Course Details

Cybersecurity and computer forensics

MF0654

Course
Cybersecurity and computer forensics
Code
MF0654
Academic Year
2024/2025
Curriculum Year
2023/2024
Degree Programme
ARTIFICIAL INTELLIGENCE AND DIGITAL INNOVATION
Curriculum
A013 - Tecnologico-Informatico
Course coordinator
Credits
9
Lecture Hours
72
Scientific Disciplinary Sector (SSD)
INF/01 - Computer Science
Course Type
Single-subject learning activity
Course Delivery
OPZ - Opzionale
Year
2
Teaching period
Primo Semestre
Campus
ALESSANDRIA
Teaching language
Italian
Course Contents
The course explores the discipline of cyber security from two
complementary perspectives.
The first one is related to methodologies and techniques for the verification
of the security level attained by a computer systems, and for achieving
a suitable security level.
The second one relates to incident response procedures
after the occurrence of a security incident.
Regarding the first perspective, software vulnerabilities will be addressed
in order to acquire the necessary knowledge providing the methodological basis
for the development of the techniques that are used
for identifying any vulnerabilities that may be present in a computing system.
In particular, of "vulnerability assessment" and "penetration testing" will be dealt with.
Subsequently, assuming that, despite the adoption of measures
of security, a computer system can still be hacked (for example,
as a result of inadequate and/or erroneously implemented and/or become
obsolete security measures), the methodologies used to correctly respond to security incidents
to reconstruct the events that characterized such incidents ("Digital Forensics") will be covered.
Reference Texts
1) W.Du, Computer Security: A Hands-on Approach, 3rd Edition, ISBN: 978-17330039-5-7
2) G. Johansen, Digital Forensics and Incident Response 3rd edition, Pack Publishing, 2022, ISBN 978-1803238678
3) A. Arnes, Digital Forensics, Wiley, 2017, ISBN 978-1119262381
Learning Outcomes
Know:
• the principles of IT security of software systems and applications
• cyber attack methodologies and techniques based on related vulnerabilities
• the countermeasures that can be set up to protect against such attacks
• the methodologies and penetration testing techniques based on the attacks in question
• the methodologies and techniques for managing a computer incident
• the general principles of the methodologies, techniques and tools that allow, in the event of a computer incident, to 1) acquire digital evidence without altering or modifying the computer system on which they are located 2) ensure that the evidence acquired on another medium is identical to the original ones 3) analyze the data without altering them 4) correlate evidence of different types

Be able to:
• Describe the security requirements of a system.
• Explain the main vulnerabilities of software systems, related attacks and possible countermeasures.
• Develop code that exploits software vulnerabilities to compromise the security of a system.
• Explain the main vulnerabilities of web systems, related attacks and possible countermeasures.
• Explain the main vulnerabilities of smartphone operating systems, related attacks and possible countermeasures.
• Explain the methodologies of penetration testing, and in particular of all the steps that they involve.
Prerequisites
In-depth knowledge of the theory and operation of computer system architectures, operating systems, communication networks, and C language programming.
Teaching Methods
Lectures in which the fundamental notions are exposed, accompanied by examples.
Some exercises will also be carried out in the laboratory with which they will be applied, to simplified case studies compared to real systems,
the different techniques exposed during the lessons.
The suggested textbooks are indicated on the DIR platform and are available
of the students of the material, which follows the topics
treated in class, being of help even for those who were not present.
Assessment Methods
The exam takes place in written form, and consists of a set of questions (both open and closed) on the topics covered in the course.
There will be questions both of a theoretical-methodological nature and of an applicative nature.
The exams will take place, where possible, through the use of IT platforms.
The evaluations will be formulated by means of marks expressed out of thirty, and will be determined by evaluating the following parameters:
a) correctness and completeness of the answers given to the questions making up the exam
b) ability to discursively organize the knowledge inherent in the answers formulated for the questions of a theoretical-methodological nature, as well as the capacity for critical reasoning that is necessary to apply in the formulation of the answers to certain questions
c) ability to correctly apply theoretical-methodological concepts to the formulation of answers to applicative questions
d) quality of the exposure
e) competence in the use of the specialized vocabulary.
During the exam, the consultation of textbooks, teacher's handouts and other teaching material will not be allowed.
The results of the written tests will be communicated by sending a message on the DIR platform.
Detailed Syllabus
1. Software Security: Vulnerabilities, Attacks, and Countermeasures.
1.1 Buffer Overflow vulnerability and attack
1.2 Return-to-libc attack
1.3 Format String vulnerability and attack
2. Web Security: Vulnerabilities, Attacks, and Coutermeasures
2.1 Same Origin Policy
2.2 Cross-Site Scripting Attack
2.3 Cross-Site Request Forgerty Attack
2.4 SQL-Injection Attack
2.5 Click-Jacking Attack
3. Vulnerability assessment e penetration testing
4. Incident Response: methodologies, techniques, and tools.
5. Digital Forensics
5.1 Digital Evidence: properties and acquisition techniques
5.1: Acquisition of evidence from computers, mobile devices, network devices
5.2: Analysis of digital evidence
Expected Learning Outcomes
Knowledge and understanding:
Be familiar with:
• the principles of IT security of systems and software applications
• IT attack methodologies and techniques based on related vulnerabilities
• the countermeasures that can be implemented to protect against such attacks
• penetration testing methodologies and techniques based on the attacks in question
• methodologies and techniques for managing an IT incident
• the general principles of the methodologies, techniques and tools which allow, in the event of an IT incident, to 1) acquire digital evidence without altering or modifying the IT system on which it is located 2) guaranteeing that the evidence acquired on another medium is identical to the original ones 3) analyze the data without altering them 4) correlate evidence of different types

Ability to apply knowledge and understanding:
Know how to:
• identify vulnerabilities present on the system
• apply penetration testing methodologies in order to assess the security level of systems and related applications, consequently proposing the appropriate countermeasures
• identify evidence that makes it possible to determine if and how a computer system has been compromised following a successful attack
• apply the methodologies necessary to manage the IT incident through the collection, analysis and interpretation of the data necessary to determine the methods of attack, and the related responsibilities, making such data suitable for being used in civil or criminal proceedings .

Making judgments:
Independently analyze and evaluate the security level of a computer system, and whether this system has been compromised following a computer attack.
Evaluate which of the methodologies, techniques and tools for managing an incident learned in class are the most suitable for use in a real case.

Communication skills:
Be able to communicate and explain, using the formal terminology specific to the topics covered in the course,
the security aspects of a computer system, the countermeasures to be taken to avoid security incidents, the impact of
an accident should it occur, the procedures necessary to bring the system back to safety and to reconstruct the events that occurred during an accident.

Learning ability;
Be able to profitably undertake subsequent studies related to cyber security and computer forensics.
Last update:09-09-2026 00:14:31