DIGITAL FORENSICS
- Course
- ITSE306 - DIGITAL FORENSICS
- Department
- Information Technology Security - English - Undergraduate
- Course Type
- Course
- Status
- Required
- Language
- Turkish
- Credit
- 3
- ECTS
- 6
- T+P+L
- 3 + 0 + 0
- Course Coordinator(s)
- -
- Prerequisite
- -
Course Description
The main objective of this course is to teach students different techniques and procedures that enables them to perform digital investigation. This course focuses mainly on the analysis of physical storage media and volume analysis. It covers the major phases of digital investigation such as preservation, analysis and acquisition of artifacts that reside in hard disks and random access memory. At the completion of the course, student will be able to create a digital image of physical storage device, they will be able to recovered deleted digital information and they will be able to use common digital forensics tools. Students will also be able to analyze various cases to determine digital actions of a user and perform digital analysis of varieties of files
DIGITAL FORENSICS
Evaluation Tools (Active Term)
No evaluation items have been defined.
Course outcomes
No course outcomes have been defined yet.
Course Syllabus
| Week | Topic |
|---|---|
| Week 1 | Introduction to Digital Forensics |
| Week 2 | Fundamentals of Computer Forensics |
| Week 3 | Types of Cybercrimes |
| Week 4 | Digital Evidence and Rules of Evidence |
| Week 5 | Forensic Readiness, Business Continuity, and Laboratory Planning |
| Week 6 | Computer Forensics Investigation Process |
| Week 7 | Crime Scene and Digital Evidence Processing |
| Week 8 | Data Acquisition, Duplication, and Hashing |
| Week 9 | Hard Disks, SSDs, and File Systems |
| Week 10 | Midterm(s) |
| Week 11 | Windows Registry, Boot Process, and Disk Encryption |
| Week 12 | Autopsy and The Sleuth Kit Applications |
| Week 13 | Digital Forensics Tools and Tool Validation |
| Week 14 | Graphics Files, Image Recovery, and Steganalysis |
| Week 15 | Virtual Machine, Network, E-mail, and Social Media Forensics |
Reference Books & Course Materials
No reference books have been listed.
Learning Outcomes
- L01 Explain the fundamental concepts, scope, and importance of digital forensics in cybersecurity investigations. SOLO 4
- L02 Describe the characteristics of cybercrimes, digital evidence, and the rules of evidence used in forensic investigations. SOLO 3
- L03 Apply the main stages of the computer forensics investigation process, including crime scene handling, evidence processing, and documentation. SOLO 4
- L04 Perform data acquisition, duplication, and hashing procedures to preserve the integrity of digital evidence. SOLO 4
- L05 Analyze storage media, file systems, Windows registry, boot processes, and disk encryption artifacts during forensic examinations. SOLO 4
- L06 Apply common digital forensic tools and validation methods to recover, examine, and interpret digital artifacts. SOLO 4
- L07 Examine graphics files, deleted images, steganalysis indicators, and artifacts related to virtual machine, network, e-mail, and social media forensics. SOLO 3
- L08 Evaluate forensic practices in relation to legal, ethical, and professional responsibilities, including evidence handling, forensic readiness, and business continuity. SOLO 5
Program Outcomes
- P01 Be able to understand and apply security protocol and tools to security challenges faced in organizations
- P02 Be able to design security software to combat security issues
- P03 Be able to identify, categorize, and develop security solutions for computer orientated challenges.
- P04 Be able to demonstrate autonomy and responsibility in managing computer security projects
- P05 Be able to follow the state of the arts concepts in computer technology security
- P06 Be able to design, implement, and evaluate a computational system to meet desired security needs within realistic constraints
- P07 Be able to use appropriate security techniques, protocols, skills, and tools necessary for securing computer systems
- P08 Be able to apply effective communication skills consistent with the professional environment
- P09 Be able to apply effective collaboration skills in teamwork consistent with the professional environment
- P10 Be able to apply appropriate security technology and techniques to facilitate a safe operation in an organization
Po-Lo Matrix
| LO | P01 | P02 | P03 | P04 | P05 | P06 | P07 | P08 | P09 | P10 | Average |
|---|---|---|---|---|---|---|---|---|---|---|---|
| L01 | 2 | 1 | 2 | 0 | 3 | 1 | 2 | 1 | 0 | 2 | 1.4 |
| L02 | 3 | 1 | 3 | 0 | 3 | 2 | 2 | 4 | 0 | 2 | 2 |
| L03 | 3 | 1 | 4 | 2 | 3 | 2 | 4 | 3 | 0 | 3 | 2.5 |
| L04 | 3 | 1 | 3 | 2 | 2 | 2 | 4 | 0 | 1 | 0 | 1.8 |
| L05 | 3 | 1 | 4 | 2 | 3 | 3 | 4 | 1 | 0 | 3 | 2.4 |
| L06 | 3 | 1 | 4 | 2 | 3 | 2 | 5 | 2 | 0 | 3 | 2.5 |
| L07 | 3 | 1 | 4 | 2 | 3 | 2 | 4 | 1 | 0 | 3 | 2.3 |
| L08 | 2 | 0 | 2 | 3 | 2 | 2 | 2 | 5 | 0 | 3 | 2.1 |