Dissertation plan - Computing research methodologies

profilecustardo
crm_examples_4.zip

CRM_Example_73_NLP.pdf

CRM_Feedback_For_EX_70.pdf

READ ME CRM Examples.docx

CRM Example Final Assessment – Project Proposal Report

Here are some actual examples of the Final Assessment for Computing Research Methodologies. Although the aims of the module and the core report remain the same from different presentations of this module some of the course work elements have changed. Please note that the final marks given include coursework elements that are not relevant to the 2014/15 Semester 2 delivery. This means that although all the examples are good, the report element presented here will not exactly equate to the overall mark given. Also you will find errors and issues that could be improved. So have a look at these and while you do, make a list of the common themes.

Make sure you have a look at the feedback for ‘CRM_Ecample_63_NN and CRM_Example_70_Security as these use the marking rubric from Turnitin and show all the standard options for each criteria.

CRM_Example_63_NN.pdf

CRM_Example_64_SPi.pdf

CRM_Example_70_forensics.pdf

1

Computing Research Methodologies

Computing Research Methodologies MOD002602

Project Proposal: Using different forensic software are forensic students able to detect the same changes in files?

Contents

2

Computing Research Methodologies

Title and Aims ............................................................................................................................ 2

Previous Work / Background / Literature Review ..................................................................... 3

Methodology / Process and Data Analysis Techniques ............................................................. 4

Outline design ............................................................................................................................ 5

Time Table .................................................................................................................................. 5

References ................................................................................................................................. 6

Appendix ..................................................................................... Error! Bookmark not defined.

Project Proposal Presentation Slide ....................................... Error! Bookmark not defined.

Project Proposal Feedback...................................................... Error! Bookmark not defined.

Computing Research Methodologies Project Topic Check List ............. Error! Bookmark not defined.

Ethical Checklist ...................................................................... Error! Bookmark not defined.

Gantt Chart.............................................................................. Error! Bookmark not defined.

Log Book Mark ........................................................................ Error! Bookmark not defined.

Title and Aims Title: Using different forensic software are forensic students able to detect the same changes in files?

3

Computing Research Methodologies

Aims: To investigate how students interact with forensic software To investigate whether students are able to find the same results with different software through their interaction techniques/skills To investigate whether the software used affects successful results This is based on usability - a usability study is a process of seeing how easy it is to use or learn to use something, in this case software. Individuals are used to test how software is used, it includes a needs analysis and what makes the software good or bad, especially in the user’s opinion. It considers usefulness too and is a user-oriented approach. There are three main approaches are Discovery, Learning and Efficiency. Discovery is searching for and finding a feature of the software which helps the user for a certain need – it can affect how long it takes a user to discover a feature and how the user gets there. Learning is how the user determines a process to use a feature to complete tasks – it affects how long the user takes to learn this process and how it is done. Efficiency is the point where the user has learnt how to use the software and its features and does not need extra knowledge or experience – it can be used to determine how well the user executes the task and how long it takes. [Microsoft Corporation, 2000] The process of observing patterns and watching users carry out tasks is Inductive. Inductive reasoning works by moving from specific observations which lead to patterns and allows the researcher to generate a tentative hypothesis, generalisations and theories. It is more open ended and exploratory. [Crossman, A. 2013] The title suggests the hypothesis that different software will affect the outcome - the way it can be used and how students will use it. The variables involved would be the students - their skills/techniques, the software, what it is able to do and the tasks given to students. These can all affect the outcome of the study and so would need consideration in the methodology, testing and evaluation as one thing can affect the other.

Previous Work / Background / Literature Review The Technical, Non-technical Issues and the Challenges of Migration to Free and Open Source Software. This paper investigates the technical issues, non-technical issues and the challenges of free and open source software particularly from previously having used proprietary software. It covers performance, technical infrastructure, usability, integrity, support availability, security, information flow control, data migration, flexibility, ease of use and the management, maintenance of Open Source software, organisational culture, human factors and legal issues. This can help in evaluating the results when comparing the software used by students in searching for file changes; it also covers some behavioural aspects which can help in evaluating observations. [Elbasir, M. Elgamel, L. Sarrab, M. 2013] On the use of data visualization techniques to support digital forensic analysis: A survey of current approaches. This paper investigates the analysis and reconstruction stages in digital forensic investigations. It covers analysis techniques and experience forensic analysts use to cover recovered information. It suggests an exploitation of 3D computer graphics and information visualisation in order to improve exploration, analysis and structure of large volumes of data which then lead to a prototype

4

Computing Research Methodologies

visualisation tool. It also analyses the strengths and weaknesses of current tools and techniques. This will help in understanding the problems involved in data recovery and the skills/techniques and preferences of students when analysing data. [Archibald, J. Ferguson, R. Hales, G. 2013] Usability of Forensics Tools: A User Study This paper investigates the usability aspect of forensics tools by using surveys and conducting interviews to get feedback from forensic analysts about the tools and techniques used, It also highlights issues with forensic tools. It covers the many factors which affect usability including a users background, computer expertise, workflow and practices. This will help in determining issues students may have with forensic software and their use of it. [Cranor, L. Hibshi, H. Vidas, T. 2011] A comparison of forensic toolkits and mass market data recovery applications This paper investigates a range of forensic software, and its research shows that there is some variation in results presented by data recovery tools. It addresses different functionality of software and compares data recovery capabilities. This will help in evaluating the results from different software. [Buchanan-Wollaston, J., Storer, T., and Glisson, W. [2012] Human-Computer Interaction: An Analysis This paper investigates the interaction between humans and computers, including the physical, psychological and theoretical aspects. It also covers usability and what makes human – computer analysis good or bad. Although it does not focus on forensic software, this paper covers an analysis of the interaction people have with computers and or software on the computer which will give me an insight into techniques students use in their tasks. [Antony, H. 2013]

Methodology / Process and Data Analysis Techniques The implementation of this study involves setting a scenario where students can investigate file changes using certain software, accompanied by questionnaires to assess their opinions on how well they got on with the task and software. This is a positivist research method and an experimental methodology as it relies on results based on tests done under controlled conditions. A positivist approach is based on observations and deals with positive facts, it means that it is quantitative and allows general conclusions or theories. Experimental research involves manipulating a certain factor to identify any connections in change – the change here would be the forensic software, the students and task would stay the same. [Nightingale, W. 2012] The first thing would be to have a target audience, as mentioned the study would be carried out on students so would focus on first, second and third year forensic students at Anglia Ruskin University. Secondly the specific software to be used would be forensic tools available to the students; these include Encase – although a commercial tool, it is available for forensic students to use. Another tool to use can be OS Forensics; this is an open source forensic tool. It is possible to add more software to the list however they would have to be able to complete the tasks which are yet to be set out. The third aspect is the task set for the student to complete; this would come in the form of a file with changes made to it forensically, for example: changing the file signature, or altering the contents of it. The student would then have to investigate this using the software and come to a conclusion on the file, what changes have been made and any additional details such as when it was made. This file or data would essentially stay the same with the software being the change, it is possible for the task to range from straight forward to more complicated in order to observe

5

Computing Research Methodologies

genuine results. However this would mean testing the different tasks across the different software and may become more complicated as a study. The fourth part is to observe the students whilst they carry out the task and explore by using a questionnaire on the students experience of the software and their approach, and whether they reached a successful end result. The fifth and last point is to evaluate and analyse all the data collected. The patterns observed can help to distinguish regularities in techniques or approach. The variables can be discussed including the technical abilities of the software as well as the users past experiences. The possible risks involved in this study are firstly ethics and approval; it is needed to protect the rights of the participants of the study and overall requires care during the study in order to minimise any errors. [Resnik, D. 2011] Another risk is that to get enough participants for the study may be difficult, as it requires them to carry out a task and to do a questionnaire it is a commitment which will take some time and many students may not want to make it. This could be overcome by setting smaller, quicker tasks and for the feedback questionnaires to be simple or short and easy to fill out – this is something which may need contingency planning. Also an accurate measurement of the project, time management needed and whether the time available is enough for what needs to be done can be an issue.

Outline design Through using files with changes made to them it can be seen whether the students are able to reach a successful result as the original file will be used to compare to. This will stay the same whether the student is different, or software is different. It is also possible to create different levels of difficulty in the tasks using files with different changes or harder to detect changes, this will show whether the students deploy different techniques in trying to find the changes. Using different software is key to the study as it shows whether the same results are achievable through a different means, and if not then what is affecting the result – is it the software itself or is it the student using it? This assumes that the task is achievable and if it isn’t then it would be expected that the same result still shows on the different software. Through observation of the students carrying out tasks it can be seen whether they find the tasks easy or difficult, and whether the find use of the software easy or difficult, and referring back to the approaches in usability mentioned earlier it can be seen how long it takes the student to complete the task through discovery, learning and efficiency approaches. The results of each student can be compared to each other to then find patterns not only individually, this will show whether they have similar discovery and learning methods, if the change in software or task affected each student differently or not. Once the tasks and observations have been completed, to help evaluate the student’s performance a questionnaire can be set on: how the students found the task, whether it was difficult, what they thought of the software, how they used it and if they were able to detect the file changes. The questionnaire will be a good way to find out the students’ opinions and how they felt about the task and software, this can then be compared to the actual results and observations made in order to see if they correlate and therefore back up any findings.

Time Table Fig. 1: Gantt chart to show time management for project

6

Computing Research Methodologies

Above is a gantt chart to show an estimate of the time management needed in completing the project and its various components. Two weeks have been given to the project proposal approval as it may need to be changed and would take some time to go over. Research and literature reviews are expected to take possibly a month in order to gain a good perspective. Task generation may take some time as I would expect to review my options with a forensic computing lecturer or technician in order to see which tasks would be possible and how to conduct a task which would test the students’ techniques. After this the questionnaire can be created, relating to the tasks and the software. Participants would need to be chosen and any ethics forms and participation approval would need to be done. The experiment can then be carried out; this could take approximately two weeks however this process can be carried out as participants are selected. Recovering results and carrying out an analysis may take three weeks, and an analysis may take another two weeks using the research to refer to in helping to reach conclusions. Once the main components have been completed the draft write up can be finalised and checked through, then finalised towards the deadline. It would be expected that supervisor feedback would be available throughout the project and that each component would have some sort of overlap. In the appendix the original idea with feedback is attached.

References Antony, H. (2013). Human-Computer Interaction: An Analysis.Available: http://txcdk- v15.unt.edu/SLIS5223-2/handle/123456789/160. Last accessed 12/05/13. Archibald, J. Ferguson, R. Hales, G. (2013). On the use of data visualization techniques to support digital forensic analysis: A survey of current approaches . University of Abertay. Available: http://www.gavinhales.co.uk/research/cyberforpaper.pdf.

7

Computing Research Methodologies

Buchanan-Wollaston, J., Storer, T., and Glisson, W. (2012) A comparison of forensic toolkits and mass market data recovery applications. In: Ninth Annual IFIP WG 11.9 International Conference on Digital Forensics, 28-30 Jan 2013, National Center for Forensic Science Orlando, FL, USA. Cranor, L. Hibshi, H. Vidas, T. (2011). Usability of Forensics Tools: A User Study. Available: http://www.kau.edu.sa/Files/611/Researches/60469_31299.pdf. Last accessed 12/05/13. Crossman, A. (2013). Deductive Reasoning Versus Inductive Reasoning. Available: http://sociology.about.com/od/Research/a/Deductive-Reasoning-Versus-Inductive-Reasoning.htm. Last accessed 12/05/13. Elbasir, M. Elgamel, L. Sarrab, M. (2013). The Technical, Non-technical Issues and the Challenges of Migration to Free and Open Source Software . International Journal of Computer Science Issues. 10 (Issue 2). Available: http://ijcsi.org/papers/IJCSI-10-2-3-464-469.pdf Microsoft Corporation. (2000). Usability in Software Design. Available: http://msdn.microsoft.com/en-us/library/ms997577.aspx. Last accessed 12/05/13. Nightingale, W.. (2012). Positivist Approach to Research. Available: http://www.wider- mind.com/research/wdn-positivism-v2.pdf. Last accessed 12/05/13. Resnik, D. (2011). What is Ethics in Research & Why is it Important? Available: http://www.niehs.nih.gov/research/resources/bioethics/whatis/. Last accessed 12/05/13.

CRM_Example_70_GameRecording.pdf

CRM_Example_70_Security.pdf