21.7 References

  • Here's a useful resource with some static tools for IR on Intel systems. (http://www.incident-response.org)

  • The FIRST web site, with resources on procedures for IR. (http://www.first.org/docs)

  • Handbook for Computer Security Incident Response Teams (CSIRTs). (http://www.sei.cmu.edu/ publications /documents/98. reports /98hb001/98hb001abstract.html)

  • SecurityFocus IR resource archive. (http://online.securityfocus.com/cgi-bin/sfonline/incidents_topics.pl)

  • Dave Dittrich on incident cost evaluation. (http://staff.washington.edu/dittrich/misc/faqs/incidentcosts.faq)

  • "Incident Response Procedures," by Dave Dittrich. Washington University. (http://staff.washington.edu/dittrich/talks/blackhat/blackhat/incident-response.html)

  • Computer Security Incident Response Team (CSIRT) Frequently Asked Questions (FAQ). (http://www.cert.org/csirts/csirt_faq.html)

  • Internet Storm Center. (http://isc.incidents.org)

  • CERT [3] Coordination Center. (http://www.cert.org)

    [3] Unlike the popular misconception , CERT is not a Computer Emergency Response Team (see http://www.cert.org/faq/cert_faq.html#A2).

  • Windows Internet Security: Protecting Your Critical Data , by Seth Fogie and Cyrus Peikari. Prentice Hall, 2001.

  • "How the FBI Investigates Computer Crime." (http://www.cert.org/tech_tips/FBI_investigates_crime.html)

