Database forensics: Difference between revisions

Content deleted Content added
m Typo fixing per WP:HYPHEN, sub-subsection 3, points 3,4,5, replaced: well known → well-known using AWB (8046)
m ISBNs (Build KC)
Line 10:
 
Currently many database software tools are in general not reliable and precise enough to be used for forensic work as demonstrated in the first paper published on database forensics.<ref>[http://www.giac.org/certified_professionals/practicals/gcfa/0159.php Oracle Database Forensics using LogMiner - GIAC Certified Student Practical<!-- Bot generated title -->]</ref>
There is currently a single book published in this field,<ref>Oracle Forensics ISBN 09776715260-9776715-2-6 (May 2008)</ref> though more are destined.<ref>Oracle Forensics Using Quisix ISBN 047019118X0-470-19118-X (Dec 2008)</ref>
Additionally there is a subsequent SQL Server forensics book by Kevvie Fowler named SQL Server Forensics which is well regarded also.<ref>SQL Server Forensics ISBN 03215443660-321-54436-6 (Dec 2008)</ref>
 
The forensic study of relational databases requires a knowledge of the standard used to encode data on the computer disk. A documentation of standards used to encode information in well-known brands of DB such as SQL Server and Oracle has been contributed to the public ___domain.<ref>[http://www.sans.org/reading_room/whitepapers/forensics/1906.php SANS Institute - Forensic Analysis of a SQL Server 2005 Database Server<!-- Bot generated title -->]</ref><ref>[http://www.databasesecurity.com/oracle-forensics.htm Oracle Forensics and Incident Response - databasesecurity.com<!-- Bot generated title -->]</ref>
Line 22:
* Fair Credit Reporting Act (FCRA) http://www.gao.gov/new.items/d06674.pdf
* Oracle Forensics In a Nutshell, Paul M. Wright (May 2007) http://www.oracleforensics.com/wordpress/wp-content/uploads/2007/03/OracleForensicsInANutshell.pdf
* Oracle Forensics, Paul Wright, Rampant Techpress, ISBN 09776715260-9776715-2-6, May 2008. http://www.rampant-books.com/book_2007_1_oracle_forensics.htm
 
== References ==