login

Guide to integrating forensic techniques into incident response

Published 1 January 2006Open access
Karen Kent, Sébastien Chevalier, T Grance, H Dang
Citations573
View PDF

TL;DR

The guide presents forensics from an IT view, not a law enforcement view, and provides advice regarding different data sources, including files, operating systems (OS), network traffic, and applications.

Abstract

The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology. ITL's responsibilities include the development of technical, physical, administrative, and management standards and guidelines for the cost-effective security and privacy of sensitive unclassified information in Federal computer systems. This Special Publication 800-series reports on ITL's research, guidance, and outreach efforts in computer security and its collaborative activities with industry, government, and academic organizations.

Keywords

Computer Science