Although I read this book in 2008, I haven't had a chance to post a review. I just published my 4-star review for Patrolling Cyberspace by Howard A. Schmidt at Amazon.ca.
In this short book, the author passes on invaluable information derived from his personal experience in the field of information security. Every security professional should create a book like this and reduce the need to re-invent the wheel again and again.
In Chapter 1, the author provides a brief history of the development of Phreaks and their techniques. The author also mentions how law enforcement reacted to Phreaks and their activities. While most of us know the identity and purpose of Phreaks, knowing the history of Phreaks definitely helps us to understand the big picture. Law enforcement’s struggle to keep up with “high tech” crimes continues today.
In Chapter 2, the author talks about early computer forensics work, and how criminals try to hide their tracks. The author shows us that when an inexperienced forensic analyst overwrote the original file for an important investigation, the forensic community realized the need for a “duplicate copy” of the digital evidence to preserve the original copy.
In Chapter 3, the author provides some concrete examples of how serious and sophisticated the attacks were on the government networks (e.g. The Cuckoo’s Egg) The Morris Worm and The Rome Lab incidences are other important events in the history of information security. The motivation and mentality of hackers have been dramatically changed since the early 1980s.
The development of important cybercrime laws and acts is the subject of Chapter 4.
In Chapter 5, the author summarizes the effects of major viruses, worms or DoS attacks such as, Fluffi Bumi, MafiaBoy, The Melissa virus, The code red, Blaster, and Nimda worms. I agree with the author that it is not easy to determine whose hat is white and whose hat is black.
In Chapter 6, the author mentions that while the Internet doesn’t have any boundaries, laws and regulations do. He surveys how other nations were approached cybercrime. The U.S. has led the way to internationalize cybercrime laws.
In Chapter 7, includes following interesting quote: “We have not found any new crimes as a result of the Internet; criminals are just finding new ways to commit old crimes,” Kevin Delli-Colli. This chapter deals with how US governmental (state and local) organizations are working together to fight cybercrime. The author expresses some concerns that multiple organizations may not share the information very well in a timely manner leading to some sort of cyber catastrophe.
In Chapter 8, the author details U.S. government efforts to combine under one umbrella the fight against cybercrime. Although the U.S. government has come a long way to protect, prevent, and respond to cyber crime related incidents, the author believes that there is still some room for improvement.
Chapter 9’s Top Ten Trends impacting security are still true. The author is optimistic we can fight against cybercrime effectively and efficiently.
In this short book, the author passes on invaluable information derived from his personal experience in the field of information security. Every security professional should create a book like this and reduce the need to re-invent the wheel again and again.
In Chapter 1, the author provides a brief history of the development of Phreaks and their techniques. The author also mentions how law enforcement reacted to Phreaks and their activities. While most of us know the identity and purpose of Phreaks, knowing the history of Phreaks definitely helps us to understand the big picture. Law enforcement’s struggle to keep up with “high tech” crimes continues today.
In Chapter 2, the author talks about early computer forensics work, and how criminals try to hide their tracks. The author shows us that when an inexperienced forensic analyst overwrote the original file for an important investigation, the forensic community realized the need for a “duplicate copy” of the digital evidence to preserve the original copy.
In Chapter 3, the author provides some concrete examples of how serious and sophisticated the attacks were on the government networks (e.g. The Cuckoo’s Egg) The Morris Worm and The Rome Lab incidences are other important events in the history of information security. The motivation and mentality of hackers have been dramatically changed since the early 1980s.
The development of important cybercrime laws and acts is the subject of Chapter 4.
In Chapter 5, the author summarizes the effects of major viruses, worms or DoS attacks such as, Fluffi Bumi, MafiaBoy, The Melissa virus, The code red, Blaster, and Nimda worms. I agree with the author that it is not easy to determine whose hat is white and whose hat is black.
In Chapter 6, the author mentions that while the Internet doesn’t have any boundaries, laws and regulations do. He surveys how other nations were approached cybercrime. The U.S. has led the way to internationalize cybercrime laws.
In Chapter 7, includes following interesting quote: “We have not found any new crimes as a result of the Internet; criminals are just finding new ways to commit old crimes,” Kevin Delli-Colli. This chapter deals with how US governmental (state and local) organizations are working together to fight cybercrime. The author expresses some concerns that multiple organizations may not share the information very well in a timely manner leading to some sort of cyber catastrophe.
In Chapter 8, the author details U.S. government efforts to combine under one umbrella the fight against cybercrime. Although the U.S. government has come a long way to protect, prevent, and respond to cyber crime related incidents, the author believes that there is still some room for improvement.
Chapter 9’s Top Ten Trends impacting security are still true. The author is optimistic we can fight against cybercrime effectively and efficiently.
No comments:
Post a Comment