description page
List(s) this item appears in: E-BOOK LIST
Holdings
Item type Current library Call number Status Date due Barcode Item holds
e-BOOK MTU Bishopstown Library eBook 005.8 (Browse shelf(Opens below)) Not for loan
Total holds: 0

Enhanced descriptions from Syndetics:

Cisco IOS (the software that runs the vast majority of Cisco routers and all Cisco network switches) is the dominant routing platform on the Internet and corporate networks. This widespread distribution, as well as its architectural deficiencies, makes it a valuable target for hackers looking to attack a corporate or private network infrastructure. Compromised devices can disrupt stability, introduce malicious modification, and endanger all communication on the network. For security of the network and investigation of attacks, in-depth analysis and diagnostics are critical, but no book currently covers forensic analysis of Cisco network devices in any detail.

Cisco Router and Switch Forensics is the first book devoted to criminal attacks, incident response, data collection, and legal testimony on the market leader in network devices, including routers, switches, and wireless access points.

Why is this focus on network devices necessary? Because criminals are targeting networks, and network devices require a fundamentally different approach than the process taken with traditional forensics. By hacking a router, an attacker can bypass a network's firewalls, issue a denial of service (DoS) attack to disable the network, monitor and record all outgoing and incoming traffic, or redirect that communication anywhere they like. But capturing this criminal activity cannot be accomplished with the tools and techniques of traditional forensics. While forensic analysis of computers or other traditional media typically involves immediate shut-down of the target machine, creation of a duplicate, and analysis of static data, this process rarely recovers live system data. So, when an investigation focuses on live network activity, this traditional approach obviously fails. Investigators must recover data as it is transferred via the router or switch, because it is destroyed when the network device is powered down. In this case, following the traditional approach outlined in books on general computer forensics techniques is not only insufficient, but also essentially harmful to an investigation.

Jargon buster: A network switch is a small hardware device that joins multiple computers together within one local area network (LAN). A router is a more sophisticated network device that joins multiple wired or wireless networks together.

Description based on print version record

Includes index.

Cisco Router and Switch Forensics is the first book devoted to criminal attacks, incident response, data collection, and legal testimony on the market leader in network devices, including routers, switches, and wireless access points--Resource description page

Electronic reproduction.: ProQuest LibCentral. Mode of access: World Wide Web.

Table of contents provided by Syndetics

  • Introduction: An Overview of Cisco Router and Switch Forensics
  • Chapter 1 Digital Forensics and Analyzing Data
  • Chapter 2 Seizure of Digital Information
  • Chapter 3 The Basics of Networking
  • Chapter 4 The Language and Mindset of a Network Administrator
  • Chapter 5 Subnetting and CIDR
  • Chapter 6 Arrival on the Scene
  • Chapter 7 Diagramming the Network Infrastructure
  • Chapter 8 Cisco IOS Router Basics
  • Chapter 9 Understanding the Methods and Mindset of the Attacker
  • Chapter 10 Collecting the Non-Volatile Data from a Router
  • Chapter 11 Collecting the Volatile Data from a Router
  • Chapter 12 Cisco IOS Switch Basics
  • Chapter 13 Virtual LANs
  • Chapter 14 Collecting the Non-Volatile and Volatile Data from a Switch
  • Chapter 15 Preparing Your Report
  • Chapter 16 Preparing to Testify
  • Appendix A Cisco Wireless Device Forensics

Author notes provided by Syndetics

Dale Liu, (MCSE Security, CISSP, MCT, IAM/IEM, CCNA) has been working in the computer and networking field for over 20 years. Dale's experience ranges from programming to networking to information security and project management. He currently teaches networking, routing and security classes, while working in the field performing security audits and infrastructure design for medium to large companies.

Powered by Koha