A book to help you recover from an attack to your Windows software

Opinion
Aug 16, 20043 mins

* "Windows Forensics and Incident Recovery"

A fascinating new book dropped into my inbox the other day. Now before you get the wrong impression, “fascinating” in this context doesn’t mean a “page-turner” or “pot-boiler” such as “The Da Vinci Code.” Rather, I’m thinking of “fascinate” as meaning: “to render motionless, as with a fixed stare or by arousing terror or awe.” Not terror in the Stephen King sense, though. In this book, the cast of characters is all-Windows: Windows NT, Windows XP, Windows 2000 and Windows Server 2003. The plot is all about identifying and solving problems. But it’s not just another troubleshooting tome, not by a long shot.

“Windows Forensics and Incident Recovery” (Addison-Wesley, see link below) may well be the first book expressly for Windows operating systems that deals solely with finding, identifying, removing and recovering from Trojans, worms, viruses, hackers, malicious users and other deliberately provoked nasty incidents.

There are lots of Windows troubleshooting books, but they concentrate on recovering from failed hardware, faulty drivers, misconfigurations, and other accidental problems. Harlan Carvey has written a book specifically to combat the affects and after-affects of malicious operations.

Carvey begins by defining the possible bad events that can occur and leads you through development of systems and practices designed to find and identify compromised data, applications, services and files on your desktop and server machines. Carvey doesn’t leave you there, though. He goes on to show you how to isolate and remove the problem as well as what needs to be done to clean up and recover your systems. Today’s sophisticated hacks and other attacks are seldom easy to spot and remove, frequently keeping multiple images at various points around the system in order to re-inflict themselves should one instance be removed.

The author points out that, while Unix and other operating systems have a long history of forensic tools and incident recovery utilities, Windows lags behind. Still, the tools and utilities are out there and Carvey shows you where to find them.

There is, of course, the obligatory section on preventing nasty incidents, but most Windows books have those. What this one has that the others don’t is a well-designed methodology for dealing with the evil, malicious, nasty things that people can do to your computer systems. Look over the book’s Web site, read the sample chapter and thumb through the book when you visit the bookstore. While it might not be made into an exciting movie, it’s as hair-raising as a good Stephen King novel, which just might cause you to have nightmares after reading it.