ITSY-2343 Computer System Forensics


Philip Cupina

Credit Summer 2023


Section(s)

ITSY-2343-001 (64004)
LEC MW 6:05pm - 8:20pm DIL DLS DIL

LAB MW 8:20pm - 9:05pm DIL DLS DIL

Course Requirements

Pre-requisite:  ITSY 2342

Acquires and evaluates information

Interprets and communicates information

Uses computers to process information

Participates as a member of a team: Contributes to group effort

Monitors and corrects performance: Distinguishes trends, predicts impacts on system operations, diagnoses systems performance, and corrects malfunctions

Improves or Designs Systems: Suggests modifications to existing systems and develops new or alternative systems to improve performance

Selects technology: Chooses procedures, tools, or equipment, including computers and related technologies

Applies technology to task: Understands overall intent and proper procedures for setup and operation of

Maintains and troubleshoots equipment: Prevents, identifies, or solves problems with equipment, including computers and other technologies

Reading: Locates, understands, and interprets written information in prose and in documents such as manuals

Arithmetic: Performs basic computations; uses basic numerical concepts such as whole numbers, etc.

Listening: Receives, attends to, interprets, and responds to verbal messages and other cues

Problem solving: Recognizes problems and devises and implements plan of action.

Seeing Things in the Mind’s Eye: Organizes and processes symbols, pictures, graphs, objects and other

Knowing how to learn: Uses efficient learning techniques to acquire and apply new knowledge and skills.

Reasoning:  Discovering  a rule or principle underlying the relationship between two or more objects and applies it

Responsibility Exerts a high level of effort and perseveres towards goal attainment

Self-Esteem: Believes in own self-worth and maintains a positive view of self.

Social ability: Demonstrate understanding, friendliness, adaptability, empathy, and politeness in group settings.


Readings

EnCE The Official EnCase Certified Examiner study guide 3rd Edition Steve Bunting, EnCE, CCFT

ISBN- 978-0-470-90106-9


Course Subjects

In-depth study of system forensics including methodologies used for analysis of computer security breaches. Gather and evaluate evidence to perform postmortem analysis of a security breach. This course will progress through what a typical computer forensics analyst performs during an investigation. We will be covering hardware, files systems, advanced EnCase concepts, file signature and hash analysis.


Student Learning Outcomes/Learning Objectives

  1. Understand computer boot process, mechanics of FAT and NTFS file systems, and disk partitions
  2. Describe first response actions
  3. Acquire digital evidence
  4. Comprehend EnCase operation and use it for forensics purposes
  5. Describe advanced EnCase features
  6. Perform data searches and bookmarking
  7. Perform signature analysis and hash analysis
  8. List, describe, and access Windows artifacts
  9. Create reports

Schedule

ITSY  2343 Schedule
Dates are subject to change
The Instructor Reserves the Right to Make Schedule Changes

Week 1

May 31

Introduction to the course
Explanation and Discussion of Syllabus

Fill out Computer Studies Student Information Form

Lab 1 : Installing EnCase

Read Chapter 1, 2
 

Week 2

June 5, 7

Mon - Lecture chapter 1 Computer Hardware

Wed - Lecture Chapter 2 File Systems, MBR

Quiz chap. 1 & 2

Lab #1, 2

Read Chapter 3,4

Turn in Chapter 1 & 2 Homework

 

Week 3

June 12, 14

Mon - Lecture: Chapter 3 First Response

Wed - Lecture:  Chapter  4: Acquiring Digital Evidence

Lab Chapter 3,4

Quiz Chapter 3, 4

Read Chapter 5, 6

Turn in Chapter 3, 4 Homework

 

Week 4

June 19, 21

Review for Exam #1 Chapters 1-4

Continue with Labs

Exam #1 (Wednesday)

Review Chapters 1- 4

Read Chapter 5, 6

 

Week 5

June 26, 28

Mon - Lecture: Chapter 5  EnCase Concepts Wed - Lecture:  Chapter 6- EnCase Environment

Lab Chapter 5 & 6

Quiz Chapter 5, 6

Read Chapter 7

Turn in Chapter 5, 6 Homework

 

Week 6

July 3, 5

Mon -Lecture: Chapter 7 Understanding, Searching For, and Bookmarking Data

Quiz Chapter 7

Wed – Corporate crimes (not in book)

Wed - Review for Exam #2,  Lab #7

 

Read Chapter 8

Turn in Chapter 7 Homework

 

 

Week 7

July 10, 12

Mon - Exam #2 Chapters 5-7

Wed – Chapter 8 File Signature Analysis and Hash analysis

Quiz chapter 8, Lab chapter 8

 

Read Chapter 9

Turn in Chapter 8 Homework

Week 8

July 17, 19

Mon - Lecture:  Chapter 9 Windows Operating System Artifacts

Quiz Chapter 9

Lab Chapter 9

 

Read Chapter 10

Turn in Chapter 9 Homework

Week 9

July 24, 26

Mon - Lecture: Chapter 10 Advanced EnCase

Quiz Chapter 10

Lab Chapter 10, Review for Exam #3

 

Wed - Exam # 3 Chapters 8-10

Re-read Chapters 8-10

Turn in Chapter 10 Homework

 

 

 


Office Hours

M W 12:10 PM - 12:40 PM Online in classroom

NOTE

M W 5:35 PM - 6:10 PM Online

NOTE Or by appointment

Published: 05/29/2023 07:51:00