联系我们: 手动添加方式: 微信>添加朋友>企业微信联系人>13262280223 或者 QQ: 1483266981
Department of Computer Science
COMP343 Individual coursework
Assignment 2- Essay
1 Overall marking scheme
The coursework for COMP343 consists of Two assignments, contributing to 30% of the final
mark. The contribution of the single assignments is as follows:
Assignment 1 15%
Assignment 2 15%
TOTAL 30%
Failure in any assignment may be compensated for by higher marks in other components of
the module.
This document describes Assignment 2. Assignment 2 will be marked according to the
following broad criteria:
correctness of the arguments.
presence/absence of the evidence on the experiments.
original contribution either in implementation, or analysis.
The end of this document contains complete marking descriptors.
2 Aims of Assignment 2
Demonstrate a systematic and thorough understanding of the theoretical concepts,
processes and role of a computer forensics investigator in the organization and law
enforcement.
Ability to select appropriate tools and techniques to analyse material from a range of
sources
2
Demonstrating a critical awareness of issues and requirements for dealing with evidence.
Demonstrate a critical awareness of issues and requirements when analysing and
evaluating physical and forensic computing data evidence.
3 A Critical analysis of forensic methodology
Produce an Essay that focuses on a particular forensic investigation methodology – this
method should be critically analysed for its suitability for law enforcement and use in a
commercial environment, you may wish to also debate its suitability for other environments.
The Essay should be between 3000-4000 words and the structure can (optional) be:
1. Title page
2. Abstract
3. Introduction
4. Background and Literature Review (at least 7 academic references)
5. Method(s) (or Methodology)
6. Findings and Discussion (Critical Analysis or Interpretation)
7. Conclusions and Recommendations
8. References
9. Appendices (optional)
You may choose to either:
– investigate volatile vs persistent (non-volatile) digital evidence handling process.
or
– one of the following forensic Process models:
1. Framework for a Digital Investigation (Kohn, et al., 2006)
2. The Four Step Forensic Process (Kent, et al., 2006)
3. FORZA – Digital forensics investigation framework (Ieong, 2006)
4. Process Flows for Cyber Forensics Training and Operations (Venter, 2006)
5. The Common Process Model (Freiling & Schwittay, (2007)
6. The Two-Dimensional Evidence Reliability Amplification Process Model (Khatir, et
al., 2008)
7. The Systematic Digital Forensic Investigation Model (SRDFIM) (Agarwal, et al., 2011)
3
8. The Advanced Data Acquisition Model (ADAM): A process model for digital forensic
practice (Adams, 2012)
4 Useful Links
Study Skills Guidance Academic: https://liverpool.instructure.com/courses/24284
Writing guide: https://liverpool.instructure.com/courses/24284/pages/academic-writing
5 Submission
You need to submit:
Report (in *.pdf, *.doc,or *.docx format)
The work must be submitted electronically via the Electronic Coursework Submission
System. This must be done by
17.00 on Monday, 29th April 2024
Please be aware of the standard University policies on plagiarism, collusion and fabricated
data in Section 9 and on late submission Section 6, CoPA. Are applied to this assignment.


发表评论