Preventing and investigating hacking by auditing web applications

Dario Valentino Forte · Network Security · 2010

One of the post mortem tasks usually conducted by forensic investigators, especially after a hacking case, is investigating how the system has been compromised and/or whether or not the system itself has been secured by the administrators. That happens especially for web applications and architectures, the most attractive targets for hackers and criminals. For this purpose, incident responders should also know about what is usually done at the Audit level. This is an important task to understand, because every information security incident should be investigated using audit techniques and double checks. This article examines why web security audit can be useful also for incident response.

Read the paper · More papers on PaperTik