i want too make my assignment related computer networking and security
Budget: €30 – €250 EUR
Your report as a word document.
This assessment will be marked anonymously. This means Moodle will hide student identities from the marker during the marking process. To protect this anonymity, please do not incorporate your personal details, including your name, email and student number anywhere within the actual assignment or its file name.
Please also be aware that if you take an extension, it may not be possible for your work to be marked anonymously. This is because the technology reveals all student identities to the marker on the standard feedback return date, but your assignment might be marked after this.
If you have any questions about anonymous assessment, please contact your Module Tutor.
The requirements for the assessment
Despite the security measures you had put in place at Fern Woods Medical Centre, they were exploited by an as yet unknown vulnerability in Microsoft Internet Explorer that allowed someone to gain remote root-level control to one of their server machines.
Fern Woods Medical Centre had recently appointed a new pharmacist, who had limited knowledge in cybersecurity and naively clicked on a malicious link received by an e-mail that gave the attacker access to one of their server machines with the IP address of 172.16.100.26.
With that IP address, the IT Technician was able to use the medical centres network traffic logging data store to isolate full-capture pcap data for that system during the period of interest (see attached .pcap file). Furthermore, the medical centre is concerned about how easily it was for their staff to be subject to receiving malicious emails and has come back to you for your advice as a cyber-security consultant.
Your objective is to create a report for Fern Woods Medical Centre providing an analysis of what happened, in addition to recommendations on how to improve their security.
Your report should contain the following parts:
Introduction – This should provide a brief introduction to the case indicating any assumptions (technical and non-technical) you have made.
Analysis of Investigative Tools – In this section you should provide an analysis of the tools you used for your investigation, detailing why they are beneficial, and any limitations.
Investigation Set-Up – In this section you should provide an overview of how you have set yourself up for the investigation, such as details of using a VM, customisation of Wireshark columns etc.
The Investigation – You should detail the steps taken to investigate the breach with screenshots as evidence. This should include the use of a sandbox environment to run your packet analysing software. In this section you should document everything that looks suspicious and try to explain what happened.
Recommendations on how to mitigate threats and improve security - This section should include an explanation and justification of any recommended security measures or procedures based on the attack which happened and other similar attacks that the Medical Centre may be susceptible to. This section should include addressing concerns about the nature of the attack/breach, and what can be done to directly address this issue in future. This section should discuss both technical and non-technical security measures and should relate to academic literature.
Conclusion
References
Assessment Criteria
Marks will be awarded for the accuracy and level of detail explaining what happened in the attack, and for the general quality of your report. It is expected that where applicable, you will relate your report to tools, methods and content discussed throughout the module, to academic literature, reports of attacks in the sector, and any relevant guidelines/standards. Higher marks are awarded where there is greater justification of points made, greater relevancy of points to the case provided, and where limitations and alternatives are also discussed.
Open the pcap file within a Linux virtual machine such as Kali Linux!
This assessment will be marked anonymously. This means Moodle will hide student identities from the marker during the marking process. To protect this anonymity, please do not incorporate your personal details, including your name, email and student number anywhere within the actual assignment or its file name.
Please also be aware that if you take an extension, it may not be possible for your work to be marked anonymously. This is because the technology reveals all student identities to the marker on the standard feedback return date, but your assignment might be marked after this.
If you have any questions about anonymous assessment, please contact your Module Tutor.
The requirements for the assessment
Despite the security measures you had put in place at Fern Woods Medical Centre, they were exploited by an as yet unknown vulnerability in Microsoft Internet Explorer that allowed someone to gain remote root-level control to one of their server machines.
Fern Woods Medical Centre had recently appointed a new pharmacist, who had limited knowledge in cybersecurity and naively clicked on a malicious link received by an e-mail that gave the attacker access to one of their server machines with the IP address of 172.16.100.26.
With that IP address, the IT Technician was able to use the medical centres network traffic logging data store to isolate full-capture pcap data for that system during the period of interest (see attached .pcap file). Furthermore, the medical centre is concerned about how easily it was for their staff to be subject to receiving malicious emails and has come back to you for your advice as a cyber-security consultant.
Your objective is to create a report for Fern Woods Medical Centre providing an analysis of what happened, in addition to recommendations on how to improve their security.
Your report should contain the following parts:
Introduction – This should provide a brief introduction to the case indicating any assumptions (technical and non-technical) you have made.
Analysis of Investigative Tools – In this section you should provide an analysis of the tools you used for your investigation, detailing why they are beneficial, and any limitations.
Investigation Set-Up – In this section you should provide an overview of how you have set yourself up for the investigation, such as details of using a VM, customisation of Wireshark columns etc.
The Investigation – You should detail the steps taken to investigate the breach with screenshots as evidence. This should include the use of a sandbox environment to run your packet analysing software. In this section you should document everything that looks suspicious and try to explain what happened.
Recommendations on how to mitigate threats and improve security - This section should include an explanation and justification of any recommended security measures or procedures based on the attack which happened and other similar attacks that the Medical Centre may be susceptible to. This section should include addressing concerns about the nature of the attack/breach, and what can be done to directly address this issue in future. This section should discuss both technical and non-technical security measures and should relate to academic literature.
Conclusion
References
Assessment Criteria
Marks will be awarded for the accuracy and level of detail explaining what happened in the attack, and for the general quality of your report. It is expected that where applicable, you will relate your report to tools, methods and content discussed throughout the module, to academic literature, reports of attacks in the sector, and any relevant guidelines/standards. Higher marks are awarded where there is greater justification of points made, greater relevancy of points to the case provided, and where limitations and alternatives are also discussed.
Open the pcap file within a Linux virtual machine such as Kali Linux!
Related categories:
Web Security
Health & Medicine
Report Writing
Research Writing
Internet Security