Reference no: EM133759666
DIGITAL FORENSICS
Learning Outcome 1: Apply procedures, theories and techniques of digital forensics
Learning Outcome 2: Demonstrate forensic examination skills on a variety of devices, operating systems, and technologies
Learning Outcome 3: Compare the effectiveness of digital forensic tools based on the requirements of the digital crime
Learning Outcome 4: Assemble forensic reports based on digital evidence according to the digital security practices in industry
Learning Outcome 5: Evaluate ethical and legal considerations involved in the profession of computer forensics
Assessment 1
Purpose: Weekly tutorial exercises are designed to encourage engagement and reinforce the knowledge presented in the lectures. They will help students to enhance theoretical and practical skills in digital forensics.
Task Details: Complete the weekly tutorial exercises that encompass a range of topics related to digital forensics. The exercises will simulate real-world scenarios to ensure practical proficiency
Assessment 2
Purpose: The purpose of this assignment is to assess the students' knowledge on forensics tools and ethical Considerations in Digital Forensics Investigations. Students need to write a report on this task.
Assessment topic: Forensics tools and ethical Considerations in Digital Forensics Investigations
Task Details: Cyber-enabled crimes are proliferating, necessitating law enforcement to expand their investigative activities into the digital realm. The field of digital forensics has evolved significantly to unearth evidence crucial for prosecuting cyber criminals in a court of law. However, this surge in investigative capabilities has raised ethical concerns pertaining to organizational rights, individual privacy, and societal perceptions of justice. In this research assignment, students are tasked with critically analysing the ethical considerations associated with untrammelled digital forensics investigations. Additionally, students will explore the use of digital forensics tools in addressing these concerns.
Introduction:
Provide a succinct overview of the increasing prevalence of cyber-enabled crimes and the corresponding rise in digital forensics investigations.
Introduce the ethical concerns surrounding unbridled digital forensics activities on organizational, individual, and societal levels.
Literature Review:
Conduct an in-depth literature review on the evolution of digital forensics, emphasising its sophistication and its role in supporting cybercrime prosecution.
Explore existing scholarly discussions on the ethical concerns associated with digital forensics investigations.
Ethical Concerns Analysis:
Examine the potential impact of unconstrained digital forensics investigations on organizational rights, including intellectual property disclosure.
Investigate the risk of legal privacy rights violations for individuals subjected to forensic investigations.
Analyse societal concerns related to the perceived inequality in current digital forensics practices.
Digital Forensics Tools Evaluation:
Identify and evaluate digital forensics tools commonly used in investigations.
Assess how these tools may contribute to or mitigate the ethical concerns identified in the analysis.
Case Study Integration:
Integrate real-world case studies or examples illustrating instances where digital forensics investigations led to ethical dilemmas.
Analyse the outcomes and consequences of these cases in the context of organizational, individual, and societal perspectives.
Recommendations and Conclusion:
Propose ethical guidelines and considerations for conducting digital forensics investigations that balance the need for evidence with respect for rights and justice.
Conclude the research by summarizing key findings and highlighting potential areas for future exploration in the field of digital forensics ethics.
Assessment 3
Assessment type: Digital Forensic Principles and Analysis (2000 words)
Purpose: The purpose of this assignment is to assess the students' knowledge on forensics analysis.
Assessment topic: Principles of digital forensics and how machine learning can be used to enhance the digital forensics process
Task Details: Digital forensics is the practice of using scientific methods and technologies to identify, preserve, analyse, and present digital evidence in a manner that is legally acceptable. In recent years, machine learning has become an increasingly important tool in digital forensics, as it can be used to automate and enhance various tasks in the digital forensics process.
For this assignment, you will be required to explore the role of machine learning in digital forensics and how it can be applied to a case scenario. You will need to demonstrate your understanding of the theories, techniques, and procedures of digital forensics and how machine learning can be used to enhance these processes. Additionally, you will be required to demonstrate your digital forensics skills on the analysis of applying machine learning techniques to a case study.
The criteria for this assignment are as follows:
Understanding of digital forensics principles and the use of machine learning techniques: Student should demonstrate a clear understanding of machine learning and how it can be used to automate and enhance various tasks in the digital forensics process. This should include examples of how machine learning algorithms can be used to automate the analysis of data, classify digital evidence, and detect anomalies in data.
Digital forensics skills: Student should demonstrate their digital forensics skills by analysing machine learning techniques on a scenario or case study. This should include the analysis of digital evidence, the determination of its relevance and authenticity, and the presentation of findings in a clear manner.
Overall, this assignment will require you to demonstrate your understanding of the principles of digital forensics and how machine learning can be used to enhance various tasks in the digital forensics process.
Assessment 4
Assessment type: Practical and report assessment - Group assignments (2500 words)
Purpose: The primary objective of this assignment is to (i) Apply the computer forensics methodologies, (ii) Write an analysis of a case study, and (iii) Prepare an outline of a professional computer forensic plan.
Task Details: This assignment is based on the following case. Please read it carefully: M57.biz is a new company that researches patent information for clients. Facts of the case:
1 president / CEO
3 additional employees
The firm is planning to hire more employees, so they have a lot of inventory on hand (computers, printers, etc.).
Current employees:
President: Pat McGoo
Information Technology: Terry
Patent Researchers: Jo, Charlie
Employees work onsite and conduct most business exchanges over email. All the employees work in Windows environments, although each employee prefers different software (e.g. Outlook vs. Thunderbird).
One of the employees in M57 is stealing proprietary research from the company and passing it on to an outside entity. This employee has taken some measures to cover their tracks, but probably did not count on the company machines being imaged in the ongoing investigation of other criminal activity.
You are tasked with determining the following questions:
Who is exfiltrating the data?
How are they doing it? Can you identify the specific items they have stolen? What is required to access the data?
Who is the outside contact?
Is there anything in your analysis to suggest that this person might be charged with more than one criminal offense?
At the end of your investigation you should prepare a report in order to find the above questions. You must find relevant evidences after performing the investigation on the following images:
charlie-2009-12-11.E01
jo-2009-12-11-001.E01
charlie-work-usb-2009-12-11.E01
jo-work-usb-2009-12-11.E01
terry-workusb-2009-12-11.E01
Your investigation should answer questions asked in the case and formulate a conclusion. Your conclusion should be supported by your investigated evidence. Use the forensic software's you have learnt in the lab for this investigation but if require feel free to use other available forensic tools available out there for free (or trial).
Instructions:
Incapacity of a computer forensics specialist, your task is to prepare a computer forensics investigation plan to enable a systematic collection of evidence and subsequent forensic analysis of the electronic and digital data. Briefly, you should discuss a general overview of the methodology that you will use and provide a reasoned argument as to why the particular methodology chosen is relevant. You should also discuss the process that you will use to collect evidence and discuss the relevant guidelines that need to be followed when collecting digital evidence.
This plan should detail the following:
Justify why the use of the digital forensic methodology and approach is warranted including appropriate procedures for the Company's investigation.
Describe the resources required to conduct a digital forensic investigation, including skill sets and the required software and hardware for the forensics team members.
Outline an approach for data/evidence identification and acquisition that should occur in order to be able to identify and review the digital evidence.
Outline an approach and steps to be taken during the analysis phase.
Develop relevant security policies for the Company.
Provide recommendations to the Company for dealing with similar future problems.
Tips for preparing your computer forensics investigative plan
In writing the computer forensics investigative plan, students need to address the following points. Do note that points listed below are not exhaustive and need to be considered as helpful tips.
Introduction: Justify a need for computer forensics methodology and consider the scope of the case including the nature of alleged misconduct leading to consideration of how electronic and digital evidence may support the investigation. The plan should consider how computer forensics differs from other techniques (such as network forensics, data recovery) and detail the overall steps for the systematic computer forensics approach.
Resource requirements: Consider the required resources and include details regarding preparation plan for evidence gathering (such as evidence forms, types, storage media and containers), forensics workstation and peripherals needed, software/tools for analysis depending on the type of evidence to be gathered including rationale for selected tools, and consideration of team member skills in digital analysis (such as OS knowledge, skills for interviewing, consultation, working as per the needs of the auditing team and understanding of law and corporate policies).
Data acquisition: Detail the approach for data acquisition including the different types of evidence that can be gathered and their source depending upon the nature of the case and scope of investigation, develop a plan for data acquisition including rationale for selected plan and contingency planning, detail type of data acquisition tools needed including rationale and an outline for the data validation & verification procedures.
Forensics analysis: Provide an outline of the forensic analysis procedures/steps depending upon the nature of evidence to be collected, and detail the validation approach. This can include techniques to counter data hiding, recovering deleted files, procedures for network and e-mail analysis. Each student need to do the analysis.
Security policies: Develop suitable security policies for the Company.
Conclusion: Provide appropriate recommendations to the Company for dealing with the problems.