need it within 20 hours

profileLover boy
BN305-Assignment1_T1_2019.pdf

Prepared by: Dr Ghassan Kbar Moderated by: Dr Noor-U-Zaman Laghari March, 2019

Assessment Details and Submission Guidelines

Unit Code BN305 – T1 2019

Unit Title Virtual Private Networks

Assessment Type Individual Assignment

Assessment Title Assignment 1 – SSL/TLS VPN Technologies

Purpose of the assessment (with ULO Mapping)

The purpose of this assignment is to review existing literatures on important

VPN technologies and issues and write a report. The report must be specific

to the given topics, use appropriate examples and detail of the topic given to

develop a review paper. In preparing the assignment, students should acquire

not only the knowledge of current technical aspects of VPN but also research,

data collection, analysis and writing skills. Students should be able to

demonstrate their achievements in the following unit learning outcomes:

a. Explain the significance of VPN for contemporary organisations

b. Discuss the role of VPN to support the security of businesses

Weight 15% of the total assessments

Total Marks 100

Word limit 1800 words max

Due Date 29/4/ 2019, 11:55 PM. (Week 7)

Submission Guidelines

 All work must be submitted on Moodle by the due date along with a completed Assignment Cover Page.

 The assignment must be in MS Word format, 1.5 spacing, 11-pt Calibri (Body) font and 2 cm margins on all four sides of your page with appropriate section headings.

 Reference sources must be cited in the text of the report and listed appropriately at the end in a reference list using IEEE referencing style.

Extension If an extension of time to submit work is required, a Special Consideration Application must be submitted directly through AMS. You must submit this application within three working days of the assessment due date. Further information is available at: http://www.mit.edu.au/about-mit/institute-publications/policies- procedures-and-guidelines/specialconsiderationdeferment

Academic Misconduct

Academic Misconduct is a serious offence. Depending on the seriousness of the case, penalties can vary from a written warning or zero marks to exclusion from the course or rescinding the degree. Students should make themselves familiar with the full policy and procedure available at: http://www.mit.edu.au/about-mit/institute-publications/policies- procedures-and-guidelines/Plagiarism-Academic-Misconduct-Policy- Procedure. For further information, please refer to the Academic Integrity Section in your Unit Description.

BN305 Virtual Private Networks Page 2 of 5

Prepared by: Dr Ghassan Kbar Moderated by: Dr Noor-U-Zaman Laghari March, 2019

Assignment Questions:

Objective: Your tasks are to analyse and to write a report about the processes and the security

technologies being used when you access any website (which uses HTTPS) online via a web

browser. It is a well-known fact that the Internet is a public network and every single message you

exchange with the server can potentially be intercepted by attackers. You need to analyse in detail

what technologies and techniques are used to prevent attackers from modifying the

communication between you and web server and what keeps your passwords and other details

safe.

A. You need to explain the significance of VPN for contemporary organisations. This should include

a comparison of SSL/VPN and IPSEC/VPN

b. Discuss the role of VPN to support the security of businesses, and describe the advantages

of SSL/VPN over IPSEC/VPN

You are also required to address the following topics and task in details in relation to SSL/VPN in your report:

Authentication and Access Control

1. Analyse and write report on how the browser ensures that it is communicating to the right

server. Please visit a website and add screenshots also highlighting the related part. How SSL

and TLS provide authentication?

2. Describe how digital signatures work and what is role in authentication process, add the

relevant screenshot from your web browser showing the details of signature. What happens

during certificate verification?

3. Analyse and write report on how the server make sure that it is communicating to the right

client, discuss several methods; e.g. if you are using MIT Moodle, how the server verifies that

it’s actually YOU?

4. Explain the centralized access control for a variety of organizational resources and how

SSL/VPN help in this regards.

5. Describe the Network access control for SSL/VPN.

Confidentiality and Integrity

1. Analyse and write a report on how the confidentiality and integrity is achieved in SSL

communication, and how server & client agree on one cipher suit?

2. Explain what the role of symmetric encryption and hash algorithms in SSL communication is.

Add take screenshots from your browser showing symmetric encryption and hash details.

3. Describe the VPN client software options

4. Describe the VPN client OS support

BN305 Virtual Private Networks Page 3 of 5

Prepared by: Dr Ghassan Kbar Moderated by: Dr Noor-U-Zaman Laghari March, 2019

5. Describe the Support for simultaneous users at VPN

Anti-Replay

1. Analyse and write a report on how the anti-replay attacks are mitigated in SSL

communication.

2. How to protect your organization against SSL attacks?

Instructions

1. To enhance your understanding of the technology in this report you are required to describe how the technology works theoretically, as well as you need to perform some small practical activities and include the screenshots and the descriptions of them. The questions are organized in the logical order, however to make them easy to distinguish, the analytical questions are presented in blue and the practical questions are presented in green.

2. Include cover page with the subject name, the assignment name, the student name and ID, submission date.

3. Include table of contents. 4. Include table of figures. 5. Ensure that all the figures are numbered and names. You have to refer to the figures you

add in the contexts. 6. Strictly follow the IEEE reference format for in-body citations and the references section. 7. You can use trustable online resources and documentations from well-known technology

companies such as Microsoft, Cisco, Juniper and etc. 8. No plagiarism is allowed. 9. There are no limitations to the minimum and maximum word counts included in this

assignment. However, it is expected that the report is correct, it is written to the point and using the right technical terminologies. Hence, a good report would include around 1800 words.

BN305 Virtual Private Networks Page 4 of 5

Prepared by: Dr Ghassan Kbar Moderated by: Dr Noor-U-Zaman Laghari March, 2019

Marking Criteria: Marking of assignment1 would be done by tutors and then verified

according to individual demonstration by students. The final mark might be reduced to half based

on students’ presentation.

Questions Description Marks

Formatting Cover page, fonts, sizes, spacing, captions, headings. 3

Table of

Contents and

Table of Figures

Table of Contents and Table of Figures.

2

Introduction Outline of the report and specify the scope of your report.

10

Authentication

& Access

Control

Students need to complete theoretical and practical tasks outlined in

the assignment description.

30

Confidentiality

and Integrity

Processes

Students need to complete theoretical and practical tasks outlined in

the assignment description.

30

Protection

against Replay

Attacks

Students need to complete to complete theoretical tasks outlined in

the assignment description.

10

Conclusion Write summary of the report.

10

References Follow IEEE reference style and use references from trustworthy sources.

5

Total 100

BN305 Virtual Private Networks Page 5 of 5

Prepared by: Dr Ghassan Kbar Moderated by: Dr Noor-U-Zaman Laghari March, 2019

Marking Rubric

Sections Excellent Good Fair Poor

Formatting Completely follows the formatting instructions

Mostly follows

formatting

Acceptably following

the instructions

Clearly lacks

formatting

instructions

Table of contents Highly appropriate

names for

chapters and

figures

Appropriate

names for

chapters and

figures.

Acceptably

appropriate names for

chapters and figures.

Misses names of

chapters and

figures

Introduction Highly appropriate and clear

Appropriate and

clear

Appropriate but

contains ambiguities

Not valid and

not appropriate

Authentication All elements are

present and highly

valid

All elements are

present and valid

Either some of the

elements are missed or

a few of the elements

are invalid.

Lacks elements

and generally

invalid

Confidentiality

and Integrity

All elements are

present and highly

valid

All elements are

present and valid

Either some of the

elements are missed or

a few of the elements

are invalid.

Lacks elements

and generally

invalid

Anti-replay

Attacks

All elements are

present and highly

valid

All elements are

present and valid

Either some of the

elements are missed or

a few of the elements

are invalid.

Lacks elements

and generally

invalid

Conclusion Highly appropriate

and clear

Appropriate and

clear

Appropriate but

contains ambiguities

Not valid and

not appropriate

References Clear styles with

excellent source of

references.

Clear referencing/

style

Outdated referencing /

minor styling errors

Lacks

consistency with

many errors