Course Details

Cybersecurity and computer forensics

MF0654

Course
Cybersecurity and computer forensics
Code
MF0654
Academic Year
2026/2027
Curriculum Year
2025/2026
Degree Programme
ARTIFICIAL INTELLIGENCE AND DIGITAL INNOVATION
Curriculum
A013 - Tecnologico-Informatico
Course coordinator
Credits
9
Lecture Hours
72
Scientific Disciplinary Sector (SSD)
INF/01 - Computer Science
Course Type
Single-subject learning activity
Course Delivery
OPZ - Opzionale
Year
2
Teaching period
Primo Semestre
Campus
ALESSANDRIA
Teaching language
Italian
Course Contents
The course addresses cybersecurity and digital forensics as complementary fields. The first part focuses on vulnerabilities in systems and software applications, major attack techniques, and the corresponding countermeasures. The second part focuses on incident response and digital forensics: identification, acquisition, preservation, analysis, and correlation of digital evidence, while ensuring integrity, traceability, and repeatability. Theoretical topics are complemented by examples and laboratory activities conducted on simplified cases and controlled environments.
Reference Texts
Main textbooks:

1. W. Du, Computer & Internet Security: A Hands-on Approach, 3rd edition. This book is the main reference for cybersecurity principles, software and web vulnerabilities, attack techniques, and related countermeasures. The chapters indicated during the course are coordinated with the laboratory exercises and the Cybersecurity CTF activities.
2. J. Kävrestad, M. Birath, N. Clarke, Fundamentals of Digital Forensics: A Guide to Theory, Research and Applications, 3rd edition, Springer, 2024, ISBN 978-3-031-53648-9. This book is the main reference for the principles, methodologies, and tools used to acquire, preserve, analyse, and correlate digital evidence, as well as for the Digital Forensics CTF activities.

Recommended textbooks for further study:

3. G. Johansen, Digital Forensics and Incident Response, 3rd edition, Packt Publishing, 2022, ISBN 978-1-80323-867-8. This book provides further coverage of the operational and organisational aspects of incident response and their integration with digital forensic investigations.
4. D. Andriesse, Practical Binary Analysis, No Starch Press, 2018, ISBN 978-1-59327-912-7. This book is recommended for further study of executable-file analysis and software-security techniques.

The materials available on the DIR platform, including lecture slides, laboratory instructions, CTF challenges, examples, and technical documentation, are an integral part of the study material. For each part of the syllabus, the platform specifies the chapters and materials required to prepare for the written test and the oral discussion.
Learning Outcomes
The course contributes to the learning objectives of the Degree Programme by providing knowledge and methodological tools to assess the security of computer systems, evaluate vulnerabilities and countermeasures, and correctly manage a cybersecurity incident.

By the end of the course, students will be able to:
1. describe the fundamental security requirements of systems and software applications;
2. explain major software and web vulnerabilities, related attacks, and countermeasures;
3. apply vulnerability-analysis and penetration-testing methodologies in controlled environments;
4. describe the phases of cybersecurity incident management;
5. acquire and analyse digital evidence without altering its content, documenting integrity, provenance, and chain of custody;
6. correlate heterogeneous evidence to reconstruct relevant incident events;
7. justify technical choices and communicate results, limitations, and implications using appropriate terminology.

The course awards 9 ECTS credits and includes 72 hours of teaching activities, divided into 24 hours of lectures and 48 hours of interactive learning. The conventional overall workload is 225 hours, including 153 hours of individual study and self-directed learning.
Prerequisites
Students are expected to have sound knowledge of:
- computer architecture;
- operating systems, processes, memory, file systems, and protection mechanisms;
- computer networks and communication protocols;
- C programming;
- binary data representation and memory management;
- basic Unix/Linux environments and command-line tools.

Students should also be able to read code fragments, execution traces, system logs, and network traffic. Any formal prerequisites are those established by the Degree Programme regulations.
Teaching Methods
The course combines lectures and interactive learning activities.

Lectures cover cybersecurity principles, software and web vulnerabilities, attack and defence techniques, and digital forensics. Topics are illustrated through examples, diagrams, and case analyses.

Interactive activities include exercises, laboratory work, and Capture the Flag challenges for both Cybersecurity and Digital Forensics, conducted in controlled environments and on simplified cases. They are aimed at:
- recognising vulnerabilities and understanding selected attacks;
- identifying suitable countermeasures;
- analysing logs, artefacts, and other sources of digital evidence;
- applying acquisition and integrity-verification procedures;
- correlating evidence and reconstructing event sequences;
- documenting concisely the procedure followed, the tools used, and the evidence leading to each flag;
- critically discussing methodological choices and limitations.

Offensive activities are conducted exclusively in authorised and controlled environments for educational and defensive purposes. The DIR platform provides teaching materials, operational instructions, and a concise template for documenting the activities, suitable for non-attending students as well.
Additional Information
All information required to prepare for the examination is included in this syllabus and in the material available on DIR. Organisational information concerning examination sessions is communicated through institutional channels.

Students with disabilities, Specific Learning Disorders, or Special Educational Needs may request dedicated services and tools by contacting the relevant University office and consulting:
https://uniupo.it/it/servizi/servizi-studentesse-e-studenti-condizione-di-disabilit%C3%A0-e-dsa

After contacting the University office, students may contact the course instructor to agree on the implementation of the approved measures concerning teaching activities and assessment.
Assessment Methods
The examination consists of a compulsory written test and an optional oral test. Registration is required through ESSE3 by the deadlines set for each examination session.
The written test is taken individually using the computers in the teaching laboratory. It lasts 2 hours and involves solving one or more Cybersecurity and Digital Forensics challenges. Candidates must analyse scenarios, data or digital evidence, identify relevant vulnerabilities or evidence, and correctly apply the methods and tools covered in the course. For each challenge, they may be asked to provide the solution or flag, briefly describe the procedure followed, interpret the outputs obtained, and justify the main technical choices.

The written test assesses:
* the ability to apply Cybersecurity and Digital Forensics methods and tools;
* the ability to analyse vulnerabilities, incidents, data and digital evidence;
* the correctness of the procedure and results;
* the ability to interpret outputs and intermediate results, justify technical choices, and identify errors or alternatives;
* operational autonomy and appropriate use of specialist terminology.

Assessment considers the correctness and completeness of the solutions, the appropriateness of the methods and tools used, the interpretation of evidence, and the clarity with which the procedure is documented. The test is graded out of 30 and is passed with a mark of at least 18/30.

A passing performance requires candidates to identify the essential elements of the challenges and reach substantially correct solutions through a technically appropriate procedure, despite minor omissions or inaccuracies. Higher marks require complete and rigorous solutions, informed use of tools, correct interpretation of evidence, and autonomy in addressing complex situations. Excellence requires full correctness, autonomy, methodological rigour, and critical justification of choices.

After passing the written test, candidates may take an optional oral test on the methodological aspects of the course. It assesses understanding of Cybersecurity and Digital Forensics methods; the ability to connect principles and procedures, critically discuss limitations, errors and alternatives, and present arguments clearly and accurately.

If the oral test is not taken, the final mark is the written-test mark. If taken, it may confirm the written mark or change it by up to 3 points, either upward or downward. It cannot compensate for a failed written test. Honours may be awarded to candidates who obtain 30/30 in the written test and give an excellent oral performance demonstrating full methodological mastery, independent judgement, and exceptional clarity.

Assessment levels:
* fail: fragmented preparation, inability to apply fundamental procedures, failure to understand practical solutions, or significant conceptual errors;
* 18–20/30: essential knowledge and application of fundamental procedures, with no serious errors;
* 21–23/30: reasonably complete knowledge and generally correct application;
* 24–26/30: sound knowledge, correct analysis, and clear justification;
* 27–29/30: in-depth knowledge, analytical autonomy, and high methodological and technical accuracy;
* 30/30 and 30 with honours: complete and critical mastery, full understanding of practical activities, and rigorous, particularly clear argumentation. Honours require an exceptionally high level of depth, autonomy, and quality of presentation.

Preparation for the written test requires personal completion of the Cybersecurity and Digital Forensics practical activities and challenges, together with review of the related solutions and documentation available on DIR. For the optional oral test, candidates should study the texts and materials on the methodological aspects of the course published on DIR. Six examination sessions are held each year; dates are published on ESSE3.
Detailed Syllabus
1. Cybersecurity foundations
- Confidentiality, integrity, availability, authenticity, and accountability.
- Threats, vulnerabilities, risks, attacks, and countermeasures.
- Defence in depth, least privilege, and attack-surface reduction.

2. Software security
- Buffer-overflow vulnerabilities and attacks.
- Return-to-libc attacks.
- Format-string vulnerabilities and attacks.
- Countermeasures at compiler, operating-system, and application level.
- Controlled analysis of vulnerable code.

3. Digital evidence and digital-forensics principles
- Properties of digital evidence.
- Integrity, authenticity, repeatability, and reproducibility.
- Identification, collection, acquisition, preservation, analysis, and presentation.
- Hashing, forensic imaging, write blockers, and chain of custody.
- Distinguishing observed data, interpretation, and conclusions.

4. Evidence acquisition
- Acquisition from computers and storage media.
- Acquisition from mobile devices.
- Acquisition from network devices and infrastructures.
- Persistent and volatile data.
- Integrity verification and documentation.

5. Evidence analysis and correlation
- File systems, metadata, and system artefacts.
- Logs, timelines, and events.
- Application, browser, and communication artefacts.
- Network evidence.
- Correlation of heterogeneous sources.
- Event reconstruction and analysis limitations.

6. Applied activities
- Controlled exercises on vulnerabilities and countermeasures.
- Incident-scenario analysis.
- Acquisition and verification of forensic images.
- Analysis and correlation of digital artefacts.
- Concise reporting of technical findings and justified conclusions.

Integration of the gender dimension
The course promotes inclusive technical language and awareness of how security measures and incident analyses may affect different people and groups, avoiding discriminatory assumptions or interpretations.
Expected Learning Outcomes
Knowledge and understanding
By the end of the course, students will know and understand:
- fundamental cybersecurity principles and requirements;
- major software vulnerabilities, related attack techniques, and available countermeasures;
- the principles of digital evidence, with particular reference to integrity, authenticity, traceability, repeatability, and reproducibility;
- methods for identifying, acquiring, preserving, analysing, and presenting digital evidence;
- major evidence sources, including file systems, metadata, logs, system artefacts, applications, browsers, communications, and network data;
- criteria for correlating heterogeneous sources and reconstructing event sequences.

Applying knowledge and understanding
Students will be able to:
- identify vulnerabilities in simple scenarios or code fragments;
- explain selected attack techniques and propose coherent countermeasures;
- apply procedures for acquiring persistent and volatile data and document the operations performed;
- verify the integrity of acquired copies using hash functions;
- analyse file systems, metadata, logs, and other digital artefacts;
- correlate evidence from different sources;
- produce a justified reconstruction of events, distinguishing observed data, inferences, and conclusions.

Making judgements
Students will be able to select relevant information, assess the reliability and limitations of available evidence, choose suitable methods and tools, state assumptions explicitly, and justify their conclusions.

Communication skills
Students will be able to describe vulnerabilities, attacks, countermeasures, acquisition procedures, and analytical findings clearly, logically, and accurately, using appropriate specialist terminology.

Learning skills
Students will be able to use textbooks, technical documentation, teaching material, and laboratory tools to independently study new vulnerabilities, defence techniques, and digital-forensics methods.

Minimum passing level
To pass the examination, students must know the fundamental concepts of all major syllabus areas, recognise common vulnerabilities and countermeasures, correctly describe the essential phases of forensic acquisition and analysis, apply standard procedures to simple cases, and provide understandable and substantially correct answers.

Advanced level
An advanced level requires broad and integrated knowledge, autonomous analysis of scenarios that are not identical to those practised, the ability to correlate heterogeneous evidence, critically assess alternative hypotheses, and produce rigorous, complete, and well-justified conclusions.

Last update:09-09-2026 00:14:31