Subject

Digital Forensics

1. Course Title Digital Forensics
Digital forensics
2. Code F23L3S093
3. Study Programme Security, Cryptography and Coding
4. Organizer of the study programme (unit, institute, department or division) Faculty of Computer Science and Engineering
5. Degree level (first, second, third cycle) First Cycle
6. Academic year / semester 6 / Summer
7. Number of ECTS credits 6
8. Teacher Vesna Dimitrova
9. Prerequisites for enrolling in the course Operating Systems
10. Objectives of the course programme (competences) Upon completion of the course, students will acquire knowledge of the principles and techniques required for a digital forensic investigation. Students will also gain practical experience working with various forensic tools for different operating systems.
11. Course content (1) Fundamentals of Digital Forensics, Analysis, and Post-Incident Incident Management
(1) Data System Forensics, Forensic Plan, and Technologies in Linux and Android
(1) Memory forensics on Windows systems and tools used under Windows
(1) Forensic tools for a Windows data system
(1) Data collection on Windows/Linux systems
(1) Forensic analysis of Windows using the registry and other artifacts
(1) Rootkit kernel modules
Techniques for structuring the data obtained from digital forensics and its visualization
(1) Techniques and tools for detecting money laundering and Internet crime
(1) Blockchain technology and Ethereum
(1) Using blockchain technology for forensic applications
(1) Using chain analysis to protect the integrity of digital assets.
12. Learning methods Lectures supported by slide presentations, interactive lectures, exercises (using equipment and software packages), teamwork, case studies, guest lecturers, independent preparation and defense of a project assignment and seminar paper, learning in an electronic environment (forums, consultations).
13. Total available time 6 ECTS x 30 hours = 180 hours
14. Distribution of available time 30 + 45 + 15 + 15 + 75 = 180 hours
15. Forms of teaching activities
15.1. Lectures - theoretical instruction 30 hours
15.2. Exercises (laboratory, auditory), seminars, teamwork 45 hours
16. Other forms of activities
16.1. Project assignments 15 hours
16.2. Independent assignments 15 hours
16.3. Home study 75 hours
17. Assessment method
17.1. Tests 10 points
17.2. Seminar paper / project (presentation: written and oral) 15 points
17.3. Activities and learning 10 points
17.4. Final exam 70 points
18. Grading criteria (points / grade)
up to 50 points5 (five) (F)
from 51 to 60 points6 (six) (E)
from 61 to 70 points7 (seven) (D)
from 71 to 80 points8 (eight) (C)
from 81 to 90 points9 (nine) (B)
from 91 to 100 points10 (ten) (A)
19. Requirement for obtaining a signature and taking the final exam completed activities 15.1 and 15.2
20. Language of instruction Macedonian and English
21. Method for monitoring the quality of teaching internal evaluation and survey mechanism
22. Literature
22.1. Required literature
1. John Sammons | The Basics of Digital Forensics, Second Edition: The Primer for Getting Started in Digital Forensics | Elsevier | 2014
2. Mark Gates | Blockchain: Ultimate guide to understanding blockchain, bitcoin, cryptocurrencies, smart contracts and the future of money | Amazon Digital Services LLC | 2017
3. Michael K Robinson | Digital Forensics Workbook: Hands-on Activities in Digital Forensics | CreateSpace Independent Publishing Platform | 2015
22.2. Additional literature
No. Author Title Publisher Year