• No results found

Advanced Digital Forensics ITP 475 (4 Units)

N/A
N/A
Protected

Academic year: 2021

Share "Advanced Digital Forensics ITP 475 (4 Units)"

Copied!
6
0
0

Loading.... (view fulltext now)

Full text

(1)

Advanced Digital Forensics

ITP 475 (4 Units)

Description In 2007, the FBI reported that over 200 major companies reported a loss

of over 60 million dollars due to computer crime. Computers are

becoming more of a threat today than ever before. From cyber-terrorism to identity theft, the digital age has brought about a change in the way that crime is being committed. The usage of computers in crime has led to the emerging field of computer forensics.

This course is designed as an advanced course in computer forensics focusing on Windows systems. According to marketshare.hitslink.com, Windows still comprises over 85% of operating systems used worldwide. The course assumes that students have either satisfied the prerequisite of ITP 375 – Digital Forensics, or instructor approval. Students will engage in advanced topics in windows operating system analysis, including Windows Server, Exchange Server, and IIS servers.

Objective Upon completing this course, students will:

-

Be able to investigate Windows workstations and Servers

-

Understand how the Windows Operating system works for the purposes of collecting evidence

-

Understand Windows file systems, FAT and NTFS

-

Research upcoming topics in digital forensics

-

Complete a variety of case studies in digital forensics

Prerequisites/ Recommended

Preparation ITP 375 or Department Approval Instructor Joseph Greenfield

Contacting the

Instructor [email protected] | 213-740-4542 Office Hours Monday & Wednesday, 9:00 – 10:00

Tuesday & Thursday, 3:00 – 5:00

Office Location OHE 412

Lecture/Lab Tuesday & Thursday, 5:00 – 6:50 Required

Textbooks Windows Forensic Analysis, DVD Toolkit, 2nd Edition. Carvey ISBN: 1597494224

Recommended Textbook

Hacking Exposed Computer Forensics, Second Edition ISBN: 0071626778

Web Site All course material will be on Blackboard at blackboard.usc.edu Grading Grading will be based on percentages earned in assignments. The

scheduled class time will involve a combination of lectures and structured labs. Students are expected to spend time at home completing the assignments.

Labs & Cases 75%

Final Case 25%

(2)

Grading Scale The following is the grading scale to be used for the final grades at the

end of the semester 93% and above A 90% – 93% A- 87% – 90% B+ 83% – 87% B 80% – 83% B- 77% – 80% C+ 73% - 77% C 70% – 73% C- 67% – 70% D+ 63% – 67% D 60% – 63% D- Below 60% F

Policies - Projects turned in after the deadline will automatically have 5%

deducted per day. Projects will not be accepted after 1 week beyond the project’s deadline

- No make-up exams (except for medical or family emergencies) will be offered nor will there be any changes made to the Final Exam

schedule.

- It is your responsibility to submit your project on or before the due date. It is not the responsibility of the lab assistant. Do not turn in anything to your lab assistant!

- All projects will be digitally submitted through blackboard except where specifically specified. Always keep a backup copy of your labs

Academic

Integrity The use of unauthorized material, communication with fellow students during an examination, attempting to benefit from the work of another student, and similar behavior that defeats the intent of an examination or other class work is unacceptable to the University. It is often difficult to distinguish between a culpable act and inadvertent behaviour resulting from the nervous tension accompanying examinations. When the

professor determines that a violation has occurred, appropriate action, as determined by the instructor, will be taken.

Although working together is encouraged, all work claimed as yours must in fact be your own effort. Students who plagiarize the work of other students will receive zero points and possibly be referred to Student Judicial Affairs and Community Standards (SJACS).

All students should read, understand, and abide by the University Student Conduct Code listed in SCampus, and available at:

(3)

Disabilities required to register with Disability Services and Programs (DSP) each

semester. A letter of verification for approved accommodations can be obtained from DSP. Please be sure the letter is delivered to me (or to your TA) as early in the semester as possible. DSP is located in STU 301 and is open 8:30 a.m. - 5:00 p.m., Monday through Friday. The phone number for DSP is (213) 740-0776.

(4)

Advanced Digital Forensics

ITP 475 (4 Units)

Course Outline

Outline subject to change throughout the semester

Week 1 – Digital Forensics Review

- Investigative Process

- Analysis methodologies

- Tools and techniques

Reading: Instructor Notes

Week 2 – Lab Setup and Network Overview

- Setting up the investigative software

- Establishing remote connection to server

Reading: Instructor Notes

Case 1: Windows Review (Windows standalone) case

Week 3 – FAT32 File Systems

- History & background of FAT

- Allocation Tables

- Directory Entries

- Bitmaps

- Deleted files and unallocated space

Reading: Chapter 5

Lab 1: FAT analysis

Week 4 – NTFS File Systems

- History & background of NTFS

- Master File Table (MFT)

- MFT Entries

- Deleted entries

Lab 2: NTFS analysis

Week 5 – Filesharing and Peer-to-Peer

- Popular file sharing protocols and applications

- Filesharing logs

- Network logs

- Advanced BitTorrent Analysis

Reading: Instructor Notes

Lab 3: BitTorrent Lab

Case 2: BitTorrent Case

Week 6 – Executable File Analysis

(5)

- Dynamic Analysis

- Virtualization

Reading: Chapter 6

Week 7 – Viruses, Rootkits and Rootkit Detection

- The “virus defense”

- Malware

- Rootkits

- Rootkit analysis

Reading: Chapter 7

Lab 4: Rootkits

Case 3: Compromised System Analysis

Week 8 – Advanced E-mail and Internet analysis

- Web cache, history, bookmarks, etc.

- Mail header analysis

- E-mail server analysis

- Building timelines

Case 4: Employee Investigation

Week 9 – MIDTERM

Week 10– Windows Registry

- Networking 101

o Topologies and designs

o Protocols

o Enterprise setups

- Introduction to network forensics

- Decrypting Logs!

Reading: Chapter 4

Lab 6: Registry Analysis

Week 11 – Incident Response and Live Analysis

- Live analysis of systems

- Collecting volatile data

- Analyzing Log Files

Reading: Chapters 1 & 2

Case 5: Moot court case

Week 12 – Memory Analysis

- Dumping physical memory

- Analyzing physical memory

Reading: Chapter 3

(6)

Week 13 – Court and Deposition

- The game of court

- Court documents

- Interacting with attorneys

Week 14 – Law enforcement and forensics

- Role of digital forensics in law enforcement

- Guest speakers from various agencies

Week 15 – Preparing for the final case

Week 15 – Mock Trial

References

Related documents

between the active duty locations model and the MCRC locations model, which serves as an indication that passive measures of recruiting (i.e., presence of active duty personnel

Especially for collective and organized forms of resisting video surveillance, anticipative knowledge, and experience with policing of certain protest events is required as

Week 6: Malware against Security Systems (Software Vulnerability Attacks and Analysis) Week 7: Attack Models against Security Systems – Introduction Lab #2. (Current Cyber Event

Prior to the start of the InfraWatch project, an initial monitoring applica- tion was developed, that allows the visual inspection of both video and sensor information. The

A protective role for GLUT1 is supported by the finding that peroxisome proliferator-activated receptor (PPAR) γ agonist rosiglitazone, shown to prevent kidney disease in a

If the Lord of the 3rd be that Planet who doth afflict or impedite, and he in the Ascendant or 7th house, it shall be by Brethern or Kindred; an Infortune in the 10th, notes

Column and Surface Wraps; Breakage/Shatter Resistant Glass; Window Wraps Robotic Disarm/Disable Systems (***Limited to FBI accredited, recognized Bomb squads) Support Equipment

A qualitative, explorative, descriptive, contextual, and phenomenological research design was used to explore and describe the experiences of newly employed professional