Macintosh, OSX, & ios Forensics ITP 445 (3 Units)



Similar documents
Security and Computer Forensics ITP 477 (4 Units)

Introduction to Computer Forensics ITP 499 (3 Units)

Advanced Digital Forensics ITP 475 (4 Units)

Introduction to Information Technology ITP 101x (4 Units)

Network Security ITP 457 (4 Units)

DESIGN FOR USER EXPERIENCE (ITP 310)

Enterprise Information Systems ITP 320x (4 Units)

Data Warehouses and Business Intelligence ITP 487 (3 Units) Fall Objective

Technologies for Interactive Marketing ITP499 (4 Units)

ITP 300: Database Web Development. Database Web Development (Monday section) Fall 2012 Course Units

Social Games Workshop ITP499 (3 Units) Spring 2010 (2010-1)

Mobile App Design ITP 340x (3 Units)

Mobile Application Technologies ITP 140 (2 Units)

Interactive Web Development ITP 301 (4 Units)

Mobile Application Development ITP 342 (3 Units)

CE 460 Course Syllabus

Computer and Network Forensics INF 528 (3 Units)

Introduction to Cloud Technologies ITP 111x (2 Units)

Mobile App Project ITP 442x (4 Units)

Mobile Application Development ITP 342 (3 Units)

CE 460 Course Syllabus

3D Modeling, Animation, and Special Effects ITP 215x (2 Units)

Database Web Development ITP 300 (3 Units)

3D Modeling, Animation, Compositing, and Special Effects ITP 215x (2 Units)

Fundamentals of Computer Programming CS 101 (3 Units)

Fall Biology 2401 Human Anatomy and Physiology I Course Syllabus.

SHC Client Remote Access User Guide for Citrix & F5 VPN Edge Client

Faronics Products SYSTEM REQUIREMENTS Last modified: October 2014

COLLIN COLLEGE COURSE SYLLABUS

CIT 212 Microsoft Networking II Windows Server 2012 R2 Administration Fall 2015

Multiplayer Game Programming ITP 484x (4 Units)

Tentative: Subject to Change CHEM 205Lxg Chemical Forensics: the Science, and its Impact. Course Overview:

MUSC 4230, 5230 Technology in Music Education University of West Georgia Department of Music

Minimum Requirements for Web Based Applications

Syllabus: ECE 401 History and Foundations of Early Childhood Education Fall 2013

SAMPLE ONLY. COMM 304 Interpersonal Communication Spring 2015 Tu/Th 11:00 12:20 ANN L101

CTC 328: Computer Forensics

Syllabus -- CIS Computer Maintenance / A+ Certification

Video Game Programming ITP 380 (4 Units)

INF 203: Introduction to Network Systems (3 credit hours) Spring W1, Class number 9870

IOM433 Creative Information Systems Analysis and Design Spring 2006 T/Th 2-3:50 HOH406 (Labs meet in HOH401)

PROJECT MANAGEMENT DSO 580 Fall 2014

Please see the course lecture plan (at the end of this syllabus) for more detailed information on the topics covered and course requirements.

BUSA 501: Introduction to Business Analytics

ECON 351: Microeconomics for Business

Install and End User Reference Guide for Direct Access to Citrix Applications

NURS 529 Nursing Informatics

Lakeland Christian Academy Online Course Handbook

Carroll Hospital Center

GGR272: GEOGRAPHIC INFORMATION AND MAPPING I. Course Outline

MIS 426: Management Information Systems

Quick User Guide. The KLZ Home Page

Introduction to Java Programming ITP 109 (2 Units) Fall 2015

SOMITS is located in the 1648 Pierce Drive School of Medicine Building, Suite AB51.

GESM 160 Seminar in Quantitative Reasoning Wireless Computing Technologies for Medicine with Legal and Ethical Implications.

Remote Access End User Reference Guide for SHC Portal Access

Sage Grant Management System Requirements

Computer Virtualization (ITNW 1313) Credit: 3 semester credit hours (2 hours lecture, 4 hours lab) Prerequisite/Co-requisite: None

WBIT Human Computer Interaction. Course Syllabus

CSC 341, section 001 Principles of Operating Systems Spring 2015 Monday/Wednesday 1:00 PM 2:15 PM

HARFORD COMMUNITY COLLEGE 401 Thomas Run Road Bel Air, MD Course Outline

Outlook 2011 Setup For ITS Exchange 2010 Server Using A SOM Domain Login

AT&T Connect System Requirements for End Users v9.5. March 2013

SOC W: GLB/US Social Problems COURSE SYLLABUS Spring 2016

ipad Classroom Installation & Deployment Important information

Vanguard University of Southern California Natural Science and Mathematics


INFO 2130 Introduction to Business Computing Fall 2014

Psychological Testing (PSYCH 149) Syllabus

etroy Abnormal Psychology 3304 TERM 1, 2015

EMR Link Server Interface Installation

CJ Introduction to Criminal Justice COURSE SYLLABUS: Spring 2013

The objectives of the course are to provide students with a solid foundation in all aspects of internet marketing. Specifically my goals are:

CENTRAL TEXAS COLLEGE ITSY 2401 FIREWALLS AND NETWORK SECURITY. Semester Hours Credit: 4 INSTRUCTOR: OFFICE HOURS:

Prerequisite Math 115 with a grade of C or better, or appropriate skill level demonstrated through the Math assessment process, or by permit.

OPERATIONS, BUSINESS ANALYTICS & INFORMATION SYSTEMS

Hardware and Software Requirements. Release 7.5.x PowerSchool Student Information System

Installing and Configuring Windows Server 2012 (ITNW 1301)

It is recommended that you use a clean installation of Lion client before upgrading to Lion Server.

LanSchool 7.7. Classroom Management Software Installation Guide for the Teacher s Assistant on the ipad, iphone, ipod

Introduction to Computer Forensics Course Syllabus Spring 2012

Course Title: ITAP 3471: Web Server Management

Collin College Business and Computer Systems

ITSY1342 Section 151 (I-Net) Information Technology Security

How to configure your Desktop Computer and Mobile Devices post migrating to Microsoft Office 365

Building the High Tech Startup ITP 499x (4 Units)

PD 360 Training. Getting Started Series. PD 360 Essentials (Distance Learning) PD 360 Essentials. School Leadership and PD 360

Student Getting Started Guide

GGR272: GEOGRAPHIC INFORMATION AND MAPPING I. Course Outline

Computer Forensics (3 credit hours)

REMOTE ACCESS SERVICE SUPPORT. ICR User Support Guide

CJ 4480 Digital Forensics II Syllabus - Term

Transcription:

Macintosh, OSX, & ios Forensics ITP 445 (3 Units) Background Objective Apple Becomes World's Number One Smartphone Vendor in Q2 2011 (businesswire.com) Apple has seen its PC market share expand from 9 percent to 15 percent in just four quarters HP and Apple will fight for top position in Q4 2011. (Tim Coulling, Canalys Analysis) Once found only in classrooms and family rooms, Apple Inc. has seen significant growth with the launch of the iphone and ipad. As these mobile devices make their way into corporate offices across the globe they bring Apple OS X hardware with them. With 15% market share, Apple hardware and software is becoming a more frequent target of corporate, family, and law enforcement forensic investigations. Upon completing this course, students will: - Understand the fundamentals of computer forensics for OS X and ios systems - Understand the relationship between IT and forensics - Learn best practices for incident response of Apple hardware, software, and mobile devices including methods of acquisition - Be able to use the latest forensic tools to conduct OSX and ios investigations Prerequisites ITP 375 Instructor Pierson Clair Contacting the Instructor pclair@usc.edu Office Hours TBA Lecture/Lab TBA Required Textbooks iphone and ios Forensics: Investigation, Analysis and Mobile Security. Andrew Hoog, Katie Strzempka. June 2011. ISBN: 1597496596 Website Mac OS X, ipod, and iphone Forensic Analysis DVD Toolkit. Kubasiak, Morrissey, Varsalone. December 2008. ISBN: 1597492973 All course material will be on Blackboard at blackboard.usc.edu

Grading Grading Scale Grading will be based on percentages earned in assignments. The scheduled class time will involve a combination of lectures and structured labs. Students are expected to spend time at home completing the assignments. Labs (4) Case Practical 1 10% Case Practical 2 15% Midterm 10% Final Paper/Presentation 20% Final Exam 25% Total 100% 20% (5% each) The following is the grading scale to be used for the final grades at the end of the semester 93% and above A 90% 93% A- 87% 90% B+ 83% 87% B 80% 83% B- 77% 80% C+ 73% - 77% C 70% 73% C- 67% 70% D+ 63% 67% D 60% 63% D- Below 60% F Policies - Projects turned in after the deadline will automatically have 5% deducted per day. Projects will not be accepted after 1 week beyond the project s deadline - No make-up exams (except for medical or family emergencies) will be offered nor will there be any changes made to the Final Exam schedule. - It is your responsibility to submit your project on or before the due date. It is not the responsibility of the lab assistant. Do not turn in anything to your lab assistant! - All projects will be digitally submitted through blackboard except where specifically specified. Always keep a backup copy of your labs - 2 -

Academic Integrity The use of unauthorized material, communication with fellow students during an examination, attempting to benefit from the work of another student, and similar behavior that defeats the intent of an examination or other class work is unacceptable to the University. It is often difficult to distinguish between a culpable act and inadvertent behavior resulting from the nervous tension accompanying examinations. When the professor determines that a violation has occurred, appropriate action, as determined by the instructor, will be taken. Although working together is encouraged, all work claimed as yours must in fact be your own effort. Students who plagiarize the work of other students will receive zero points and possibly be referred to Student Judicial Affairs and Community Standards (SJACS). Students with Disabilities All students should read, understand, and abide by the University Student Conduct Code listed in Scampus, and available at: http://www.usc.edu/student-affairs/sjacs/nonacademicreview.html Any student requesting academic accommodations based on a disability is required to register with Disability Services and Programs (DSP) each semester. A letter of verification for approved accommodations can be obtained from DSP. Please be sure the letter is delivered to me (or to your TA) as early in the semester as possible. DSP is located in STU 301 and is open 8:30 a.m. 5:00 p.m., Monday through Friday. The phone number for DSP is (213) 740-0776. - 3 -

Macintosh, OSX, & ios Forensics ITP 499 (3 Units) Week 1 Forensic Review Course Outline Outline subject to change throughout the semester - Review of Forensic Methodologies - Review of Legal Requirements - Apple v Windows Reading: TBA Week 2 Introduction to Apple Hardware - Acquisition Methodologies - Apple Hardware - Partitions/HFS+/GUID/MBR - PowerPC & Intel Architecture - 32bit v 64bit Reading: Kubasiak Chapter 1 Assignment/Lab: Wireshark Packet Analysis of OSX System Week 3 Introduction of Apple Operating Systems - Leopard (10.5) - Snow Leopard (10.6) - Snow Leopard Server - Lion (10.7) - Lion Server - System 6, 7, 8, 9 - Time Stamps Readings: Kubasiak Chapter 2 http://appleexaminer.com/macsandos/opersys/opersys.html Assignment/Lab: Basic OS Information Lab Week 4 Forensic Artifacts - Initial Triage - PLists - USB Connected Devices - Connected Network Devices - Print Spool Readings: Kubasiak Chapter 3 http://appleexaminer.com/macsandos/analysis/analysis.html Assignment/Lab: Case Practical 1 Assigned - 4 -

Week 5 Securing Apple Systems - User Accounts - Firewall - Access & Network Controls - Sharing Reading: Kubasiak Chapter 4 Assignment/Lab: Image Recovery Lab Week 6 Introduction of Apple Software & Artificats - ilife Suite - iwork Suite - OS Applications (Mail, ical, Address Book, idvd, imovie) Reading: Kubasiak Chapter 5 http://appleexaminer.com/macsandos/appleapps/appleapps.html Week 7 iphone/ipad Acquisition & Midterm review Week 8 MIDTERM - Versions - Contacts - SMS/MMS - Calendar - Applications Reading: Hoog Chapters 1 and 2 http://appleexaminer.com/iphoneipad/iosanalysistools/iosanalysistool s.html Assignment/Lab: Case Practical 1 Due Week 9 Introduction of ios - Versions of ios - Contacts - SMS/MMS - Calendar - Apple Applications Reading: Hoog Chapters 3 and 4 http://appleexaminer.com/iphoneipad/idg_iphone/idg_iphone.html Assignment/Lab: Introduce Final Paper Assignment (see week 14) Week 10 ios and Mac OSX Third Party Apps - Microsoft Office - Web Browsers (Firefox, Chrome, etc) - ios Applications Reading: Hoog Chapter 5, Kubasiak Chapter 6 Assignment/Lab: Case Practical 2-5 -

Week 11 Guest Lecture/Time Machine Analysis - Snow Leopard Time Machine - Lion Time Machine - Network Time Machine with a Time Capsule or Lion Server Reading:http://appleexaminer.com/Networking/TimeMachine/TimeMac hine.html Week 12 Lion Server - Network Setup - Proper DNS Configuration - SMB - VPN - Firewall - Security Reading: TBA Assignment/Lab: Lion Server Lab Week 13 TBA Guest Lecture/Case & Lab Work Time Week 14 Final Paper Presentations Week 15 Conclusion The Final Paper assignment will allow students to gain a deeper technical understanding into a very specific part of either the Lion or Snow Leopard Operating System or a commonly installed Mac application. Alternatively an ios component may be selected. The selection will be approved by the Professor. Students may work individually or in pairs. If students elect to work in pairs, the work will be expected to be double an individual s effort. During week 14, the paper will be presented in class with individuals having up to 8 minutes to present their research and groups having up to 15 minutes to present their research. - Review for the final exam - Conclusion to the course - Completion of Case Practical 2 Final exam to be held on the date and time according to the schedule of classes, in the normal classroom - 6 -