COMP40571 - Coursework 2 Referral - November 2021 - Tagged
COMP40571 - Coursework 2 Referral - November 2021 - Tagged
Work will only be accepted beyond the five working day deadline if satisfactory
evidence, for example, an NEC is provided. Any issues requiring NEC
https://ntu.ac.uk/current_students/resources/student_handbook/app
eals/index.html
If copied with the agreement of the other candidate both parties are considered
guilty of Academic Irregularity.
3
Penalties for Academic irregularities range from capped marks and zero marks
to dismissal from the course and termination of studies.
To ensure that you are not accused of plagiarism, look at the sections
on Plagiarism Support and Turnitin support.
I. Assessment Requirements
This assignment allows you to build your knowledge and critical evaluation of
computer forensics investigations. To pass the coursework you must demonstrate
your understanding of the practice of digital investigations as they are conducted
in an organisation. This is achieved through the investigation of computer-based
evidence using tools and techniques that you have been introduced to during the
module delivery. You are allowed to make use of any references during your
digital investigation but are encouraged to use academic sources such as
conference and journal papers. This is an individual coursework.
Assessment Scenario/Problem
You work for a US law enforcement agency. You have recently received a summary
report (download “Final Report – Summary”) from a forensic analyst describing how
analysis of various computing devices revealed two planned criminal offences at the
National Gallery DC. The report consists of a summary of the planned offences and of
the events leading up to them, and their discovery. It also gives brief biographies of
the people involved and lists all the files from which evidence was extracted.
Unfortunately, the forensic analyst’s services are no longer available to you after he
spent too long walking down the street staring at his cellphone. All you have is his
summary report and a draft of one of his reports on evidence from individual devices
(Carry’s phone). The case is due to come to court in late May and your boss wants the
evidence laid out in a manner that the lawyers can easily use. There is no alternative
but to re-analyse the files yourself; to extract the relevant evidence to support the
summary; and to prepare reports on data extracted from individual devices.
4
The relevant files can be downloaded from Digital Corpora » 2012 National Gallery DC Attack .
Most are too large to upload to NOW. The files that you may need to consider are:
a) Network logs
b) The email log provided by the keylogger
c) Carry’s tablet
d) Tracy’s Macbook Air (you need to download both the .E01 and the .E02 file but
you only need to open the .E01 file)
e) Tracy’s external hard drive
f) Tracy’s iPhone
You do NOT need to re-analyse Carry’s phone.
Fortunately a colleague agrees to work with you. The colleague performs some of the
analyses but asks you to answer specific questions.
No references or citations are required. There is no word limit but you are encouraged
to report all and only the findings relevant to the questions that you are asked.
5
II. Assessment Criteria
Marking criteria Exceptional Distinction Commendation Pass High fail near miss Fail
absence
ZERO Work of no merit or
Distinction
Types of evidence on Correct answers, Correct answers, very Correct or partly Some correct answers, A few correct answers, Very few or no correct
a phone excellent descriptions good descriptions correct answers, good adequate descriptions poor descriptions answers, very poor or
descriptions no descriptions.
Evidence questions Correct answers, Correct answers, very Correct or partly Some correct answers, Few correct answers, Very few or no correct
excellent reporting good reporting correct answers, good adequate reporting poor reporting answers, very poor or
reporting no reporting
Quality of the report Exceptional written Excellent written Very good written Communication shows Communication shows Inadequate
language and language and language and some clarity little clarity with some presentation;
presentation of presentation of presentation of presentation and acceptable written information can be
arguments; flawless. arguments with few arguments/evidence written language, e.g. language, e.g. major followed and
very minor structural or with some minor some errors in errors in punctuation, understood only with
typographical errors; structural or punctuation, spelling, spelling, and sentence effort.
excellent presentation typographical errors; and sentence construction; the report
and clear throughout. very good presentation construction; the report has some merit but
and clear throughout. follows a logical flow. falls marginally short of
expectations.
6
Remember to use Outlook or physical calendars to block out time between lectures
and labs to work on this coursework.
V. Moderation