teaching digital forensics in a large class
play

Teaching digital forensics in a large class Teaching forensics at - PowerPoint PPT Presentation

Teaching digital forensics in a large class of students Teaching digital forensics in a large class Teaching forensics at of students UL FRI Generating customized disk images Gaper Fele-or University of Ljubljana, Faculty of


  1. Teaching digital forensics in a large class of students Teaching digital forensics in a large class Teaching forensics at of students UL FRI Generating customized disk images Gašper Fele-Žorž University of Ljubljana, Faculty of Computer and Information Science polz@fri.uni-lj.si

  2. Forensics in Ljubljana at FRI Teaching digital forensics in a large class of students Teaching ◮ approx. 60 students forensics at UL FRI ◮ 6 lectures by the professor (Andrej Brodnik) ◮ 4 lectures by invited speakers ◮ 15-minute student presentations instead of 2 lectures ◮ 14 lab sessions ◮ 2 lab assignments (graded practical homework)

  3. Problem description Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ Everyone should be graded fairly ◮ Students are cooperative ◮ One person to grade them all

  4. Problem description - goals Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ Create a disk image ◮ Access the data on a disk ◮ Search for incriminating files ◮ Check file metadata

  5. Image/tool repositories Teaching digital forensics in a large class of students Teaching ◮ Computer Forensic Reference Data Sets (CFReDS) forensics at UL FRI ◮ digitalcorpora.org ◮ Lance Mueller’s Practical Exercises ◮ The International Society of Forensic Computer Examiners R � - Sample Practical Exercise

  6. Image/tool repositories Teaching digital forensics in a large class of students Teaching ◮ Computer Forensic Reference Data Sets (CFReDS) forensics at UL FRI ◮ digitalcorpora.org ◮ Lance Mueller’s Practical Exercises ◮ The International Society of Forensic Computer Examiners R � - Sample Practical Exercise ◮ forensicfocus.com/images-and-challenges

  7. D-FET Teaching digital forensics in a large class of students Teaching forensics at ◮ developed by Institute Josef Stefan UL FRI ◮ cloud-based ◮ individualized assignments for each pupil ◮ assignments created with input from law enforcement ◮ http://www.d-fet.eu/

  8. Forensic Image Generator Teaching digital forensics in a large class of students Teaching forensics at UL FRI “All the world’s a stage, And all the men and women merely players; They have their exits and their entrances, And one man in his time plays many parts, His acts being seven ages.” — William Shakespeare, As You Like It

  9. Typical assignment Teaching digital forensics in a large class of students Teaching forensics at UL FRI Find all files containing verses from the King James edition of the Bible on a set of floppy disk images

  10. An alternative Teaching digital forensics in a large class of students Teaching forensics at UL FRI A little girl has lost her pet, Sylvester. We have assembled a list of suspects whose computers we have confiscated. Find the culprit!

  11. Cases Teaching digital forensics in a large class of students Teaching forensics at UL FRI A case involves ◮ People ◮ Evidence ◮ Story (template)

  12. Persons Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ name, surname ◮ gender ◮ address, birthdate, birthplace, description, e.t.c.

  13. Roles Teaching digital forensics in a large class of students Teaching forensics at ◮ victim UL FRI ◮ perpetrator ◮ accomplice ◮ female_accomplice, male_accomplice ◮ all

  14. Files Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ different sets of files for each role ◮ some files are exclusive to one person, others can be shared with others ◮ files can be "sent" to other persons

  15. A "perp" file Teaching digital forensics in a large class of students Teaching forensics at UL FRI

  16. An "all" file Teaching digital forensics in a large class of students Teaching forensics at UL FRI

  17. Metadata Teaching digital forensics in a large class of students Teaching forensics at ◮ ODT author UL FRI ◮ ODT modification time ◮ JPEG camera type ◮ JPEG modification date ◮ Other EXIF tags

  18. Story / Case generation Teaching digital forensics in a large class of students Teaching forensics at ◮ pick a case UL FRI ◮ assign roles ◮ prepare files ◮ generate disk images ◮ pack images

  19. Metadata preparation Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ ODT: unzip, modify the XML directly, zip ◮ JPEG: pyexiv2

  20. Disk image generation Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ kpartx + mount ◮ qemu-nbd ◮ libguestfs

  21. Student reactions Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ So, who did it? ◮ We want to know the grading criteria in advance ◮ Did I find everything?

  22. Problems / downsides Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ bus factor of 1 ◮ preparing cases is relatively time-consuming ◮ the motivational improvement is unproven ◮ current cases not based on reality

  23. Future work Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ get more users ◮ create more cases ◮ use testing automation tools for image creation

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend