Digital Security Assignment Computer Science

profilecustardo
mod003264_digitalsecurity_mg.pdf

MOD003264 – Digital Security

AMW/DS/V1.0 Page 1 of 25 2/22/2016

Digital Security

Department: Computing and Technology Module Code: MOD003264 Level:5 Academic Year: 2015/16 Semester: 2

MOD003264 – Digital Security

AMW/DS/V1.0 Page 2 of 25 2/22/2016

1 Key Information ................................................................................................ 3 2 Introduction to the Module ................................................................................ 4 3 Intended Learning Outcomes............................................................................ 5 4 Outline Delivery ................................................................................................ 6 5 Module Operation............................................................................................. 7 5.1 Attendance Requirements.......................................................................... 7 5.2 Behaviour in Lectures and Teaching Sessions........................................... 7 5.3 Lecture notes:............................................................................................ 8 5.4 Support Materials....................................................................................... 8

6 Assessment...................................................................................................... 9 6.1 Assessment Components .......................................................................... 9 6.2 Feedback................................................................................................. 11

7 How is My Work Marked?............................................................................... 13 8 Assessment Offences..................................................................................... 17 9 Learning Resources........................................................................................ 20 9.1 Recommended Texts............................................................................... 20 9.2 Recommended Internet Resources.......................................................... 20 9.3 Other Resources...................................................................................... 20

10 Module Evaluation .......................................................................................... 21 11 Links to Other Key Information ....................................................................... 22 12 Report on Last Delivery of Module.................................................................. 24

MOD003264 – Digital Security

AMW/DS/V1.0 Page 3 of 25 2/22/2016

1 Key Information Module: Digital Security Module Leader: Adrian Winckles BEng(Hons) MSc CEng CITP MBCS Leader Title: Course Leader in Information Security and Forensic

Computing Module Lecturer: Mark Graham MSc Room: COM308 Office Hour: By appointment only Email: [email protected]

Every module has a Module Definition Form (MDF) which is the officially validated record of the module. You can access the MDF for this module in three ways: • the Virtual Learning Environment (VLE) • the My.Anglia Module Catalogue at www.anglia.ac.uk/modulecatalogue • Anglia Ruskin’s module search engine facility at

www.anglia.ac.uk/modules All modules delivered by Anglia Ruskin University at its main campuses in the UK and at partner institutions throughout the UK and overseas are governed by the Academic Regulations. You can view these at www.anglia.ac.uk/academicregs. A printed extract of the Academic Regulations, known as the Assessment Regulations, is available for every student from your Faculty Office (COS010)(all new students will have received a copy as part of their welcome pack). In the unlikely event of any discrepancy between the Academic Regulations and any other publication, including this module guide, the Academic Regulations, as the definitive document, take precedence over all other publications and will be applied in all cases.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 4 of 25 2/22/2016

2 Introduction to the Module ‘Digital Security' is essentially about giving individuals the freedom to embrace the digital lifestyle, confidently engaging in everyday interactions across all digital devices with a certainty that the accessibility and integrity of the data is ensured. Digital security affects all aspects of the digital lifestyle, which, among others, comprises computers and the internet, telecommunications, financial transactions, transportation, healthcare, and secure access. This module essentially covers these broad topic areas:

• Computer Security Principles covers security objectives such as authentication, authorization, access control, confidentiality, data integrity, and non-repudiation. The module also introduces fundamental software design principles such as that of least privilege, fail-safe stance, and defence-in-depth.

• Introduction to Cryptography covers both symmetric encryption and public-key cryptography, discussing how they are used to achieve security goals and build PKI (Public-Key Infrastructure) systems. Technologies covered are typically DES, 3DES, AES, RC4, RSA, ECC, MD5, SHA-1, X.509, digital signatures, and all cryptographic primitives necessary to understand PKI. Diffie-Hellman key exchange and man- in-the-middle attacks will also be discussed.

• Secure Programming Techniques discusses the threats that worms and hackers present to software and the programming techniques that developers can use to defend against software vulnerabilities such as buffer overflows, SQL injection, and off-line dictionary attacks.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 5 of 25 2/22/2016

3 Intended Learning Outcomes

On successful completion of this module the student will be expected to be able to:

Knowledge and understanding

1. Compare and contrast the use of cryptographic techniques for ensuring the confidentiality, integrity and availability of user data whether in transit, processing or storage.

2. Critically analyse and appraise both the use of and application of cryptographic techniques that should be applied in certain case study scenarios such as trusted computing.

Intellectual, practical, affective and transferable skills

3. Demonstrate how digital data security can be achieved in given scenario so that the principles of security are maintained.

4. Configure and implement key digital security techniques to protect web servers and web applications from common vulnerabilities and security issues.

Both the formal log book approach with lab exercises and the formal assessment provide the student with the opportunity to meet all the formal outcomes. Additional learning material is provided to the student to help them meet the 150 guided learning hours for the module through their own study time. Students are encouraged to take responsibility for their individual study and preparation for labs. They must be proactive and work in their own time as well as during the timetabled classes.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 6 of 25 2/22/2016

4 Outline Delivery

The schedule below indicates the material which should be covered each week though there may be enforced changes to this schedule. Any changes to this schedule will be documented on the VLE site wherever possible. There are also details of the background reading associated with each week’s material. As part of the learning and teaching methodology of the module you are required to complete a number of practical laboratory activities. These labs underpin the theoretical material covered in the course and some of them are required to be completed as part of the module assessment. Lab activity should be recorded through a logbook that will be assessed and recorded by the module tutor.

Week Lecture Lab Activities

1

Digital Security Fundamentals Introduction to NETLAB Capturing Network Traffic

2

Introduction to Cryptographic Principles

Protocols and Default Network Ports– Transferring Data using TCP/IP

3

Symmetric Encryption Cryptography

4

Asymmetric Encryption Protocols and Default Network Ports – Connecting to a Remote System

5

Secure Hash Functions Analyse and Differentiate Type of Attacks using Window Command Lines

6

Public Key Infrastructures and Certificate Authorities

Authentication, Authorisation and Access Control

7

Digital Signatures Mitigation and Deterrent Techniques – Password Cracking

8

Trusted Computing and Anonymous Systems

Discovering Security Threats and Vulnerabilities

9

Virtual Private Networks Incident Response Procedures

10

Securing Web Servers and Web Applications (Part 1)

Mitigation and Deterrent Techniques – Anti-Forensic

11

Securing Web Servers and Web Applications (Part 2)

Assignment Workshop

12

Module Review Assignment Workshop

MOD003264 – Digital Security

AMW/DS/V1.0 Page 7 of 25 2/22/2016

5 Module Operation Each session will be divided into two parts. The first one will be the lecture and the second a seminar or discussion. Any examples, ideas, experiences that you can offer personally will of course be welcomed. Each Week in Semester 1, formal teaching will consist of

• One Lecture, of 1 hours duration. (Total of 12)

• One Practical of 2 hours duration, (Total of 12)

5.1 Attendance Requirements

Attending all your classes is very important and one of the best ways to help you succeed in this module. In accordance with the Student Charter, you are expected to arrive on time and take an active part in all your timetabled classes. If you are unable to attend a class for a valid reason (e.g.: illness), please contact your Module Tutor. Anglia Ruskin will closely monitor the attendance of all students and will contact you by e-mail if you have been absent without notice for two weeks. Continued absence can result in the termination of your registration as you will be considered to have withdrawn from your studies. International students who are non-EEA nationals and in possession of entry clearance/leave to remain as a student (student visa) are required to be in regular attendance at Anglia Ruskin. Failure to do so is considered to be a breach of the immigration regulations. Anglia Ruskin, like all British Universities, is statutorily obliged to inform the Border and Immigration Agency of the Home Office of significant unauthorised absences by any student visa holders.

5.2 Behaviour in Lectures and Teaching Sessions

Disruptive behaviour including the following: talking, eating, leaving the lecture (without just cause) and any use of mobile phones are not tolerated during lectures, or in laboratory or other teaching sessions. Please ensure all mobiles are turned off prior to entering a lecture, no personal stereos/CD Players or MP3 players will be allowed and if you intend doing other work within the lecture, please do not attend as you will be asked to leave. Lecturers are empowered to stop the teaching session immediately if any students are not complying with this policy. Members of staff can request the University ID card from offending students, which will be returned to the student later. Failure to present the card means the student can be removed

MOD003264 – Digital Security

AMW/DS/V1.0 Page 8 of 25 2/22/2016

from the teaching environment and appropriate steps taken for the purposes of identifying the student. Any students identified as infringing this rule will be automatically referred as per university regulations. Please ensure you turn up to the lecture on time, if you are more than 10 minutes late, please do come into the lecture as you will disrupt others.

5.3 Lecture notes:

You are expected to make your own but copies of Powerpoint’s will be available on the VLE either before or shortly after depending on whether alterations have been made. It is expected that additional discussion during lectures and seminars will not be documented and students will be expected to listen and make notes of the additional material.

5.4 Support Materials

Additional Support Materials will be made available on a week by week basis within the VLE. This will consist of lab materials, case studies, user guides, templates and other examples.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 9 of 25 2/22/2016

6 Assessment All coursework assignments and other forms of assessment must be submitted by the published deadline which is detailed above. It is your responsibility to know when work is due to be submitted – ignorance of the deadline date will not be accepted as a reason for late or non-submission. Most student work which contributes to the eventual outcome of the module (i.e.: if it determines whether you will pass or fail the module and counts towards the mark you get for the module) is submitted via the iCentre using the formal submission sheet Academic staff CANNOT accept work directly from you. The only exception to this is for online proposals and discussion forum entries within the VLE. If you decide to submit your work to the iCentre by post, it must arrive by midday on the due date. If you elect to post your work, you do so at your own risk and you must ensure that sufficient time is provided for your work to arrive at the iCentre Posting your work the day before a deadline, albeit by first class post, is extremely risky and not advised. Any late work (submitted in person, online or by post) will NOT be accepted and a mark of zero will be awarded for the assessment task in question. You are requested to keep a copy of your work.

6.1 Assessment Components

The assessment for this module will be in multiple parts:

DESCRIPTIVE TITLE

Research based assignment presented as a formal report (worth 100% of the assessment marks).

Assessment Element

010

DETAILS ABOUT THE

ASSESSMENT

The module lectures cover three topic areas:

• Computer Security Principles

• Introduction to Cryptography

• Secure Programming Techniques

Three questions will be provided based upon content covered in the lectures.

You should answer ALL THREEALL THREEALL THREEALL THREE questions.

The assignment will specify a different scenario on which to base the context of

your answers, such as a University, Hospital or Council. Whilst your target

audience has some level of IT knowledge, they have employed you as the

subject expert. Answers to each question should be provided at a level of

technical detail sufficient to that target audience in the given scenario.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 10 of 25 2/22/2016

You should apply the knowledge gained from the lectures, and compliment this

with your own research in order to demonstrate an understanding of the subject

material, explaining the technology and how it applies to the context of the

given scenario, providing suitable examples where appropriate.

Learning Outcomes 1 - 4 Weighting 100% Marking Approach

Fine Grade

WHAT IS BEING SUBMITTED

You should compile a well-constructed, formal

written report that encompasses industry

standard fundamental digital security best

practices.

Each of the THREE answers carry a maximum of

25 marks each, with 10 marks for report

presentation and 15 marks for quality of

referencing.

Your report should be written in the third

person and the body of the report must be no

more than 2,000 words. Your report findings

should be backed up with solid references,

given in Harvard format.

Your work should be spiral or comb bound with

the following minimum components:

� Cover Page to include

o Module title

o Course code

o Your Student ID number

o Date of submission

� Table of Contents

� Body of your report (2,000 word guide)

� Any supporting diagrams and tables

� A minimum of 8 references (Harvard

reference style)

� Appendices (if appropriate)

Qualifying Mark

30%

SUBMISSION Date: 9/05/16 Time: 14:00 Location iCentre

MARKER(S): Mark Graham

MODERATOR(S): Adrian Winckles

FEEDBACK By Date: 7/06/16 Where to get your feedback

By Email

MOD003264 – Digital Security

AMW/DS/V1.0 Page 11 of 25 2/22/2016

DESCRIPTIVE TITLE

Lab Portfolio (Pass/Fail) Assessment Element

011

DETAILS ABOUT THE

ASSESSMENT

10 lab exercises based upon IT vulnerability discovery, mitigation and good

practise security techniques will be provided. In order to pass the lab assessment

you must complete a minimum of 80% of the 10 exercises to the lab tutor’s

satisfaction.

You are expected to maintain an engineering lab book (either paper or digital)

containing evidence of the completed exercises, screen shots, what you have

learnt and any further research undertaken.

As part of the assessment you are required to hand in formal proof that you

have completed these exercises in the form of a Lab Completion sign-off sheet,

provided by the tutor. Each week your tutor will inspect your lab book and sign-

off the exercise on a pass/fail basis. Do not lose this sheet as this is your

evidence of completing the lab assessment.

Learning Outcomes 1 – 4 Weighting 0% Marking Approach

Pass/Fail

WHAT IS BEING SUBMITTED

Lab Completion sign-off sheet (including

evidence of any exercises not completed).

At the end of the module, EIGHT lab books will

be chosen at random from the entire cohort for

submission. Lab books are to be submitted

either as a paper copy, on USB or disk.

Qualifying Mark

100%

SUBMISSION Date: 9/05/16 Time: 14:00 Location iCentre

MARKER(S): Mark Graham

MODERATOR(S): Adrian Winckles

FEEDBACK By Date: 7/06/16 Where to get your feedback

During the weekly lab sessions.

6.2 Feedback

You are entitled to written feedback on your performance for all your assessed work. For all assessment tasks which are not examinations, this is provided by a member of academic staff completing the assignment coversheet on which your mark and feedback will relate to the achievement of the module’s intended learning outcomes and the assessment criteria you were given for the task when it was first issued. Examination scripts are retained by Anglia Ruskin and are not returned to students. However, you are entitled to feedback on your performance in an

MOD003264 – Digital Security

AMW/DS/V1.0 Page 12 of 25 2/22/2016

examination and may request a meeting with the Module Leader or Tutor to see your examination script and to discuss your performance. Anglia Ruskin is committed to providing you with feedback on all assessed work within 20 working days of the submission deadline or the date of an examination. This is extended to 30 days for feedback for a Major Project module (please note that working days excludes those days when Anglia Ruskin University is officially closed; e.g.: between Christmas and New Year). At the main Anglia Ruskin University campuses, each Faculty will publish details of the arrangement for the return of your assessed work (e.g.: a marked essay or case study etc.). Work which is not collected by you from the Faculty within this timeframe is returned to the iCentres from where you can subsequently collect it. The iCentres retain student work for a specified period prior to its disposal To assure ourselves that our marking processes are comparable with other universities in the UK, Anglia Ruskin provides samples of student assessed work to external examiners as a routine part of our marking processes. External examiners are experienced academic staff from other universities who scrutinise your work and provide Anglia Ruskin academic staff with feedback and advice. Many of Anglia Ruskin’s staff act as external examiners at other universities. On occasion, you will receive feedback and marks for pieces of work that you completed in the earlier stages of the module. We provide you with this feedback as part of the learning experience and to help you prepare for other assessment tasks that you have still to complete. It is important to note that, in these cases, the marks for these pieces of work are unconfirmed as the processes described above for the use of external examiners will not have been completed. This means that, potentially, marks can change, in either direction! Marks for modules and individual pieces of work become confirmed on the Dates for the Official Publication of Results which can be checked at www.anglia.ac.uk/results.

Marks for modules and individual pieces of work become confirmed on the Dates for the Official Publication of Results which can be checked at www.anglia.ac.uk/results.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 13 of 25 2/22/2016

7 How is My Work Marked?

After you have handed your work in or you have completed an examination, Anglia Ruskin undertakes a series of activities to assure that our marking processes are comparable with those employed at other universities in the UK and that your work has been marked fairly and honestly. These include:

• Anonymous marking – your name is not attached to your work so, at the point of marking, the lecturer does not know whose work he/she is considering. When you undertake an assessment task where your identity is known (eg: a presentation or Major Project), it is marked by more than one lecturer (known as double marking)

• Internal moderation – a sample of all work for each assessment task in each module is moderated by other Anglia Ruskin staff to check the marking standards and consistency of the marking

• External moderation – a sample of student work for all modules is moderated by external examiners – experienced academic staff from other universities (and sometimes practitioners who represent relevant professions) - who scrutinise your work and provide Anglia Ruskin academic staff with feedback, advice and assurance that the marking of your work is comparable to that in other UK universities. Many of Anglia Ruskin’s staff act as external examiners at other universities.

• Departmental Assessment Panel (DAP) – performance by all students on all modules is discussed and approved at the appropriate DAPs which are attended by all relevant Module Leaders and external examiners. Anglia Ruskin has over 25 DAPs to cover all the different subjects we teach.

This module falls within the remit of the Computing & Technology (Cambridge) DAP.

The following external examiners are appointed to this DAP and will oversee the assessment of this and other modules within the DAP’s remit:

External Examiner’s Name

Academic Institution Position or Employer

Prof. Merlyne De Souza Sheffield University Professor

Prof. Steven Furnell Plymouth University Professor

Dr. Gerhard Hancke City University of Hong Kong Assistant Professor

Dr. Eric Chowanietz De Montfort University Principal Lecturer

Mr. Steven Bennett University of Hertfordshire Principal Lecturer

Mr. Andrew Smith Open University Senior Lecturer

Mr. Islah (Izzy) Ali- MacLachlan

Birmingham City University Senior Lecturer

MOD003264 – Digital Security

AMW/DS/V1.0 Page 14 of 25 2/22/2016

The above list is correct at the time of publication. However, external examiners are appointed at various points throughout the year. An up-to-date list of external examiners is available to internal browsers only at www.anglia.ac.uk/eeinfo. Anglia Ruskin’s marking process is represented in the flowchart below:

MOD003264 – Digital Security

AMW/DS/V1.0 Page 15 of 25 2/22/2016

Student submits

Work collated and passed to Module

Work is marked by Module Leader and Module Tutor(s)

1 . All

Internal moderation samples selected.

Unconfirmed marks and feedback to students within 20

External moderation samples selected

Marks submitted to DAP

5 for

Marks Approved by DAP

5 and forwarded

Any issues?

Any issues?

Students receive initial

Confirmed marks

issued to

M a rk in g S ta g e

In te rn a l M o d e ra ti o n

E x te rn a l

D A P

4 S ta g e

YE

YE

NO

NO

1 All work is marked anonymously or double marked where identity of

the student is known (eg: in a presentation) 2 The internal (and external) moderation process compares work from

all locations where the module is delivered (eg: Cambridge, Chelmsford, Peterborough, Malaysia, India, Trinidad etc.)

3 The sample for the internal moderation process comprises a minimum

of eight pieces of work or 10% (whichever is the greater) for each

Flowchart of Anglia Ruskin’s

MOD003264 – Digital Security

AMW/DS/V1.0 Page 16 of 25 2/22/2016

ANGLIA RUSKIN UNIVERSITY GENERIC ASSESSMENT CRITERIA AND MARKING STANDARDS - LEVEL 6 (was level 3)

Level 6 is characterised by an expectation of students’ increasing autonomy in relation to their study and developing skill sets.

Students are expected to demonstrate problem solving skills, both theoretical and practical. This is supported by an understanding of appropriate theory; creativity of expression and thought based in individual judgement; and the ability to seek out, invoke, analyse and evaluate competing theories or methods of working in a critically constructive and open manner. Output is articulate, coherent and skilled in the appropriate medium, with some students producing original or innovative work in their specialism.

Generic Learning Outcomes (GLOs) (Academic Regulations, Section 2)

Mark Bands Outcome Knowledge & Understanding

Intellectual (thinking), Practical, Affective and Transferable Skills

90-100%

Exceptional information base exploring and analysing the discipline, its theory and ethical issues with extraordinary originality and autonomy. Work may be considered for publication within Anglia Ruskin University

Exceptional management of learning resources, with a higher degree of autonomy/exploration that clearly exceeds the assessment brief. Exceptional structure/accurate expression. Demonstrates intellectual originality and imagination. Exceptional team/practical/professional skills. Work may be considered for publication within Anglia Ruskin University

80-89% Outstanding information base exploring and analysing the discipline, its theory and ethical issues with clear originality and autonomy

Outstanding management of learning resources, with a degree of autonomy/exploration that clearly exceeds the assessment brief. An exemplar of structured/accurate expression. Demonstrates intellectual originality and imagination. Outstanding team/practical/professional skills

70-79%

Excellent knowledge base that supports analysis, evaluation and problem-solving in theory/practice/ethics of discipline with considerable originality

Excellent management of learning resources, with degree of autonomy/research that may exceed the assessment brief. Structured and creative expression. Very good academic/ intellectual skills and practical/team/professional/problem-solving skills

60-69% Good knowledge base that supports analysis, evaluation and problem-solving in theory/ practice/ethics of discipline with some originality

Good management of learning resources, with consistent self- directed research. Structured and accurate expression. Good academic/intellectual skills and team/practical/ professional/problem solving skills

50-59%

Achieves module outcome(s) related to GLO at this level

Satisfactory knowledge base that supports some analysis, evaluation and problem-solving in theory/practice/ethics of discipline

Satisfactory management of learning resources. Some autonomy in research but inconsistent. Structured and mainly accurate expression. Acceptable level of academic/ intellectual skills going beyond description at times. Satisfactory team/practical/professional/problem-solving skills

40-49%

A marginal pass in module outcome(s) related to GLO at this level

Basic knowledge base with some omissions at the level of theoretical/ethical issues. Restricted ability to discuss theory and/or or solve problems in discipline

Basic use of learning resources with little autonomy. Some difficulties with academic/intellectual skills. Some difficulty with structure/accuracy in expression, but evidence of developing team/practical/professional/problem-solving skills

30-39%

A marginal fail in module outcome(s) related to GLO at this level. Possible compensation. Sat- isfies qualifying mark

Limited knowledge base. Limited understanding of discipline/ethical issues. Difficulty with theory and problem solving in discipline

Limited use of learning resources. Unable to work autonomously. Little input to teams. Weak academic/ intellectual skills. Still mainly descriptive. General difficulty with structure/accuracy in expression. Practical/professional/ problem-solving skills that are not yet secure

20-29% Little evidence of knowledge base. Little evidence of understanding of discipline/ethical issues. Significant difficulty with theory and problem solving in discipline

Little evidence of use of learning resources. Unable to work autonomously. Little input to teams. Very weak academic/ intellectual skills. Work significantly descriptive. Significant difficulty with structure/accuracy in expression. Little evidence of practical/professional/problem-solving skills

10-19% Inadequate knowledge base. Inadequate understanding of discipline/ethical issues. Major difficulty with theory and problem solving in discipline

Inadequate use of learning resources. Unable to work autonomously. Inadequate input to teams. Extremely weak academic/intellectual skills. Work significantly descriptive. Major difficulty with structure/accuracy in expression. Inadequate practical/professional/ problem-solving skills

1-9% No evidence of knowledge base; no evidence of understanding of discipline/ethical issues. Total inability with theory and problem solving in discipline

No evidence of use of learning resources. Completely unable to work autonomously. No evidence of input to teams. No evidence of academic/intellectual skills. Work wholly descriptive. Incoherent structure/accuracy and expression. No evidence of practical/professional/ problem-solving skills

C h a ra c te ri s ti c s o f S tu d e n t A c h ie v e m e n t b y M

a rk in g B a n d

0%

Fails to achieve module outcome(s) related to this GLO. Qualifying mark not satisfied. No compensation available

Awarded for: (i) non-submission; (ii) dangerous practice and; (iii) in situations where the student fails to address the assignment brief (eg: answers the wrong question) and/or related learning outcomes

MOD003264 – Digital Security

AMW/DS/V1.0 Page 17 of 25 2/22/2016

8 Assessment Offences As an academic community, we recognise that the principles of truth, honesty and mutual respect are central to the pursuit of knowledge. Behaviour that undermines those principles diminishes the community, both individually and collectively, and diminishes our values. We are committed to ensuring that every student and member of staff is made aware of the responsibilities s/he bears in maintaining the highest standards of academic integrity and how those standards are protected. You are reminded that any work that you submit must be your own. When you are preparing your work for submission, it is important that you understand the various academic conventions that you are expected to follow in order to make sure that you do not leave yourself open to accusations of plagiarism (eg: the correct use of referencing, citations, footnotes etc.) and that your work maintains its academic integrity. Definitions of Assessment Offences Plagiarism Plagiarism is theft and occurs when you present someone else’s work, words, images, ideas, opinions or discoveries, whether published or not, as your own. It is also when you take the artwork, images or computer-generated work of others, without properly acknowledging where this is from or you do this without their permission. You can commit plagiarism in examinations, but it is most likely to happen in coursework, assignments, portfolios, essays, dissertations and so on. Examples of plagiarism include:

• directly copying from written work, physical work, performances, recorded work or images, without saying where this is from;

• using information from the internet or electronic media (such as DVDs and CDs) which belongs to someone else, and presenting it as your own;

• rewording someone else’s work, without referencing them; and

• handing in something for assessment which has been produced by another student or person.

It is important that you do not plagiarise – intentionally or unintentionally – because the work of others and their ideas are their own. There are benefits to producing original ideas in terms of awards, prizes, qualifications, reputation and so on. To use someone else’s work, words, images, ideas or discoveries is a form of theft. Collusion Collusion is similar to plagiarism as it is an attempt to present another’s work as your own. In plagiarism the original owner of the work is not aware you are using it, in collusion two or more people may be involved in trying to produce one piece of work to benefit one individual, or plagiarising another person’s work.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 18 of 25 2/22/2016

Examples of collusion include:

• agreeing with others to cheat;

• getting someone else to produce part or all of your work;

• copying the work of another person (with their permission);

• submitting work from essay banks;

• paying someone to produce work for you; and

• allowing another student to copy your own work. Many parts of university life need students to work together. Working as a team, as directed by your tutor, and producing group work is not collusion. Collusion only happens if you produce joint work to benefit of one or more person and try to deceive another (for example the assessor). Cheating Cheating is when someone aims to get unfair advantage over others. Examples of cheating include:

• taking unauthorised material into the examination room;

• inventing results (including experiments, research, interviews and observations);

• handing your own previously graded work back in;

• getting an examination paper before it is released;

• behaving in a way that means other students perform poorly;

• pretending to be another student; and

• trying to bribe members of staff or examiners. Help to Avoid Assessment Offences Most of our students are honest and want to avoid making assessment offences. We have a variety of resources, advice and guidance available to help make sure you can develop good academic skills. We will make sure that we make available consistent statements about what we expect. You will be able to do tutorials on being honest in your work from the library and other central support services and faculties, and you will be able to test your written work for plagiarism using ‘Turnitin®UK’ (a software package that detects plagiarism). You can get advice on how to honestly use the work of others in your own work from the library website (www.libweb.anglia.ac.uk/referencing/referencing.htm) and your lecturer and personal tutor. You will be able to use ‘Turnitin®UK’, a special software package which is used to detect plagiarism. Turnitin®UK will produce a report which clearly shows if passages in your work have been taken from somewhere else. You may talk about this with your personal tutor to see where you may need to improve your academic practice. We will not see these formative Turnitin®UK reports as assessment offences. If you are not sure whether the way you are working meets our requirements, you should talk to your personal tutor, module tutor or other member of academic staff. They will be able to help you and tell you about other resources which will help you develop your academic skills.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 19 of 25 2/22/2016

Procedures for assessment offences An assessment offence is the general term used to define cases where a student has tried to get unfair academic advantage in an assessment for himself or herself or another student. We will fully investigate all cases of suspected assessment offences. If we prove that you have committed an assessment offence, an appropriate penalty will be imposed which, for the most serious offences, includes expulsion from Anglia Ruskin. For full details of our assessment offences policy and procedures, see the Academic Regulations, section 10 at: www.anglia.ac.uk/academicregs To see an expanded version of this guidance which provides more information on how to avoid assessment offences, visit www.anglia.ac.uk/honesty

MOD003264 – Digital Security

AMW/DS/V1.0 Page 20 of 25 2/22/2016

9 Learning Resources

9.1 Recommended Texts

Anderson, Ross, Security Engineering, Wiley, 2nd Edition, 2008.

First edition available by free download at http://www.cl.cam.ac.uk/~rja14/book.html

Ferguson, N, Kohno, T & Schneier, B, Cryptography Engineering: Design Principles

and Practical Applications, Wiley, 2010

9.2 Recommended Internet Resources

SANS Institute

http://www.sans.org/network_security.php

Lots of free training material, links etc

OWASP (Open Web Application Security Project)

http://www.owasp.org

Please note OWASP resources are essential reading for the later weeks of the course.

9.3 Other Resources

Sharepoint VLE

https://vle.anglia.ac.uk/modules/2015/MOD003264/

There is a dedicated VLE for this course. The VLE provides access to all of the

resources for this course including a copy of the assignment. Your normal Anglia

Ruskin login is used to access these resources.

NETLAB (http://cam-netlab.computing.anglia.ac.uk)

NETLAB is a proprietary remote network lab solution. It provides students with the

ability to access real networking equipment and virtual systems remotely. A Student

Guide to NETLAB is available from the manufacturer (www.netdevgroup.com) and

on the course pages of the VLE.

Students will be expected to carry out some lab exercises either in the lab or using

resources such as Netlab remotely

.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 21 of 25 2/22/2016

10 Module Evaluation

During the second half of the delivery of this module, you will be asked to complete a

module evaluation questionnaire to help us obtain your views on all aspects of the

module.

This is an extremely important process which helps us to continue to improve the

delivery of the module in the future and to respond to issues that you bring to our

attention. The module report in section 11 of this module guide includes a section

which comments on the feedback we received from other students who have studied

this module previously.

Your questionnaire response is anonymous.

Please help us to help you and other students at Anglia Ruskin by completing the

Module Evaluation process. We very much value our students’ views and it is very

important to us that you provide feedback to help us make improvements.

In addition to the Module Evaluation process, you can send any comment on anything

related to your experience at Anglia Ruskin to [email protected] at any time.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 22 of 25 2/22/2016

11 Links to Other Key Information

Assessment Offences: As an academic community, we recognise that the principles of

truth, honesty and mutual respect are central to the pursuit of knowledge. Behaviour

that undermines those principles weakens the community, both individually and

collectively, and diminishes our values. There is more information on these

principles, and the types of Assessment Offences, available here. Penalties for poor

academic practice can be severe so ensure you are aware of what is expected and how

to reference correctly.

In cases where the Module Leader suspects that the assignment submitted is not the

work of the student, and may have been produced by another person, the Module

Leader informs the Director of Studies of the suspicion of an assessment offence. In

the process of considering the academic integrity of the work, the Director of Studies

may invite the student to a meeting, with the Module Leader, to answer questions

about the assignment.

There is a Guide to Good Academic Practice available.

Attendance Information: Attending all your classes is very important and one of the

best ways to help you succeed in this module. Details on Attendance Requirements.

Assessments and TurnitinUK: TurnitinUK is used for submitting the majority of your

assessments, it is important that you read the information on preparing your

assignment.

Information on submitting your assignment must be read and guidelines adhered to,

please ensure you read: https://vle.anglia.ac.uk/sites/LTA/Grademark/Content/Quick-

Start.aspx

The direct link to TurnitinUK is: http://www.turnitinuk.com

Examinations: Examinations are held in January (semester/trimester 1), May

(semester/trimester 2) and in August (trimester 3). All examinations are scheduled by

the Examinations Unit, the dates and locations will be posted on the following

website: http://web.anglia.ac.uk/anet/students/exams/

External Examiners: An up-to-date list of external examiners is available to students

and staff at http://www.anglia.ac.uk/eeinfo The external examiner for this module is

in the Computing and Technology Departmental Assessment Panel. These are

academic examiners from other institutions who independently approve and confirm

the quality and standard of our modules and assessments.

Feedback in TurnitinUK: Link to more details on the viewing feedback is here:

https://vle.anglia.ac.uk/sites/LTA/Grademark/Content/Feedback.aspx

How is My Work Marked and Flowchart of Anglia Ruskin’s Marking Process: After

you have handed your work in or you have completed an examination, Anglia Ruskin

undertakes a series of activities to assure that our marking processes are comparable

with those employed at other universities in the UK and that your work has been

marked fairly, honestly and consistently. Information about this process is available

here.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 23 of 25 2/22/2016

Module Evaluation: During the second half of the delivery of this module, you will be

asked to complete a module evaluation questionnaire to help us obtain your views on

all aspects of the module, more about this process is included here.

Reading Lists: These are now all available online: http://readinglists.anglia.ac.uk, or

follow the direct link in this guide or on the VLE.

Re-assessments: Re-assessment dates will be stated on e-vision, you can check the

specific date your re-assessment assignment is due in on: http://e-vision.anglia.ac.uk

or alternatively, if it is an examination, these are scheduled by the Examinations Unit,

the dates and locations will be posted on the following website:

http://web.anglia.ac.uk/anet/students/exams/

University Generic Assessment Criteria: The level for this module is given on the

front page of this guide. Information on the criteria that the university uses to mark

your work at this level can be found here [word document].

MOD003264 – Digital Security

AMW/DS/V1.0 Page 24 of 25 2/22/2016

12 Report on Last Delivery of Module

MODULE REPORT FORM

This form should be completed by module tutors (where there is more than one delivery) and forwarded to Module Leaders who compiles the results on to one form for use at the Programme Committee and other methods of disseminating feedback to students.

Module Code and Title: MOD003624 Digital Security Anglia Ruskin Department: Computing and Technology Location(s) of Delivery: Cambridge Academic Year: 2014-15 Semester/Trimester: 2 Enrolment Numbers (at each location): 54 Module Leader: Adrian Winckles Other Module Tutors: Mark Graham Student Achievement Provide a brief overview of student achievement on the module as evidenced by the range of marks awarded. A detailed breakdown of marks will be available at the Departmental Assessment Panel.

Generally students performed well and within tolerances. 3 students failed to submit a written report, and also failed to submit a lab book. 5 students submitted a written report, but did not submit a lab book. Of those that submitted a lab book, all but 2 attempted all 12 labs.

Feedback from Students Briefly summarise student responses, including any written comments

Most students enjoyed the module. Many felt the module was relevant to their course however it is my belief is the gaming students found the course less relevant. Attendance at the lectures remained fairly high (estimate 60-80% attendance) throughout the semester, despite a number of comments that Friday 4pm-5pm is not the ideal time to discuss complex encryption concepts. Several students regularly remained behind after lectures to discuss points of interest raised during the lecture. Students felt that mixing lecture slides with video examples helped keep the lectures interesting and relevant. Attendance at the labs was high across all 12 weeks. I estimate most students attended 10 – 12 lab sessions. A handful of students attended less than half. I know of one student that did not attend any labs. It took students a few weeks to grasp why we delivered the labs via Netlab, but once this was accepted most students agreed this was the best format to deliver labs. Feedback on the labs was very good. Only 2 students felt the labs were not relevant to the course. The remainder were happy to spend 2 hours a week on labs. Maybe as many as 20 students fed back to me that they really enjoyed the labs and learnt a great deal. 1 student claimed it was his favourite part of the week and described the labs as “brilliant”.

MOD003264 – Digital Security

AMW/DS/V1.0 Page 25 of 25 2/22/2016

Module Leader/Tutor’s Reflection on Delivery of the Module, including Response to Feedback from Students (including resources if appropriate)

I think the course was generally enjoyed by almost all students. I think the students learnt a lot, and I know 2 or 3 students found it inspirational enough to seriously consider possible careers in this field. We had some issues with Netlab, but these were overcome quite quickly. Chris Holmes support for the labs was better than excellent. The main issue with Netlab was, following an upgrade, if multiple student started a lab concurrently, the lab would crash. Once students learnt to stagger their lab start time by 5 minutes, they were generally forgiving of netlab. I was disappointed that there was no material (lectures or labs) for this module. I spent a significant part of each week writing the lectures. A lot of time was spent at the start of the semester with the module leader working out how we would deliver 12 labs, however once we decided to use Netlab, this was definitely the correct decision. The lectures were delivered in Opt103. Several students complained that this room was like a furnace. As the lecture I can agree this room was uncomfortably warm as to make it difficult to concentrate.

Developments during the current year or planned for next year (if appropriate)

A few issues with Netlab need to be sorted out. The module leader is aware of these issues.

External Examiner’s Comments State whether the external examiner agreed the marks and/or commented on the module