IT914
Course Name:
Digital Forensics (IT914)
Programme:
Credits (L-T-P):
Content:
Introduction to legal issues, context, and digital forensics; Stages of Forensic: acquisition or imaging of exhibits, analysis and reporting standards. Computer forensics. Network forensics: monitoring and analysis of Computer Networks, Social Network analysis for Online Forensics. Database forensics: forensic study of databases and their metadata. Investigative use of database contents, log files and in-RAM data in order to build a time-line or recover relevant information. Mobile device forensics: recovery of digital evidence or data from a mobile device. Media Analysis: disk structure, file systems (NTFS, EXT 2/3, HFS), and physical layer issues; Tools for digital forensics. Analysis Techniques: keyword searches, timelines, hidden data; Application Analysis; Network Analysis; Analysis of Cell phones, PDAs, etc.; Binary Code Analysis; Evidence: collection, preservation, testimony.