teaching digital forensics in a large class
play

Teaching digital forensics in a large class Teaching forensics at - PowerPoint PPT Presentation

Teaching digital forensics in a large class of students Teaching digital forensics in a large class Teaching forensics at of students UL FRI Generating customized disk images Gaper Fele-or University of Ljubljana, Faculty of


  1. Teaching digital forensics in a large class of students Teaching digital forensics in a large class Teaching forensics at of students UL FRI Generating customized disk images Gašper Fele-Žorž University of Ljubljana, Faculty of Computer and Information Science polz@fri.uni-lj.si

  2. Forensics in Ljubljana at FRI Teaching digital forensics in a large class of students Teaching ◮ approx. 60 students forensics at UL FRI ◮ 6 lectures by the professor (Andrej Brodnik) ◮ 4 lectures by invited speakers ◮ 15-minute student presentations instead of 2 lectures ◮ 14 lab sessions ◮ 2 lab assignments (graded practical homework)

  3. Problem description Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ Everyone should be graded fairly ◮ Students are cooperative ◮ One person to grade them all

  4. Problem description - goals Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ Create a disk image ◮ Access the data on a disk ◮ Search for incriminating files ◮ Check file metadata

  5. Image/tool repositories Teaching digital forensics in a large class of students Teaching ◮ Computer Forensic Reference Data Sets (CFReDS) forensics at UL FRI ◮ digitalcorpora.org ◮ Lance Mueller’s Practical Exercises ◮ The International Society of Forensic Computer Examiners R � - Sample Practical Exercise

  6. Image/tool repositories Teaching digital forensics in a large class of students Teaching ◮ Computer Forensic Reference Data Sets (CFReDS) forensics at UL FRI ◮ digitalcorpora.org ◮ Lance Mueller’s Practical Exercises ◮ The International Society of Forensic Computer Examiners R � - Sample Practical Exercise ◮ forensicfocus.com/images-and-challenges

  7. D-FET Teaching digital forensics in a large class of students Teaching forensics at ◮ developed by Institute Josef Stefan UL FRI ◮ cloud-based ◮ individualized assignments for each pupil ◮ assignments created with input from law enforcement ◮ http://www.d-fet.eu/

  8. Forensic Image Generator Teaching digital forensics in a large class of students Teaching forensics at UL FRI “All the world’s a stage, And all the men and women merely players; They have their exits and their entrances, And one man in his time plays many parts, His acts being seven ages.” — William Shakespeare, As You Like It

  9. Typical assignment Teaching digital forensics in a large class of students Teaching forensics at UL FRI Find all files containing verses from the King James edition of the Bible on a set of floppy disk images

  10. An alternative Teaching digital forensics in a large class of students Teaching forensics at UL FRI A little girl has lost her pet, Sylvester. We have assembled a list of suspects whose computers we have confiscated. Find the culprit!

  11. Cases Teaching digital forensics in a large class of students Teaching forensics at UL FRI A case involves ◮ People ◮ Evidence ◮ Story (template)

  12. Persons Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ name, surname ◮ gender ◮ address, birthdate, birthplace, description, e.t.c.

  13. Roles Teaching digital forensics in a large class of students Teaching forensics at ◮ victim UL FRI ◮ perpetrator ◮ accomplice ◮ female_accomplice, male_accomplice ◮ all

  14. Files Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ different sets of files for each role ◮ some files are exclusive to one person, others can be shared with others ◮ files can be "sent" to other persons

  15. A "perp" file Teaching digital forensics in a large class of students Teaching forensics at UL FRI

  16. An "all" file Teaching digital forensics in a large class of students Teaching forensics at UL FRI

  17. Metadata Teaching digital forensics in a large class of students Teaching forensics at ◮ ODT author UL FRI ◮ ODT modification time ◮ JPEG camera type ◮ JPEG modification date ◮ Other EXIF tags

  18. Story / Case generation Teaching digital forensics in a large class of students Teaching forensics at ◮ pick a case UL FRI ◮ assign roles ◮ prepare files ◮ generate disk images ◮ pack images

  19. Metadata preparation Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ ODT: unzip, modify the XML directly, zip ◮ JPEG: pyexiv2

  20. Disk image generation Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ kpartx + mount ◮ qemu-nbd ◮ libguestfs

  21. Student reactions Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ So, who did it? ◮ We want to know the grading criteria in advance ◮ Did I find everything?

  22. Problems / downsides Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ bus factor of 1 ◮ preparing cases is relatively time-consuming ◮ the motivational improvement is unproven ◮ current cases not based on reality

  23. Future work Teaching digital forensics in a large class of students Teaching forensics at UL FRI ◮ get more users ◮ create more cases ◮ use testing automation tools for image creation

Recommend


More recommend