Ziele |
(*)Students understand the basic concpets of computer forensics, its technical limitations as well as the related legal issues. They know typical problems and possess knowledge regarding securing evidence as well as extracting, observing resp. reconstructing data from various sources.
Lehrinhalte |
(*)Technical part:
- Securing evidence (imaging hard disks as well as collecting data from live systems)
- analysis of file systems (finding resp. reconstructing deleted data, carving) *recovering web browsing- and E-Mail activities
- analysis of traces in Windows systems.
Legal part:
- Expertises (structure, analysis)
- legal rules regarding evidence incl burden of proof
- criminal law in the IT area, e.g. data destruction and computer fraud.
Written exam
Lecture and discussion
Direktzuteilung |