티스토리 뷰

http://www.dfinews.com/blogs/2014/07/live-response-vs-traditional-forensics?et_cid=4054166&et_rid=497220977&type=cta

 

The term live response is being heard more and more frequently but what exactly is it and how does it differ from traditional forensics.
 
Live response and traditional forensics have a lot in common in that they both are looking for similar artifacts on a system. The differentiator with live response is that the artifacts are being discovered on a live running system. With traditional forensics images are taken of volatile memory and disks before being analyzed. Imaging alone can take hours and then the images need to be processed/indexed to allow for keyword searches. With a large disk obtaining and processing the image can easily take a day. With live response there is no imaging or processing that has to occur. Everything is real time. This dramatically improves the response time in identifying and quantifying a threat. And the quicker the threat is identified, the quicker it can be contained and remediated.
댓글
공지사항
최근에 올라온 글
최근에 달린 댓글
Total
Today
Yesterday
링크
«   2024/12   »
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31
글 보관함