Get Instant Help From 5000+ Experts For
question

Writing Get your essay and assignment written from scratch by PhD expert

Rewriting: Paraphrase or rewrite your friend's essay with similar meaning at reduced cost

Editing:Proofread your work by experts and improve grade at Lowest cost

loader
Phone no. Missing!

Enter phone no. to receive critical updates and urgent messages !

Add File

Error goes here

Files Missing!

Please upload all relevant files for quick & complete assistance.

Guaranteed Higher Grade!

Task 1: Recovering Scrambled Bits And Task 2: Digital Forensics Essay.

ITC597 Digital Forensics

7 Pages / 1,673 Words Published On: 23-11-2020

For this task, I will upload a text file with scrambled bits on the Interact site closer to the assignment due date. You will be required to restore the scrambled bits to their original order and copy the plain text in your assignment.

Deliverable: Describe the process used in restoring the scrambled bits and insert plain text in the assignment.

Task 2: Digital Forensics Report (20 Marks)

In this major task you are assumed a digital forensics investigator and asked to prepare a digital forensic report for the following scenario:  

You are investigating a possible intellectual property theft by a contract employee of Exotic Mountain Tour Service (EMTS).  EMTS has just finished an expensive marketing and customer service analysis with Superior Bicycles, LLC.  Based on this analysis, EMTS plans to release advertising for its latest tour service with a joint product marketing campaign with Superior Bicycles.  Unfortunately, EMTS suspects that a contract travel consultant, Bob Aspen, might have given sensitive marketing data to another bicycle competitor.  EMTS is under a nondisclosure agreement with Superior Bicycles and must protect this advertising campaign material.

An EMTS manager found a USB drive on the desk Bob Aspen was assigned to.  Your task is to determine whether the drive contains proprietary EMTS or Superior Bicycles data.  The EMTS manager also gives you some interesting information he gathered from the Web server administrator. EMTS filters all Web-based e-mail traffic travelling through its network and detects suspicious attachments.  When a Web-based e-mail with attachments is received, the Web filter is triggered.  The EMTS manager gives you two screen captures, shown in Figures 8-5 and 8-6 (Textbook page 327), of partial e-mails intercepted by the Web filter that lead him to believe Bob Aspen might have engaged in questionable activities.  (Nelson, Phillips, & Steuart, 2015, p. 326-327)

Deliverable: For this forensic examination, you need to search all possible places data might be hiding and submit a digital forensics report of 1800-2000 word.

Rationale

This assessment task covers data validation, e-discovery, steganography, reporting and presenting, and has been designed to ensure that you are engaging with the subject content on a regular basis. More specifically it seeks to assess your ability to:

  • determine the legal and ethical considerations for investigating and prosecuting digital crimes
  • analyse data on storage media and various file systems
  • collect electronic evidence without compromising the original data;
  • evaluate the functions and features of digital forensics equipment, the environment and the tools for a digital forensics lab;
  • compose technical tactics in digital crimes and assess the steps involved in a digital forensics investigation;
  • prepare and defend reports on the results of an investigation

Marking criteria

Task 1: Recovering scrambled bits (5 Marks) 

Criteria

HD

100% - 85%

DI

84% - 75%

CR

74% - 65%

PS

64% - 50%

FL

50% - 0

Successfully recovering the scrambled bits to their original order(5 marks)

Scrambled bits are restored to the original text. Tool used to decode the text is mentioned and justification to use the tool is also provided. The process to restore the scrambled bits is clearly described with screenshots inserted of all steps.

Scrambled bits are restored to the original text. Tool used to decode the text is mentioned but the justification is not very clear. The process to restore the scrambled bits is described with some screenshots.

Scrambled bits are restored to the original text. Tool used to decode the text is mentioned but the justification is not very clear. The process to restore the scrambled bits is described but no screenshots provided.

Scrambled bits are restored to the original text. No justification of tool used is provided, process seems to be somewhat vague. 

Scrambled bits are restored but not matching with the original text. Tool is not mentioned and process is not described.

Possible marks

5.0 – 4.25

4.24 – 3.75

3.74 – 3.25

3.24 – 2.5

2.4 – 0

Task 2: Forensics report (20 Marks) 

Criteria

HD

100% - 85%

DI

84% - 75%

CR

74% - 65%

PS

64% - 50%

FL

50% - 0

Introduction:

Background, scope of engagement, tools and findings

(3 marks)

All elements are present, well expressed, comprehensive and accurate.

All elements are present and largely accurate and well expressed.

All elements are present with few inaccuracies.

Most elements are present possibly with some inaccuracies.

Fails to satisfy minimum requirements of introduction.

Possible marks

3.0 – 2.55

2.54 – 2.25

2.24 – 1.95

1.94 – 1.5

1.4 – 0

Analysis: relevant programs, techniques, graphics

(5 marks)

 

Description of analysis is clear and appropriate programs and techniques are selected. Very good graphic image analysis.

Description of analysis is clear and mostly appropriate programs and techniques are selected. Good graphic image analysis.

Description of analysis is clear and mostly appropriate programs and techniques are selected. 

Reasonable graphic image analysis.

Description of analysis is not completely relevant. Little or no graphics image analysis provided.

Fails to satisfy minimum requirements of analysis.

Possible marks

5.0 – 4.25

4.24 – 3.75

3.74 – 3.25

3.24 – 2.5

2.4 – 0

Findings:

specific files/images, type of searches, type of evidence, indicators of ownership

(5 marks)

A greater detail of findings is provided. Keywords and string searches are listed very clearly. Evidence found is very convincing. An indication of ownership is very clear.

Findings are provided, keywords and string searchers are listed. The evidence is sound. Ownership is clear.

Findings are provided, some keywords are listed. The evidence is reasonable which relates to the ownership.

Findings are provided but are somewhat vague. Keywords

and strings are not very clear. Evidence found may be questionable.

Fails to satisfy minimum requirements providing findings.

Possible marks

5.0 – 4.25

4.24 – 3.75

3.74 – 3.25

3.24 – 2.5

2.4 – 0

Conclusion:

Summary, Results

(3 marks)

High level summary of results is provided which is consistent with the report.

Well summarised results and mostly consistent with the findings. 

Good summary of results.

Able to relate the results with findings. No new material is included.

Satisfies the minimum requirements. Results are not really consistent with the findings.

Fails to satisfy minimum requirements of summarising the results.

Possible marks

3.0 – 2.55

2.54 – 2.25

2.24 – 1.95

1.94 – 1.5

1.4 – 0

References:

Must cite references to all material used as sources for the content

(2 marks)

 

APA 6th edition referencing applied to a range of relevant resources. No referencing errors. Direct quotes used sparingly. Sources all documented.

APA 6th edition referencing applied to a range of relevant resources. No more than 2 referencing errors.

Direct quotes used sparingly. Sources all documented.

APA 6th edition referencing applied to a range of relevant resources. No more than 3 errors. Direct quotes used in-context. Sources all documented.

APA 6th edition referencing applied

to a range of relevant resources.

No more than 4 errors. Direct quotes used in-context. Some sources documented.

Referencing not done to the APA 6th edition standard. Over-use of direct quotes. Range of sources used is not appropriate and/or not documented.

Possible marks

2.0 – 1.7

1.6 – 1.5

1.4 – 1.3

1.2 – 1.0

0.9 – 0

Glossary / Appendices:

(2 marks)

Glossary of technical terms used in the report is provided which has generally acceptable source of definition of the terms and appropriate references are included. Relevant supporting material is provided in appendices to demonstrate the evidence.

Glossary of technical terms used in the report is provided which has mostly acceptable source of definition of the terms and appropriate references are included. Some supporting material is provided in appendices to demonstrate the evidence.

Glossary of some technical terms used in the report is provided which has mostly acceptable source of definition of the terms and appropriate references are included. Some supporting material is provided in appendices to demonstrate the evidence.

Glossary of some technical terms

used in the report is provided however terms are not generally common and some references are missing. Some supporting material is provided in appendices.

Most terminologies are missing. 

Appendices are either not provided or are irrelevant.

Possible marks

2.0 – 1.7

1.6 – 1.5

1.4 – 1.3

1.2 – 1.0

0.9 – 0

Presentation

The following should be included as minimum requirements in the report structure:

  • Executive Summary or Abstract
    This section provides a brief overview of the case, your involvement as an examiner, authorisation, major findings and conclusion 
    • Table of Contents
    • Introduction
    Background, scope of engagement, forensics tools used and summary of findings 
    • Analysis Conducted
    o Description of relevant programs on the examined items
    o Techniques used to hide or mask data, such as encryption, steganography, hidden attributes, hidden partitions etc
    o Graphic image analysis
    • Findings
    This section should describe in greater detail the results of the examinations and may include:
    o Specific files related to the request
    o Other files, including deleted files that support the findings
    o String searches, keyword searches, and text string searches
    o Internet-related evidence, such as Web site traffic analysis, chat logs, cache files, e-mail, and newsgroup activity
    o Indicators of ownership, which could include program registration data.
    • Conclusion 
    Summary of the report and results obtained
    • References
    You must cite references to all material you have used as sources for the content of your work
    • Glossary
    A glossary should assist the reader in understanding any technical terms used in the report. Use a generally accepted source for the definition of the terms and include appropriate references. 
    • Appendices
    You can attach any supporting material such as printouts of particular items of evidence, digital copies of evidence, and chain of custody documentation.

Follow the referencing guidelines for APA 6 as specified in .

Submit the assignment in ONE word or pdf file on TURNITIN. Please do not submit *.zip or *.rar or multiple files.

­­­­­­

Cite This Work

To export a reference to this article please select a referencing stye below:

My Assignment Help. (2020). Task 1: Recovering Scrambled Bits And Task 2: Digital Forensics Essay.. Retrieved from https://myassignmenthelp.com/free-samples/itc597-digital-forensics/investigation-process.html.

"Task 1: Recovering Scrambled Bits And Task 2: Digital Forensics Essay.." My Assignment Help, 2020, https://myassignmenthelp.com/free-samples/itc597-digital-forensics/investigation-process.html.

My Assignment Help (2020) Task 1: Recovering Scrambled Bits And Task 2: Digital Forensics Essay. [Online]. Available from: https://myassignmenthelp.com/free-samples/itc597-digital-forensics/investigation-process.html
[Accessed 22 September 2023].

My Assignment Help. 'Task 1: Recovering Scrambled Bits And Task 2: Digital Forensics Essay.' (My Assignment Help, 2020) <https://myassignmenthelp.com/free-samples/itc597-digital-forensics/investigation-process.html> accessed 22 September 2023.

My Assignment Help. Task 1: Recovering Scrambled Bits And Task 2: Digital Forensics Essay. [Internet]. My Assignment Help. 2020 [cited 22 September 2023]. Available from: https://myassignmenthelp.com/free-samples/itc597-digital-forensics/investigation-process.html.


Stuck on Any Question

Our best expert will help you with the answer of your question with best explanation.

question

Writing: Get your essay and assignment written from scratch by PhD expert

Rewriting: Paraphrase or rewrite your friend's essay with similar meaning at reduced cost

Editing: Proofread your work by experts and improve grade at Lowest cost

question
We will use e-mail only for:

arrow Communication regarding your orders

arrow To send you invoices, and other billing info

arrow To provide you with information of offers and other benefits

Phone no. Missing!

Enter phone no. to receive critical updates and urgent messages !

loader
250 words
Error goes here

Error goes here

Files Missing!

Please upload all relevant files for quick & complete assistance.

icon
5% Cashback

On APP - grab it while it lasts!

Download app now (or) Scan the QR code

*Offer eligible for first 3 orders ordered through app!

screener
ribbon
callback request mobile
Have any Query?
close
Subtraction Payment required!

Only one step away from your solution of order no.