Syllabuses - UG

CS459 - Digital Forensics

TIMETABLETEACHING MATERIAL
Credits20
Level4
SemesterTerm 2
AvailabilityAvailable as an optional class to participants taking UG Graduate and Degree Apprenticeship programmes, e.g. BSc Hons IT: Software Development, and BSc Hons Digital and Technology Solutions.
PrerequisitesCS354 Computer Networks or CS323 Computer Networks.
Learning Activities Breakdown12 tutorials, online study and preparation for the coursework assignment and class test.
AssessmentThe class will be assessed 40% via an individual coursework assignment and 60% via a class test.
LecturerJeff Yan

Aims and Objectives

The aim of the class is to enable participants to understand issues associated with the nature of cybercrime, digital evidence, detection methods and proof, in a variety of digital forensic contexts, including computers, networks and portable digital devices.

Learning Outcomes

After completing this class participants will be able to: 

  1. Understand the varieties and impact of cybercrime. 
  2. Understand how to undertake digital forensic examinations, where evidence is collected to support or oppose a hypothesis. 
  3. Understand the role of the file system in detecting and mapping user activity. 
  4. Understand network-based detection techniques. 
  5. Understand the nature of anti-forensics. 

Syllabus

Indicative topics 

  1. Context, Legal and Practical Considerations 
    • Cybercrime; Forensic process; Legal process and law enforcement; ACPO guidelines; Digital evidence; Incident response 
  2. Computer Forensics 
    • File Systems (File system organisation, Memory, Registry, System logs); Disk imaging; Programs and their traces; Searching and analysis; Investigative tools (Open Source and Proprietary) 
  3. Network Forensics 
    • Intrusion detection; Attack trace-back; Packet inspection; Log analysis 
  4. Anti-Forensics and Hostile Code 
  5. Other topics 
    • Mobile devices, Virtual forensics 

Recommended Reading

This list is indicative only – the class lecturer may recommend alternative reading material. Please do not purchase any of the reading material listed below until you have confirmed with the class lecturer that it will be used for this class.

Digital Forensics and Incident Response: Incident Response Techniques and Procedures to Respond to Modern Cyber Threats, 2nd Edition, Johansen, Gerard, 2020, ISBN: 9781838649005, Packt Publishing, Limited 

Last updated: 2022-12-15 15:08:42