10504186Introduction to Internet and Networking Concepts
Course Information
Description
This course provides an introduction to computer networking in the context of digital investigations. It will include a review of the Internet topology, Internet Protocol (IP) versions 4/6, Ethernet addressing schemes, researching network contact information and reputation as well as studying network communications between applications and the network. Students will learn how determine which network ports applications are using, how to scan network devices with NMAP as well as capture, view and search Internet traffic with Wireshark. This course will also review capturing computer memory and subsequently reviewing it with Volatility to learn about any past network activity. The course will cover email and web browser forensics using Encase and Paraben tools. Students will also learn background on anonymous email and web browsing as well as collecting investigative information from log files as well as basic malware identification techniques.
Total Credits
Course Competencies
-
Describe the role of network evidence in criminal and civil investigationsAssessment Strategiesby participating in the classby completing in-class and homework assignmentsby completing lab exerciseCriteriayou enter into class discussionsyou complete assignments in a timely fashionyou complete the lab exercise successfullyyou attend class regularlyyou arrive for class on timeyou listen attentively during class
-
Describe, in general, the network infrastructure that composes the InternetAssessment Strategiesby participating in the classby researching sources on the topicby writing a term paperCriteriayou enter into class discussions using course materialsyou attend class regularlyyou arrive for class on timeyou participate in class activities and labsyou listen attentively during class
-
Describe how Internet identifiers, including IP addresses, MAC addresses, hostnames, etc, can be used in investigations and limitationsAssessment Strategiesby participating in the classby completing lab exerciseCriteriayou enter into class discussionsyou complete the lab exercise successfullyyou attend class regularlyyou arrive for class on timeyou listen attentively during class
-
Perform an investigative analyses of email, web browser and other internet client applicationsAssessment Strategiesby participating in the classby completing in-class and homework assignmentsby group or self presentation on the subject material to the classCriteriayou participate in class discussion using course materialsyou complete assignments in a timely fashionyou participate equally in a group presentation on the subject matteryou attend class regularlyyou arrive for class on timeyou listen attentively during class
-
Perform basic analyses of collected network evidence including network capture files and related logs, eg web server, etc.Assessment Strategiesby participating in the classby completing in-class and homework assignmentsby completing lab exerciseCriteriayou enter into class discussionsyou complete assignments in a timely fashionyou complete the lab exercise successfullyyou attend class regularlyyou arrive for class on timeyou listen attentively during class
-
Perform information gathering with tools such as TCPview, whois, ipconfig, ping, passive DNS, netcat, nmap, windd32/64, Volatility, etcAssessment Strategiesby participating in the classby completing in-class and homework assignmentsby completing lab exerciseCriteriayou enter into class discussionsyou complete assignments in a timely fashionyou complete the lab exercise successfullyyou attend class regularlyyou arrive for class on timeyou listen attentively during class
This Outline is under development.