Hello, if you have any need, please feel free to consult us, this is my wechat: wx91due
BIT354: Network Vulnerability and Penetration Testing
Assignment 1 (25%)
Due Date: Week 7
Assignment Overview
For this Assignment you will install two computer systems, 64-bit operating system on Virtual Box. One is the attack machine and the other is the harden machine. You are required to use the older OS for this assignment. Below is the list of the recommended OS for this assignment:
1. Windows XP, Vista, 7
2. Ubuntu 12.04, 16.04
Do not use any personal information in the computer image. Marks will be awarded based on the sophistication and the difficulties of the hardening techniques.
Your task is to complete and write a report on the following:
1. Install the Computer System of your choosing
2. Research how to “harden” the computer system; that is the process to make a computer more secure. This should be thoroughly presented in the report
3. Implement at least eight (8) “hardening” techniques such as changing the default accounts usernames and passwords, installing updates, installing firewalls, antivirus software, group policy, etc. Your report should include screenshots of all implemented hardening techniques. You should implement a minimum of 8 techniques.
4. Compile a report of the above along with your evaluation and recommendations. The report must contain several screenshots of evidence (with name and student number at the side) that you actually did the work. (2+3+5 Marks).
5. You also need to do a 5 minutes in class presentation. In the presentation, you are required to:
a. Use powerpoint slide for the presentation as a guide but not in place of an attack.
b. You are required to present the 8 techniques used for the hardening of the OS
c. You need to demonstrate only 1 of 8 hacks into the machine.
(10 marks).
Failure to present in person, in class will result in a fail.
Videos will not be accepted as an alternative to presenting in person.
Please ensure that your screenshots are in English. You will be asked to resubmit.
Please include a time&date stamp in your screenshots so that I can authenticate your authorship.
Please do not use other peoples screenshots in your report – I do check for this.
You can also use a computer system from the following software:
· Contiki (IoT OS) http://www.contiki-os.org/ or TinyOS (http://distro.ibiblio.org/tinycorelinux/
· OwnCloud (cloud storage) https://owncloud.org/
· PFSense or Untangle
· Linux Desktop/Server Operating System
· Splunk/Snort/Nagios/Zabbix
Plagiarism
All used sources must be properly acknowledged with references and citations, if you did not create it. Quotations and paraphrasing are allowed but the sources must be acknowledged. Failure to do so is regarded as plagiarism and the minimum penalty for plagiarism is failure for the assignment. The act of given your assignment to another student is classified as a plagiarism offence. Copying large chucks and supplying a reference will result in zero marks as you have not contributed to the report.
Due Date & Submission
The report is due atWeek 7
By the due date, you must submit:
1. Name your file with your student number
2. Softcopy of your answers (with your name and student number) to TurnItIn. By submitting on MOODLE you agree that the work is yours unless properly cited.
3. You must submit a USB with your Virtual Image on it to your lecturer in the laboratory. As this will be inspected for coherence with the report and form a fundamental part of Assignment 2.
4. Fail to submit the report or the USB with the Virtual Image will result in a fail.
Late submission of assignments will be penalised as follows:
· For assignments 1 to 5 days late, a penalty of 10% (of total available marks) per day.
· For assignments more than 5 days late, a penalty of 100% will apply.
Your submission must be compatible with the software (PDF/Word) in MIT, Computer Laboratories/Classrooms.
Extensions: Under normal circumstances extensions will not be granted. In case of extenuating circumstances—such as illness—a Special Consideration form, accompanied by supporting documentation, must be received before 3 working days from the due date. If granted,an extension will be only granted only by the time period stated on the documentation; that is, if the illness medical certificate was for one day, an extension will be granted for one day only. Accordingly the student must submit within that time limit.
Penalties may apply for late submission without an approved extension.
Penalties: Academic misconduct such ascheating andplagiarism incur penalties ranging from a zero result to program exclusion.
Marking criteria:
Marks are allocated as indicated on each question, taking the following aspects into account:
|
Aspects |
Description |
|
Analysis (if appropriate) |
Investigation, comparison, discussion |
|
Explanation/justification |
Description/answer to the question |
|
Presentation |
Inadequate structure, careless presentation, poor writing |
|
Reference style |
Proper referencing if required |
|
Plagiarism |
Copy from another student, copy from internet source/textbook, copy from other sources without proper acknowledgement |
Marking Rubric for Exercise Answers
|
Grade Mark |
HD 80%+ |
D 70%-79% |
CR 60%-69% |
P 50%-59% |
Fail < 50% |
|
|
Excellent |
Very Good |
Good |
Satisfactory |
Unsatisfactory |
|
Analysis
|
Logic is clear and easy to follow with strong arguments |
Consistency logical and convincing |
Mostly consistent and convincing |
Adequate cohesion and conviction |
Argument is confused and disjointed |
|
Effort/Difficulties/ Challenges |
The presented solution demonstrated an extreme degree of difficulty that would require an expert to implement. |
The presented solution demonstrated a high degree of difficulty that would be an advance professional to implement. |
The presented solution demonstrated an average degree of difficulty that would be an average professional to implement. |
The presented solution demonstrated a low degree of difficulty that would be easy to implement. |
The presented solution demonstrated a poor degree of difficulty that would be too easy to implement. |
|
Explanation/ justification |
All elements are present and well integrated. |
Components present with good cohesion |
Components present and mostly well integrated |
Most components present |
Lacks structure. |
|
Reference style |
Clear styles with excellent source of references. |
Clear referencing/ style |
Generally good referencing/style |
Unclear referencing/style |
Lacks consistency with many errors |
|
Presentation |
Proper writing. Professionally presented |
Properly written, with some minor deficiencies |
Mostly good, but some structure or presentation problems |
Acceptable presentation |
Poor structure, careless presentation |
|
ASSESSMENT OVERVIEW AND FEEDBACK SUMMARY |
|
|
|||||
|
All assessments (except for final examination) and feedback are provided via the MOODLE site and in classes. |
|||||||
|
Assessment Tasks: |
Due Date |
Subject Learning Outcomes |
Course Learning Outcomes |
MP Graduate Attributes |
Weight (%) |
Comments |
|
|
Laboratories |
Week 10 |
a, b |
1,2,3 |
10% |
|||
|
Assignment 1 |
a, b |
25% |
|||||
|
Assignment 2 |
c, d |
25% |
|||||
|
Exam |
End of Semester |
c, d. |
40% |
Individual |
|||