Cyber Security and Digital Forensic

This course introduces the fundamental concepts of cybersecurity, ethical hacking, and digital forensics, including web application security, authentication, OSINT, reverse engineering, network forensics, cryptography, blockchain security, and cybersecurity law.

Instructor: Md. Shakil Ahmed

Term: Summer

Cyber Security and Digital Forensic

CSE 413 · Core Course · 3.0 Credit Hours

This course introduces cybersecurity, ethical hacking, and digital forensics through the study of web application security, authentication, security analysis, forensic investigation, cryptography, and cybersecurity law.
Cybersecurity Ethical Hacking Digital Forensics Web Security Authentication OSINT Python Reverse Engineering Network Forensics Cryptography Blockchain Security Cyber Law

Course Overview

This course provides a comprehensive study of cybersecurity and digital forensics, with emphasis on understanding security threats, vulnerabilities, attacks, authentication mechanisms, forensic evidence, and defensive practices. Students will examine common web application vulnerabilities, security testing techniques, information-gathering methods, reverse engineering, binary analysis, network forensics, cryptography, blockchain security, and cybersecurity law.

The course combines theoretical concepts with practical security analysis and investigation scenarios. Students will develop the ability to identify vulnerabilities, analyze security incidents, investigate digital evidence, and apply ethical, legal, and responsible cybersecurity practices.

Course Learning Outcomes

CLO1 — Cybersecurity Fundamentals

Explain fundamental cybersecurity concepts, security principles, common threats, vulnerabilities, attacks, and defensive practices.

CLO2 — Security Analysis

Analyze web application vulnerabilities, authentication weaknesses, application logic flaws, and other common security issues using appropriate security concepts and techniques.

CLO3 — Digital Forensics

Apply digital forensic methods to collect, examine, analyze, and interpret digital evidence from system, memory, and network sources.

CLO4 — Ethical and Legal Practice

Demonstrate ethical, legal, and responsible practices when performing cybersecurity analysis, security testing, and forensic investigations.

Prerequisites

  • Basic computer and operating system knowledge.
  • Basic networking concepts are recommended.
  • Basic programming knowledge is recommended.

Textbooks

  • Primary: The Web Application Hacker's Handbook by Dafydd Stuttard and Marcus Pinto.
  • Primary: Guide to Computer Forensics and Investigations by Bill Nelson.

Reference Books

  • Cybersecurity Essentials by Charles J. Brooks.
  • Social Engineering: The Science of Human Hacking by Christopher Hadnagy.
  • Black Hat Python: Python Programming for Hackers and Pentesters by Justin Seitz and Tim Arnold.
  • Practical Reverse Engineering by Bruce Dang and Alexandre Gazet.
  • Cryptography and Network Security: Principles and Practice by William Stallings.
  • Cybersecurity and Cyberlaw by Pavan Duggal.

Tools and Platforms

Security Testing

Kali Linux, Burp Suite, DVWA, Python, and related security testing tools for controlled cybersecurity exercises.

Forensic and Analysis Tools

Autopsy, Volatility, Ghidra, Wireshark, and related tools for digital forensic, memory, network, and binary analysis.

Online Resources

Course Information

Attribute Details
Course Code CSE 413
Course Title Cyber Security and Digital Forensic
Course Type Core Course
Credit Hours 3.0
Academic Term Summer 2026
Instructor Md. Shakil Ahmed

Grading

Assessment Weight
Class Participation 5%
Assignment / Presentation / Viva 10%
Class Test 15%
Midterm Examination 30%
Final Examination 40%
Total 100%

Course Schedule

Week Topic Description
1 Introduction to Cybersecurity and Digital Forensics Introduction to cybersecurity, the CIA triad, key security principles, incident management, penetration testing, digital evidence, evidence handling, and chain of custody.
2 SQL Injection and Cross-Site Scripting Study of SQL injection techniques and cross-site scripting vulnerabilities, including reflected, stored, and DOM-based XSS in controlled environments.
3 CSRF and Clickjacking Understanding Cross-Site Request Forgery, implicit trust in authenticated requests, clickjacking, UI redress attacks, and insecure DOM manipulation.
4 CORS, XXE, SSRF, and HTTP Request Smuggling Introduction to CORS misconfigurations, XML External Entity injection, Server-Side Request Forgery, and HTTP request smuggling vulnerabilities.
5 Command Injection, SSTI, and Access Control Study of OS command injection, Server-Side Template Injection, path traversal, arbitrary file access, and broken access control vulnerabilities.
6 Midterm Examination Review of the topics covered during the first half of the course followed by the midterm examination.
7 Authentication and Application Logic Study of JWT and OAuth authentication issues, token tampering, OAuth misconfiguration, and application logic vulnerabilities.
8 OSINT, Social Engineering, and Python Basics Introduction to open-source intelligence, information gathering, social engineering concepts, Python variables, loops, and file handling.
9 Python for Security and Reverse Engineering Application of Python for security automation, scanning, file analysis, and introduction to reverse engineering tools and assembly fundamentals.
10 Binary Analysis and Native Application Security Understanding compiled binaries, binary analysis, buffer overflow, integer vulnerabilities, and format string vulnerabilities.
11 Advanced and Network Forensics Study of data carving, memory analysis, network traffic capture, and analysis techniques for digital forensic investigations.
12 Cryptography and Hashing Introduction to cryptographic concepts, encryption techniques, digital security applications, and hashing algorithms.
13 Blockchain Security and Cybersecurity Law Introduction to ledger integrity, smart contract risks, cybersecurity laws, standards, compliance, and professional responsibilities.
14 Final Review and Examination Comprehensive review of cybersecurity, application security, authentication, digital forensics, cryptography, blockchain security, and cybersecurity law followed by the final examination.