Inhalt

[ 921NESECILV13 ] VL (*)Computer Forensics and IT Law

Versionsauswahl
(*) Leider ist diese Information in Deutsch nicht verfügbar.
Workload Ausbildungslevel Studienfachbereich VerantwortlicheR Semesterstunden Anbietende Uni
3 ECTS M1 - Master 1. Jahr Informatik Michael Sonntag 2 SSt Johannes Kepler Universität Linz
Detailinformationen
Quellcurriculum Masterstudium Computer Science 2025W
Lernergebnisse
Kompetenzen
(*)Students can assess the content of forensic reports regarding the methods employed and for selected contents. They know the limitations and can roughly assess the chances for successful investigations. They can determine whether a specific IT activity might be illegal according to Austrian criminal law.
Fertigkeiten Kenntnisse
(*)Students know on a theoretical level how to, respectively the basics steps to:

  • Create images of hard disks/SSD (K3)
  • Analyze the content of an image (K4)
  • Collect data from live systems (K3)
  • Assess the quality and evidentiary value of gathered data (K5)
  • Assess the quality of an expertise (K5)
  • Extract browsing data from disk images (K4)
  • Extract data regarding selected activities in Windows from disk images (K4)
  • Use carving software to reconstruct files/data (K3)
(*)Technical part:

  • Forensic process: how to secure evidence; requirements for forensic investigation procedures
  • Kinds and locations of IT evidence
  • Web browsing activity: location, extraction methods, interpretation limitations
  • Windows systems: location, extraction methods, interpretation limitations
  • Secure destruction of data
  • Carving: Methods and improvement for various file/content types

Legal part:

  • Expertises (structure, analysis)
  • Legal rules regarding evidence incl burden of proof
  • Criminal law in the IT area, e.g. data destruction and computer fraud
Beurteilungskriterien (*)Written exam
Lehrmethoden (*)Lecture and discussion
Abhaltungssprache Deutsch; tw. Englisch
Literatur (*)Slides
Lehrinhalte wechselnd? Nein
Sonstige Informationen (*)The accompanying exercise is OPTIONAL; it covers selected of the topics of this lecture as practical exercises. https://www.jku.at/en/institute-of-networks-and-security/
Äquivalenzen (*)INMNPVOIRCF: VO IT-Recht und Computerforensik (3 ECTS)
Präsenzlehrveranstaltung
Teilungsziffer -
Zuteilungsverfahren Direktzuteilung