PV280 Network Forensics

Faculty of Informatics
Spring 2022
RNDr. Milan Čermák, Ph.D. (lecturer), prof. RNDr. Tomáš Pitner, Ph.D. (deputy)
RNDr. Petr Velan, Ph.D. (lecturer)
prof. RNDr. Tomáš Pitner, Ph.D.
Department of Computer Systems and Communications - Faculty of Informatics
Thu 17. 2. to Thu 12. 5. Thu 12:00–13:50 S108
Course objectives
The course teaches students to monitor network traffic using raw packet capture and network flows. Students will be able to analyze obtained data to detect malicious behavior and network attacks. They will learn how to explore unknown networks and their services and assess their vulnerabilities.
Learning outcomes
At the end of the course, the students will be able to:
    • capture and analyze network traffic,
    • understand network flow monitoring and be able to deploy it on a network,
    • analyze flow records and extract information related to events and incidents in the monitored network,
    • understand network attacks and their detection in traffic,
    • analyze unknown network infrastructure and gain information about potential vulnerabilities.
  • Introduction to network forensics;
  • Host-side artifacts;
  • Packet capture and analysis;
  • Network flow capture and analysis;
  • Encrypted and tunneled traffic;
  • Network attacks and anomalies;
  • Intrusion detection systems;
  • Firewall and application logs;
  • Network scanning;
  • Advanced network data analysis.
Teaching methods
Hands-on seminars and homework assignments.
Assessment methods
Homework assignments during the semester (at least 60 % of all points is required).
Examination: practical assignment and follow-up discussion.
