Questions Uploads

Testing-Framework-and-Basic-Security-Controls

SDEV 460 – Homework 2
Testing Framework and Basic Security Controls
Overview:
This homework will demonstrate your knowledge of creating a testing framework and using that
framework to conduct some basic server and web application security controls.
Assignment: Total 100 points
Using

the readings from weeks 3 and 4 as a baseline, first develop a testing

framework with these phases as guidelines for your organization or an

organization you would like to work for in the future.
• Before development begins
• During definition and design
• During development
• During deployment
• Maintenance and operations
You

will need to fill in the details for each phase by 1) describing what

each phase encompasses and 2) 3 or more activities you will engage in

for each phase. In addition, you will apply part of this framework in

the phase “During development” by engaging in three tests/security

controls outlined below to the existing SDEV virtual machine in the

default root website.
Security Controls to Test
1. Fingerprint Web Server (OTG-INFO-002)
ï‚· Use netcat, httprint or other tool to discover the web server software vendor and release. Show output of the tool output.
ï‚·

Perform online research about the discovered software vendor and

release. Report upon documented vulnerabilities with the release.
ï‚· Report upon how you would mitigate any documented vulnerabilities.
2.

Review webpage comments and metadata for information leakage

(OTG-INFO-005). Manually review the sample HTML applications in the

Apache Web Server directories
ï‚· Based upon online research, what are

three or more categories of information that would be considered

information leakage that is not acceptable?
ï‚· Review the web site to

see if there is information leakage in the SDEV information. Report upon

what you have discovered and your method of discovery.
3. Test HTTP Methods (OTG-CONFIG-006) – See which HTTP methods are available on the virtual
machine. Use Netcat or other tool against this SDEV site.
ï‚· What HTTP methods are enabled and disabled on this site? Show the output of your tool indicating the HTTP methods.
ï‚· Which methods (and why) have potentially pose a security risk for a web application. Describe
how these pose a risk.
Site Configuration:
Note: The SDEV Virtual Machine you downloaded and used for SDEV 300. The URL is here if you need to download it again: https://citeapps.umuc.edu/SDEV/
The

VM runs on the latest version of Oracle Virtual Box. Also review the

instructions for installing and configuring the VM and application under

the “Course Materials” section of the course portal. It also contains

the necessary password(s) to login as well.
Deliverables:
You should submit your source testing framework document along with the results testing the three
security

controls listed above. Screen captures should be clearly labeled

indicating exactly what the screen capture represents. Your document

should be well-organized, include page numbers, include all references

used and contain minimal spelling and grammatical errors.
Grading Rubric:
Attribute
Meets
Does not meet
Testing Framework
50 points
Develops and fills in details for the “before development begins” phase testing framework.
(10 points)
Develops and fills in details for the “during definition and design” phase testing framework.
(10 points)
Develops and fills in details for the “during development” phase testing framework.
(10 points)
Develops and fills in details for the “during deployment” phase testing framework
(10 points)
Develops and fills in details for the “maintenance and operations” phase testing framework.
(10 points)
Does not develop or fill in details for the “before development begins” phase testing framework.
Does not develop or fill in details for the “during definition and design” phase testing framework.
Does not develop or fill in details for the “during development” phase testing framework.
Does not develop and fill in details for the “during deployment” phase testing framework.
Does not develop or fill in details for the “maintenance and operations” phase testing framework.
Security Controls
30 points
Fingerprints Web Server (OTG-INFO-002) in the Apache Web Server main site. Identifies and researches Apache software version.
(10 points)
Reviews webpage comments and metadata for information leakage (OTG-INFO-005).
(10 points)
Tests

HTTP Methods (OTG-CONFIG-006) and documents which HTTP methods are

available on the virtual machine main web site. Describes risks in HTTP

methods.
(10 points)
Does not fingerprint Web Server

(OTG-INFO-002) in the Apache Web Server main site. Does not identify and

research Apache software version.
Does not review webpage comments and metadata for information leakage (OTG-INFO-005).
Does

not test HTTP Methods (OTG-CONFIG-006) and document which HTTP methods

are available on the virtual machine main web site. Does not describe

risks in HTTP methods.
Documentation and Submission
20 points
Submits source testing framework document.
(5 points)
Document includes the results from testing the three security controls listed in the instructions.
(5 points)
Screen captures are clearly labeled indicating exactly what the screen capture represents.
(5 points)
Document

is well-organized, includes page numbers, includes all references used,

and contains minimal spelling and grammatical errors.
(5 points)
Does not submits source testing framework document.
Does not include the results from testing the three security controls listed in the instructions.
Screen captures are not clearly labeled indicating exactly what the screen capture represents.
Document

is not well-organized, or include page numbers, or include all

references used, and contains multiple spelling and grammatical errors.

 
Looking for a Similar Assignment? Order now and Get 10% Discount! Use Coupon Code "Newclient"

Information-Security-Research

Research Project

Due date:
16-Sep-2017

Task

In this assessment you are required to –

– Select a topic from the list given below and conduct research (based on literature, at least three recent research papers) on any major aspect of this chosen topic and prepare a summary report with brief supportive descriptions to post on the forum/blog. In your posting you should provide information about the topic (discuss the topic, associated challenges & problems, describe the relevant technologies, applications of the technologies, clarify vague areas, research questions etc.)
– Provide constructive feedback for (at least two) cohort colleagues and receive feedback from (at least two) cohort colleagues on your own report and make refinements accordingly.
– Raise questions about the information provided by other students (this must be done in an adequately professional manner)
– Respond to questions raised about your own information and that of other students
– Contribute to discussions in general

Note that the aim of this task is:
1. to build an understanding and perspective of current hot topics in Information Security; and
2. to build generic skills including, but not limited to:

– a capacity for teamwork and collaboration;
– an ability for critical thinking, analysis and problem solving;
– information technology literacy;
– a capacity for lifelong learning and an appreciation of its necessity.

As such, the more you contribute to the development of these topics and related discussion the more likely you will score well in this task.

Topics Set
1. Cyberterrorism
2. Biometrics for authentication: past. present and future
3. Web Browser Attacks
4. Recent trends in malware
5. Anomaly-based intrusion detection systems
6. Quantum cryptography
7. Privacy and security issues associated with Big Data
8. Smart device security
9. Internet of Things (IOT): Security issues and solutions
10. Threats to wireless networks and countermeasures
11. Security and privacy issues associated with social media
12. Security and privacy issues in cloud computing

Your submission:
You are required to prepare and submit a report on your topic to address the following issues (Length of the report: 2500~3000 words, excluding references):

a. Provide your published (to the forum/blog) research report on the chosen topic with brief supportive descriptions about the challenges, problems, relevant technologies, applications of the technologies, clarification on vague areas and research questions.
b. Summarize the issues discussed in the forum (at least two peers). Discuss how your own posts contributed to this knowledge and discuss whether or not the summary presented by your peers is accurate.
c. Identify any important issue/s that you believe were not addressed, or not addressed adequately in the discussions. Discuss why you view this issue/these issues as important.
d. Discuss the impact of the above mentioned issues and their application/impact in the real world.
e. Reflect on what you believe to be the most important lesson you have learnt as a result of these discussions.
f. Provide references (at least three) using APA referencing system including in text citations.

Rationale

Depending on the topic selected, this assessment item relates to a number of key learning outcomes of your subject.

Its also provides an opportunity for you to :

– demonstrate factual knowledge, understanding and application of state-of-art information security;
– demonstrates an understanding of what constitutes authoritative and valid evidence
– demonstrate ability to identify, locate, critique, integrate and apply information from various topics and ;
– apply valid and applicable knowledge and understanding to a practical situation;
– analyse current data to construct and communicate new knowledge
– demonstrate ability to work in a team, sharing knowledge.

Presentation

While there is no prescribed format for this report, the following should be included in the report:

• Executive Summary or Abstract (Provide a brief overview, your involvement/contribution, major findings and conclusion)
• Table of Content
• Introduction
• Copy of your published (to the forum/blog) research report (see marking criteria for details)
• Summary of discussion in the forum (see marking criteria for details)
• Any important issue/s that you believe were not addressed, or not addressed adequately in the discussions. (see marking criteria for details)
• Impact of the above mentioned issues and their application/impact in the real world.
• Reflection on what you believe to be the most important lesson you have learnt as a result of these discussions.
• Conclusion
• References (You must cite references to all material that you have used as sources for the content of your work. Follow the referencing guidelines for APA 6 as specified in Referencing Guides.)

  • Glossary (Preferable)
    A glossary should assist the reader in understanding any technical terms used in the report. Use a generally accepted source for the definition of the terms and include appropriate references.
  • Appendices (Preferable)
    You can attach any supporting material such as printouts of particular items of evidence, feedback from your cohort colleagues etc.
  • Submit the assignment in ONE word or pdf file via Turnitin. Please do not submit *.zip or *.rar or multiple files.

    Requirements

    Your submission must be in a form readable by Microsoft Word format.
    • A cover page (outside the page limit) must be included and should contain relevant identifying information (Name, Student ID#, Subject Code, Session, Assessment No.)
    • Your discussion postings are considered part of your assignment submission and are thus subject to Faculty regulations for academic misconduct (including plagiarism). As such, any text adapted from any source must be clearly labelled and referenced. You should clearly indicate the start and end of any such text.
    • Your discussion postings will be required to complete your assignment but do not directly form part of the assessment of the assignment. As such, no formal feedback will be provided regarding your discussions.

     
    Looking for a Similar Assignment? Order now and Get 10% Discount! Use Coupon Code "Newclient"

    Factors-affecting-respirationDicuss-environmental

    Discuss the environmental factors that affect whole plant respiration

     
    Looking for a Similar Assignment? Order now and Get 10% Discount! Use Coupon Code "Newclient"