BS, MS, Shanghai Normal University (China); MS, Ph.D., State University of New York at Binghamton


Yin Pan is a Professor in the Computing Security department. She received her Ph.D. in Systems Science and M.S. degree in Computer Science from Binghamton University. Dr. Pan holds four US patents in the areas of Network Quality of Services, Voice over IP and Artificial Intelligence. Since joining RIT in 2002, Dr. Pan has been actively involved in the IT security area, especially in security audits and computer forensics. Her current research interests include game-based digital forensics and memory-based malware detection using machine learning. She has published over 45 papers and presentations in research conferences and journals. She received grants from NSF, US Air Force Research Lab, and RIT. Dr. Pan teaches both undergraduate and graduate courses in digital forensics.


This course develops the student's knowledge and understanding of various contemporary research issues, especially in the interdisciplinary areas of computing and information sciences. The student will get involved by attending a number of research presentations and discussions. The choice of topics considered may vary and will be determined by the instructor.
Teaching is a valuable and desirable skill for PhD students. This workshop course provides an introduction to the concepts and skills needed for quality teaching in higher education. Students will be provided with lecture, reading, and class activities centered on building skills in educational analysis, design, and assessment. Prerequisites: Limited to students in the Ph.D. program. Class 2, Credit 2 (F)
An investigation of the tasks of incident response and computer system forensics will be pursued. Students will learn the basic procedure for incident response as well as the tools needed to uncover the activities of computer users (deleted and hidden files, cryptographic steganography, illegal software, etc). Students will also learn to employ the activities needed to gather and preserve this evidence to ensure admissibility in court.
A student works with a faculty member to devise a plan of study on a topic in various areas of computing security. Deliverables, evaluation methods, and number of credits need to be specified in a written proposal. A final report and presentation in the form of a poster session is expected and graded at the end of the term.
This course provides students with the latest techniques and methods needed for extracting, preserving and analyzing volatile and nonvolatile information from digital devices. Students will gain exposure to the spectrum of available computer forensics tools along with developing their own tools for “special need” situations. The core forensics procedures necessary for ensuring the admissibility of evidence in court, as well as the legal and ethical implications of the process, will be covered on both Unix and Windows platforms, under multiple file systems. Therefore, students must possess a knowledge of available filesystems on both platforms.

