CYBER SECURITY
PRACTICAL TRAINING-I REPORT
SUBMITTED IN PARTIAL FULFILLMENT OF THE
REQUIREMENTS FOR THE AWARD
OF
DEGREE OF BACHELOR OF TECHNOLOGY IN COMPUTER SCIENCE
ENGINEERING
Submitted By
Name: Ashvin Khatri
Roll No. 26034
College SUBMITTED TO: Dr. Ashima Mehta
(HOD)
Department of Computer Science & Engineering
DRONACHARYA COLLEGE OF ENGINEERING
KHENTAWAS, GURGAON, HARYANA
PRACTICAL TRAINING-I
CYBER SECURITY
Submitted in partial fulfillment of the
Requirements for the award of
Degree of Bachelor of Technology in Computer Science Engineering
Submitted By
Name: Ashvin Khatri
College Roll No. 26034 SUBMITTED TO: Dr. Ashima Mehta
(HOD)
Department of Computer Science & Engineering
GURUGRAM UNIVERSITY, GURUGRAM
(HARYANA)
CERTIFICATE
i
STUDENT DECLARATION
I hereby declare that the Practical Report entitled (ANDROID APP DEVELOPMENT)/(PRACTICAL
TRAINING-I) is an authentic record of my own work as requirements of 5 th semester during the period
from 22 JUNE 2024 to 22 JULY 2024 for the award of degree of [Link]. (Computer Science &
Engineering), Dronacharya College of Engineering.
(Signature)
Parth Shakya
25113
Date:
Certified that the above statement made by the student is correct to the best of our knowledge and belief.
Signatures
Examined by:
Head of Department
(Signature and Seal)
ii
ACKNOWLEDGEMENT
I would like to express my sincere gratitude to GRASTECH, DELHI, for providing me with
the opportunity to undertake this practical training. My heartfelt thanks go to my mentors
and trainers, whose invaluable guidance and support were instrumental in the successful
completion of my various projects. Their expertise and patience have greatly contributed to
my understanding of the technologies and tools used in the development process.
I am also thankful to my peers and colleagues for their encouragement and constructive
feedback, which motivated me to push the boundaries of my learning. Finally, I would like
to extend my appreciation to my family and friends for their unwavering support
throughout this journey. This experience has been a significant step in my professional
growth, and I am deeply grateful to everyone who has played a role in it.
ABOUT COMPANY (GRASTECH)
Grastech is a leading cyber security and IT solutions provider, committed to helping
organizations and individuals secure their digital assets. Established with the vision of
building safer digital ecosystems, Grastech specializes in:
Penetration Testing
Vulnerability Assessment
Cloud Security Solutions
Network Defense Architecture
Cyber Awareness Training Programs
Grastech provides high-quality internship and training opportunities that focus on
practical learning and real-world exposure to tools such as Kali Linux, Wireshark, Nmap,
Metasploit, Burp Suite, and other cyber defense technologies.
The company believes in preparing students and professionals to face the modern cyber
threat landscape and is actively contributing to the growth of skilled cyber security
professionals in India.
ii
Motto: “Securing Today, Safeguarding Tomorrow.”
Table of Contents
CERTIFICATE iii
DECLARATION iv
ACKNOWLEDGEMENT v
ABOUT COMPANY vi
TABLE OF CONTENTS vii
CHAPTER – 1 (Introduction to Practical Training)
Introduction to Cyber Security 1–3
Requirement of Cyber Security in the Industry 4–6
CHAPTER – 2 (Tools and Technology Used)
Overview 8–9
Kali Linux Setup 10–12
Wireshark 13–15
Nmap 16–18
Metasploit 19–21
Firewall & Antivirus Tools 22–24
CHAPTER – 3 (Snapshots of the Work Done)
Password Strength Checker 25–28
Phishing Awareness Demo 29–31
Network Packet Sniffing 32–34
CHAPTER – 4 (Results of the Work Done)
Password Strength Checker – Output 35
Phishing Awareness Demo – Output 36
Network Packet Sniffing – Output 36
CHAPTER – 5 (Conclusions and Future Scope)
Conclusions of Cyber Security 37–38
Future Scope of Cyber Security 38–39
REFERENCE 40
CHAPTER – 1
INTRODUCTION TO CYBER SECURITY AND ITS INDUSTRY
REQUIREMENTS
Introduction to Cyber Security
Cyber Security refers to the practice of protecting systems, networks, applications, and data
from digital threats such as hacking, malware, phishing, ransomware, and other cyber-attacks.
In today’s highly digitalized world, where personal information, financial transactions,
business operations, and even national security depend on the internet, cyber security has
become one of the most critical areas of technology.
ii
The key objective of cyber security is to ensure confidentiality, integrity, and availability
(CIA Triad) of information.
Confidentiality – protecting sensitive data from unauthorized access.
Integrity – ensuring that data remains accurate and unaltered.
Availability – keeping systems and data accessible when needed.
Cyber Security spans multiple areas such as network security, application security, cloud
security, mobile device security, data protection, cryptography, and ethical hacking.
With the rise of digital transformation, companies across all industries are now investing
heavily in cyber security to safeguard their assets.
Why Cyber Security Matters
1. Increasing Cyber Threats – With the rapid increase in cybercrime, organizations
face constant risks of data theft, ransomware attacks, and system breaches.
2. Digital Transformation – As businesses move to cloud computing, online platforms,
and IoT devices, the attack surface for hackers expands.
3. Financial Loss Prevention – A successful cyber-attack can cost millions in terms of
recovery, legal penalties, and reputational damage.
4. Regulatory Compliance – Governments worldwide have introduced strict data
protection regulations (like GDPR, HIPAA, Indian IT Act) that require businesses to
ensure strong security measures.
5. National Security Concerns – Cyber warfare and state-sponsored attacks target
critical infrastructure such as banking, defense, energy, and communication networks.
Key Components of Cyber Security
1. Network Security – Protecting networks with firewalls, intrusion detection systems
(IDS), intrusion prevention systems (IPS), and VPNs.
2. Application Security – Securing software applications from vulnerabilities like SQL
Injection, Cross-Site Scripting (XSS), and buffer overflows.
3. Information Security – Protecting sensitive business and customer data using
encryption and access controls.
4. Endpoint Security – Securing laptops, mobiles, and IoT devices against malware and
unauthorized access.
5. Cloud Security – Protecting cloud services and data stored in platforms like AWS,
Azure, and Google Cloud.
6. Ethical Hacking & Penetration Testing – Identifying vulnerabilities before
attackers can exploit them.
Industry Requirements of Cyber Security
The cyber security industry is evolving at a rapid pace due to the following demands:
ii
1. Skilled Professionals – Industry needs ethical hackers, penetration testers, SOC
(Security Operations Center) analysts, forensic experts, and cyber security
consultants.
2. Adoption of Advanced Tools – Proficiency in tools like Wireshark, Nmap,
Metasploit, Burp Suite, Nessus, and SIEM platforms is a must.
3. AI & Machine Learning in Security – Companies now use AI/ML to detect
anomalies and predict threats in real time.
4. Cloud Security Expertise – With most organizations moving to the cloud,
knowledge of cloud security frameworks is essential.
5. Incident Response Skills – Companies expect quick detection, response, and
recovery from cyber incidents.
6. Continuous Learning – Cyber security threats keep evolving; hence professionals
must constantly update their knowled
Conclusion of Chapter 1
Cyber Security is not just a technical requirement but a business enabler that protects assets,
ensures trust, and maintains continuity in the digital age. As cyber threats grow in
sophistication, the industry needs highly skilled professionals with both theoretical
knowledge and practical exposure to security tools, frameworks, and best practices.
CHAPTER – 2
ii
TOOLS AND TECHNOLOGY USED
Overview
In the field of Cyber Security, professionals rely on specialized operating systems,
penetration testing frameworks, network monitoring tools, and forensic applications to
analyze, detect, and prevent threats. During the training at Grastech, the following tools and
technologies were used:
1. Kali Linux – Industry-standard penetration testing operating system.
2. Wireshark – Network protocol analyzer.
3. Nmap – Network scanning and reconnaissance tool.
4. Metasploit Framework – Exploitation and penetration testing framework.
5. Firewalls & Antivirus Tools – Defensive tools for system protection.
Kali Linux Setup
Kali Linux is a Debian-based Linux distribution designed for penetration testing and security
auditing. It comes pre-installed with hundreds of tools for various information security tasks,
including penetration testing, network analysis, digital forensics, and reverse engineering.
Key Features:
Pre-loaded with tools like Nmap, Metasploit, Burp Suite, Hydra, etc.
Customizable desktop environment.
Strong support community.
ii
Wireshark
Wireshark is a widely used network packet analyzer that allows professionals to capture
and interactively browse the traffic running on a computer network.
Uses:
Packet sniffing to analyze communication.
Troubleshooting network issues.
Detecting suspicious activities (like malware communication).
ii
Nmap (Network Mapper)
Nmap is a powerful open-source network scanning tool used for network discovery and
security auditing.
Functions:
Detect live hosts on a network.
Identify open ports and services.
Detect operating systems and vulnerabilities.
ii
Metasploit Framework
Metasploit is one of the most popular frameworks for developing and executing exploit
code against a remote target machine.
Capabilities:
Exploitation of vulnerabilities.
Post-exploitation modules for privilege escalation.
Large database of exploits and payloads.
Firewall & Antivirus Tools
Firewalls are network security systems that monitor and control incoming and outgoing
network traffic based on security rules.
Antivirus Software detects and removes malicious programs.
Examples: pfSense Firewall, Windows Defender, Norton Antivirus.
ii
Conclusion of Chapter 2
Cybersecurity relies heavily on specialized tools that provide visibility, scanning,
exploitation, and defense capabilities. A combination of offensive (ethical hacking tools)
and defensive (firewall/antivirus tools) approaches helps ensure a holistic security posture.
CHAPTER – 3
SNAPSHOTS OF THE WORK DONE
During the training at Grastech, several practical projects were undertaken to apply
theoretical knowledge to real-world scenarios. These tasks focused on enhancing the
ii as password security, phishing awareness, and
understanding of cyber security concepts such
network traffic monitoring.
Project 1 – Password Strength Checker
Objective:
To develop a tool that checks the strength of user-created passwords against commonly used
patterns and provides feedback on improving security.
Process:
The program was designed in Python.
It checks for length, use of upper/lowercase letters, numbers, and special characters.
It compares passwords against a dictionary of weak/common passwords.
Provides suggestions for stronger passwords.
Learning Outcome:
Importance of complex passwords.
Awareness about brute-force and dictionary attacks.
How weak passwords compromise system security.
Project 2 – Phishing Awareness Demo
Objective:
To demonstrate how phishing attacks trick users into entering sensitive information on fake
websites.
Process:
ii
A demo phishing page was created to mimic a common login portal.
The user’s input (like username and password) was captured in a secure training
environment.
Students were shown how attackers use social engineering techniques.
Guidance was given on identifying phishing emails and fake links.
Learning Outcome:
How to recognize suspicious emails/URLs.
Techniques used in phishing (spoofed domains, urgency messages, fake attachments).
Preventive measures like checking SSL certificates, using multi-factor authentication,
and never clicking unknown links.
ii
Project 3 – Network Packet Sniffing (Wireshark)
Objective:
To analyze real-time network traffic and detect unusual patterns using Wireshark.
Process:
Wireshark was installed and configured in Kali Linux.
Packets were captured from a live network connection.
Analysis was performed on different protocols like HTTP, HTTPS, DNS, and TCP.
Suspicious packets (e.g., clear-text credentials in HTTP traffic) were identified.
Learning Outcome:
Understanding how data flows over networks.
Identifying vulnerabilities in unencrypted communication.
Role of encryption (HTTPS, VPNs) in protecting data.
ii
Conclusion of Chapter 3
These hands-on tasks provided practical exposure to common cyber security issues and
solutions. The Password Strength Checker emphasized secure authentication, the Phishing
Awareness Demo highlighted social engineering risks, and Network Sniffing showcased the
importance of encrypted communication. Together, they gave a well-rounded
understanding of cyber threats and [Link]
CHAPTER – 4
RESULTS OF THE WORK DONE
The practical tasks conducted during the training provided valuable insights into cyber
security concepts. The following are the results obtained from the projects:
1. Password Strength Checker – Output
When tested with different inputs, the Password Strength Checker generated the following
results:
Input: 12345 → Output: Very Weak Password
Input: Ashvin123 → Output: Moderate Password
Input: @shV!n#2024 → Output: Strong Password
Interpretation:
This tool highlighted the risks of using weak passwords and the effectiveness of including
uppercase, lowercase, numbers, and special characters.
2. Phishing Awareness Demo – Output
ii
The phishing awareness demo showed how users can be easily deceived by fake login pages:
When a test user entered credentials on the fake portal, the system captured the data.
Students could clearly see how attackers exploit human trust.
Interpretation:
This result demonstrated the importance of email vigilance and checking for secure HTTPS
connections before entering sensitive information.
3. Network Packet Sniffing (Wireshark) – Output
The packet sniffing project captured live traffic, revealing the following:
HTTP requests displayed usernames and passwords in plain text.
DNS queries revealed the websites users were visiting.
Encrypted HTTPS traffic could not be read, showcasing the importance of secure
protocols.
ii
Interpretation:
This experiment proved the necessity of encryption in communication and why companies
must enforce secure browsing (HTTPS, VPNs, SSL/TLS).
Conclusion of Chapter 4
The results obtained from these projects clearly underline how:
Strong password practices can prevent brute force and dictionary attacks.
Phishing awareness is critical for individuals and organizations.
Network monitoring tools like Wireshark help in detecting malicious activity and
understanding traffic patterns.
By applying these concepts practically, students gained real-world knowledge of how cyber
security protects data and systems.
CHAPTER – 5
CONCLUSIONS AND FUTURE SCOPE
Conclusions of Cyber Security Training
The practical training at Grastech provided in-depth knowledge and hands-on exposure to
the field of Cyber Security. Through the combination of theory and practical projects, the
following key conclusions were drawn:
ii
1. Cyber Security is a necessity, not an option – With the rise of cybercrime,
businesses, governments, and individuals must prioritize security at every level.
2. Tools are powerful, but awareness is stronger – Technologies like Wireshark,
Nmap, and Metasploit are essential, but human awareness of phishing and social
engineering attacks is equally critical.
3. Passwords remain the weakest link – Users often compromise systems by choosing
weak passwords; stronger authentication mechanisms like multi-factor authentication
(MFA) are required.
4. Encryption is the backbone of secure communication – The Wireshark project
highlighted the vulnerabilities of unencrypted data transfer.
5. Practical exposure is vital – Classroom learning alone is insufficient; real-world
tasks prepare students to face actual threats.
Overall, the training experience strengthened problem-solving, technical, and analytical skills
required for today’s cyber security professionals.
Future Scope of Cyber Security
Cyber Security is one of the fastest-growing industries in technology. Its future scope
includes:
1. Artificial Intelligence & Machine Learning in Security
o AI-driven systems will detect anomalies and predict threats in real-time.
2. Cloud Security Expansion
o With most businesses shifting to cloud platforms, securing cloud services will
remain a top priority.
3. IoT Security
o Billions of IoT devices (smart homes, wearable tech, smart cars) will require
advanced security frameworks.
4. Blockchain for Security
o Blockchain can be used for secure digital transactions, identity verification,
and fraud prevention.
5. Quantum Computing Challenges
o Quantum computers may break traditional encryption, creating the need for
quantum-resistant algorithms.
6. Demand for Skilled Professionals
o The demand for cyber security experts will continue to grow worldwide,
offering vast career opportunities.
7. Global Regulations and Compliance
o Stricter laws and policies (GDPR, Indian IT Act amendments, etc.) will push
organizations to adopt stronger cyber security measures.
Conclusion of Chapter 5
The training successfully highlighted the importance of cyber security in today’s digital
era. With increasing cyber threats, the industry
ii offers immense opportunities for growth,
innovation, and impact. By continuing to learn, practice, and innovate, cyber security
professionals can protect organizations and society from evolving cyber risks.
REFERENCES
1. Stallings, William. Cryptography and Network Security: Principles and Practice.
Pearson Education, 8th Edition.
2. Pfleeger, Charles P., and Shari Lawrence Pfleeger. Security in Computing. Pearson
Education.
3. Anderson, Ross. Security Engineering: A Guide to Building Dependable Distributed
Systems. Wiley.
4. NIST Cybersecurity Framework. [Link]
5. OWASP (Open Web Application Security Project). Top 10 Security Risks.
[Link]
6. Official Kali Linux Documentation. [Link]
7. Wireshark Official User Guide. [Link]
8. Nmap Reference Guide. [Link]
9. Metasploit Unleashed – Offensive Security.
[Link]
10. CERT-In (Indian Computer Emergency Response Team). [Link]
11. Kaspersky Labs – Cybersecurity Trends and Reports.
[Link]
12. Symantec/Norton Threat Report. [Link]
13. GeeksforGeeks. Introduction to Cyber Security.
[Link]
14. EC-Council. Ethical Hacking Resources. [Link]
ii