Malware Forensic Containment: Operational Tradeoffs and Evidence
Understanding Malware Forensic Containment Malware forensic containment concerns efforts to limit malicious activity while accounting for the digital evidence that may explain it. The two objectives interact. A change that interrupts an attack may alter system state, while continued operation can expose information or allow activity to spread. Containment is distinct from determining the original
Malware Forensic Containment: Operational Tradeoffs and Evidence Read More »
