Everyone gets a few bonus points, thank you prof.
“In this class, we’re going to focus on data in transit”
Intelligence and Evidence are different. One can have intel that something is going on, but no evidence.
Forensics involves rules on how you handle evidence.
There is a system forensics class - but this one is network.
Our typical data source is logs.
Three kinds of data of interest:
Types of firewalls:
Things to look at in headers:
Professor does not take attendance
Mid-semester exam will be ten short answer questions.
Semester Project