0% found this document useful (0 votes)
20 views2 pages

Computer Forensics Course Overview

The document outlines a course on Computer Forensics, designed for undergraduate students, covering principles, practices, and legal considerations of digital evidence. It includes objectives such as understanding the role of forensics in legal contexts and developing practical skills in evidence analysis. Course content spans various modules, including data acquisition, platform-specific analysis, and the use of forensic tools, with a focus on ethical and legal dimensions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views2 pages

Computer Forensics Course Overview

The document outlines a course on Computer Forensics, designed for undergraduate students, covering principles, practices, and legal considerations of digital evidence. It includes objectives such as understanding the role of forensics in legal contexts and developing practical skills in evidence analysis. Course content spans various modules, including data acquisition, platform-specific analysis, and the use of forensic tools, with a focus on ethical and legal dimensions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

DFCH2153 COMPUTER FORENSICS L T P C

Version 1:1 Date of Approval: December 2023 3 0 1 4


Pre-requisites/Exposure Nil
Co-requisites

Catalog Description
This course introduces undergraduate students to the principles and practices of computer forensics. It covers the
techniques for identifying, preserving, analyzing, and reporting digital evidence in computers and digital storage
devices, with an emphasis on legal and ethical considerations.
Course Objective:
1. Understand the role of computer forensics in legal contexts.
2. Learn methods for the collection and analysis of digital evidence.
3. Develop skills in various computer forensic tools and software.
4. Gain insight into the legal and ethical dimensions of digital investigations.

Course Outcomes
On completion of this course, the students will be able to
CO1: comprehensively understand the field of computer forensics.
CO2: Become proficient in the legal and ethical considerations of computer forensics.
CO3: Ensuring meticulous evidence collection, analysis, and maintenance of the chain of custody.
CO4: Develop practical skills in acquiring, preserving, and analyzing digital evidence.

Course Contents:

Modules Blooms Number of


level* hours
Module 1: Introduction to Computer Forensics L1 8
Overview of computer forensics: Definition, scope, and importance; Types
of digital evidence and their significance in investigations; Legal aspects:
Laws governing digital evidence, ethical issues, and chain of custody
Module 2: Data Acquisition and Storage Formats L1, L2 8
Understanding Storage Formats for Digital Evidence– Raw Format,
Proprietary Formats, Advanced Forensic Formats (E01, AF, AFF4, .mdb,
.psd etc.). Tools for data imaging and duplication; Ensuring integrity of
evidence - Hashing algorithms; Securing and preserving digital evidence.
Module 3: Platform-Specific Forensic Analysis L1, L3 10
Forensic Analysis of File Systems: Windows file system -FAT12,
FAT16, FAT32 and NTFS, UNIX file Systems- EXT and Mac file
systems- APFS; Understanding digital storage devices (Hard drives,
SSDs, USBs, etc.); Basics of data organization and storage.
Module 4: Network Forensics and Advanced Analysis Techniques L2, L3 8
Basics of network forensics: concepts and tools; Techniques for
capturing and analyzing network traffic and intrusions; Advanced
forensic analysis: encrypted data, cloud storage, and mobile devices;
Dealing with anti-forensic techniques and challenges.
Module 5: Introduction to Digital Forensic Analysis Tools L3, L4 12
Overview of digital forensic analysis tools, including EnCase, FTK,
and Autopsy. Importance of system artifacts in investigations.
Exploration of common Windows and UNIX/Linux artifacts.
Concepts of file signatures and metadata, and their roles in forensic
analysis. Methods for extracting and analyzing artifacts from email
clients and web browsers.

*Bloom’s Level: L1-Knowledge; L2-Comprehension; L3-Application; L4-Analysis; L5-Synthesis, L6-


Evaluation
Suggested Readings:
1. Casey, E. (2011). "Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet" (3rd
ed.). Academic Press.
2. Carrier, B. (2005). "File System Forensic Analysis". Addison-Wesley Professional.
3. Sammons, J. (2012). "The Basics of Digital Forensics: The Primer for Getting Started in Digital Forensics".
Syngress.
4. Farmer, D., & Venema, W. (2005). "Forensic Discovery". Addison-Wesley Professional.
5. Boddington, R. (2016). "Practical Digital Forensics". Packt Publishing.
6. SANS Digital Forensics and Incident Response Blog. (n.d.). Retrieved from [Link]
[Link]/blog
7. Cyber Forensicator. (n.d.). Retrieved from [Link]
8. DFRWS - Digital Forensic Research Workshop. (n.d.). Retrieved from [Link]
9. The Sleuth Kit & Autopsy. (n.d.). Retrieved from [Link]

Modes of Evaluation: Quiz/Assignment/Seminar/Written Examination


Examination Scheme:
Components A CT S/V/Q HA EE
Weightage (%) 5 10 8 7 70
CT: Class Test, HA: Home Assignment, S/V/Q: Seminar/Viva/Quiz, EE: End Semester Examination; A: Attendance

CO, PO and PSO Mapping:

PO PO PO PO PO PO PSO PSO PSO PSO PSO


1 2 3 4 5 6 1 2 3 4 5
CO1 1 2 -- -- -- -- 1 2 - 3
CO2 1 2 -- - -- -- 1 2 - 3
CO3 1 2 -- -- -- -- 1 2 - 3
1: strongly related, 2: moderately related and 3: weakly related

You might also like