0% found this document useful (0 votes)
6 views8 pages

Coventry Uni Intrusion Detection Assignment

This document outlines the assignment brief for Coventry University students enrolled in the Intrusion Detection and Response module (7025CEM), detailing coursework requirements, submission guidelines, and assessment criteria. Students are tasked with analyzing a client network for security vulnerabilities, developing monitoring solutions, and justifying costs associated with security measures. The assignment includes specific questions related to insider threats, data collection, incident response, and advanced persistent threats, with a focus on legal and ethical considerations.

Uploaded by

gopalshil19600
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views8 pages

Coventry Uni Intrusion Detection Assignment

This document outlines the assignment brief for Coventry University students enrolled in the Intrusion Detection and Response module (7025CEM), detailing coursework requirements, submission guidelines, and assessment criteria. Students are tasked with analyzing a client network for security vulnerabilities, developing monitoring solutions, and justifying costs associated with security measures. The assignment includes specific questions related to insider threats, data collection, incident response, and advanced persistent threats, with a focus on legal and ethical considerations.

Uploaded by

gopalshil19600
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

This document is for Coventry University students for their own use in completing their

assessed work for this module and should not be passed to third parties or posted on any
website. Any infringements of this rule should be reported to
[Link]@[Link].

Faculty of Engineering, Environment and Computing


7025CEM Intrusion Detection and Response

Assignment Brief
Module Title Individual Cohort Module Code
Intrusion Detection and Response (Sept/Jan/May) 7025CEM

Coursework Title (e.g. CWK1) Hand out date:


Intrusion Detection & Response Coursework
Lecturer Due date:
Dr. C. Panchev 6/12/2022

Estimated Time (hrs): Coursework type: % of Module Mark

Word Limit*: 3300 Assignment 100


Submission arrangement online via Aula:
File types and method of recording: Single PDF file

Mark and Feedback date (DD/MM/YY):


Mark and Feedback method: via Aula

Module Learning Outcomes Assessed:

1. Critical awareness of the legal, ethical and professional issues involved in incident response investigation.
2. Evaluate and apply appropriate technological solutions and processes in the detection, management and
investigation of information and system security incidents.
3. Critically evaluate and apply digital forensic methodology to cyber security incidents and commercial
investigation; establish an audit trail, documenting a digital investigation from a legal and professional
perspective.
4. Ensure all actions undertaken are Association of Chief Police Officers (ACPO) Principles of
Digital Evidence compliant.

Instructions

Coursework Motivation

This coursework is designed to assess your research and analytical abilities. Often, in the course of your
career, you will find that you are faced with new technologies and concepts. Such situations will require
you to conduct research and investigation to evaluate new tools and techniques. This requires a degree
of independence of thought, and building confidence in new approaches based on technical design.
Your analytical abilities will be called into question almost daily and you will often be faced with
challenges under economic, social, legal and ethical constraints.

Writing Guidance

This coursework requires you to answer ALL questions. The questions should be answered in the given
order in a single report. You do not need to provide an abstract.
This document is for Coventry University students for their own use in completing their
assessed work for this module and should not be passed to third parties or posted on any
website. Any infringements of this rule should be reported to
[Link]@[Link].

Be clear and precise with the use of terminology. So, for example, terms such as data, traffic, packets,
messages and information are often used interchangeably. Note that these are different terms and
convey different meaning in different contexts.

It is highly recommended that you read the questions carefully before answering. Illustrations are
encouraged, but should be clearly labelled and relevant to use. Otherwise it may not help clarity and
cause confusion.

Client Network

The network, shown in Figure 1, represents a client network that you are called to handle. Your role, as
a network security evaluation specialist, is to help the client design and build an effective evaluation
and monitoring solution. Your client has specific requirements that need to be met and expects you to
address some of the technical and legal challenges involved. The client owns all the data created,
processed, stored and communicated on the networked systems, some of which is sensitive.

The network is designed such that various services are spread out on server farms. The three server
farms host server nodes vie respective gateway nodes numbered 3,4 and 5. Gateway nodes 8-13
connect to client nodes (several hundred) distributed across subnets.

The nature of service traffic is a combination of web services (for external customer enquiries and
ecommerce), and various application services for use within the organisation. Some of the services
need to be accessible from the outside world.

The nodes are diverse in their configuration and with different levels of access to services and the
outside world (internet) which is accessible by gateway node 0. Nodes 1, 2, 6 and 7 serve for the
purpose of intermediary routing within the network. Nodes 14 and 15 are a series of APs providing
WiFi networking to the offices.
This document is for Coventry University students for their own use in completing their
assessed work for this module and should not be passed to third parties or posted on any
website. Any infringements of this rule should be reported to
[Link]@[Link].

Figure 1. Network diagram

The client is involved in innovation and product development within the defence and security sector
serving clients ranging from government departments, multinational firms and foreign agencies. The
nature of activity lends itself to sabotage and intellectual property theft. The collaborative nature of
the organisation also means that it hosts development teams from other partners from a variety of
countries.

Your role has specific deliverables and you are asked to prioritise the activities (set out in the
questions) detailed below. You have a few weeks to present a report to the technical leadership of
the client on these matters.

For the sake of consistency, in your answers, specific locations should be referred to by the labels
used above. It would be wise to label and help clarify particular locations that you refer to including
particular interfaces on the firewall, routers (as there are multiple), links between routers and
switches and so on.

If you need to make any assumptions in addition to the brief given above, (e.g. any particular security
software or hardware already deployed on the network, or what services are running on a particular
subnet), you should clearly specify these in a section called ‘Assumptions’ at the beginning of your
report. The assumptions section does not count toward the word limit.

Assignment

Question 1: Detecting reconnaissance (25 Marks, 1000 words)

The client is particularly vulnerable to insider attacks including sabotage (disruption and destruction)
and espionage (stealing sensitive information). To detect any such attacks, it is important that the
client has effective measures in place.

You are asked to evaluate the level of exposure for servers from insiders. Of particular interest here is
network reconnaissance (scanning and enumeration) activity that originates internally.
 Briefly explain how potential intruders (insider of the network) can collect and use
reconnaissance data for malicious purposes?
 Describe what data would you prefer to collect and at what points on the network? You are
expected to adopt a systematic approach where you justify why are you collecting the various
types of data and where?
 To support the above activity, what tools would you use and what type of activity would you
configure to detect? Your answer is expected to prescribe tools that the client may wish to
use and adopt in the future. Your client would appreciate suggestions for configuration of
such tools to assist in efficient collection, logging and analysis of data collected.
 This is a high volume network and parts of it get very busy at peak times. Any activity of
collecting traffic from the network would be a challenge. In the context of above activity,
discuss relevant strategies to help overcome the problem of scale.

Question 2: Session Data collection (15 Mark, 500 words)


This document is for Coventry University students for their own use in completing their
assessed work for this module and should not be passed to third parties or posted on any
website. Any infringements of this rule should be reported to
[Link]@[Link].

Alert data and session data are two types of NSM data of standard form that is collected over networks.
Discuss both forms of data briefly and present a justification for the collection of each. How could each
type help you understand whether potential intrusion is taking place?

In Figure 1 identify three locations of strategic interest for collecting session data. Justify your choice.
Describe what tools and configuration you will use for collection.

Question 3: Splunk or Elastic stack? (15 Marks, 500 words)

A senior security analyst on the client site is considering deploying a separate solution for insider
threat detection and automated response. She has asked you for advice on the choice between
Splunk and Elastic stack solutions. They are both widely known products available for deployment as
SIEM as well as XDR/SOAR and more.

Use your research skills to help the colleague make an informed decision. Find out more about both
solutions. What detection and automated response capabilities do they offer? Both come with high
recommendations from the security community. What makes them a popular choice? Your answer
should facilitate a clear decision.

Question 4: Incident Response (20 Marks, 600 words)

The SOC team has detected and confirmed an incident with the following events been initially
correlated: a suspicious out-of-office-hours activity (incl. external flash drive attached) on a
workstation connected to gateway 10; opening of a large number of files on a file server connected to
gateway 9; and a large volume of traffic between the workstation and a DB server connected to
gateway 5. Based on the advice you provided in Question 1 which of the data that has been collected
will be relevant to this case, and what evidence do you expect to derive from there?

This is an ongoing incident and as part of the Incident Response you have been asked to provide
advice on whether they need to start collecting any additional data, if so what type and from where
(both network-based as well as from end-points) – this is in addition to the advice you provided in
Question 1. The approach you advise should be forensically sound so that any evidence collected can
be used in court.

Question 5: Advanced persistent threats (APTs), (15 Marks, 400 words)

After devising your monitoring solution, you are asked to demonstrate how effective it is. Consider
the following three issues:
 What kind of testing would you recommend in order to determine if the system is working
accordingly to specifications and goal? Explain types of tests to be performed, who should
conduct them, where, and when.
 Are there any concerns that the company should think of with respect to the qualifications of
the testers? Review through the kind of certification, knowledge base and toolset experience
you would look for to ensure that the testers are up to the job.
 APT attacks are an increasing threat. What mechanisms of your proposed monitoring system
would address these particular threats? Give some description of the kind of APT behaviour
you may observe and how your monitoring deployment could detect or prevent it.
This document is for Coventry University students for their own use in completing their
assessed work for this module and should not be passed to third parties or posted on any
website. Any infringements of this rule should be reported to
[Link]@[Link].

Question 6: Cost effectiveness (10 marks, 300 words)

Security, be it in terms of equipment, human effort or inconvenience, has a cost. Fact! Security,
therefore, involves trade-offs. Another fact!

Your recommendations, in your answers for questions 1, 2, 3 and 5, entail significant costs in terms
of:
a) equipment, including hardware, software and training resources,
b) human, including manual configuration and steering of monitoring operations, and training,
and
c) Inconvenience, in terms of disruption to normal operations.

Present a brief justification of these costs. For each category, describe the benefit your client receives
for the investment made.

Notes:
1. You are expected to use the Coventry University APA style for referencing. For support and
advice on this students can contact Centre for Academic Writing (CAW).
2. Please notify your registry course support team and module leader for
disability support.
3. Any student requiring an extension or deferral should follow the university process as outlined
here.
4. The University cannot take responsibility for any coursework lost or
corrupted on disks, laptops or personal computer. Students should therefore
regularly back-up any work and are advised to save it on the University
system.
5. If there are technical or performance issues that prevent students submitting
coursework through the online coursework submission system on the day of
a coursework deadline, an appropriate extension to the coursework
submission deadline will be agreed. This extension will normally be 24 hours
or the next working day if the deadline falls on a Friday or over the weekend
period. This will be communicated via your Module Leader.
6. Assignments that are more than 10% over the word limit may result in a
deduction of 10% of the mark i.e. a mark of 60% will lead to a reduction of
6% to 54%. The word limit includes quotations, but excludes the
bibliography, reference list and tables.
7. You are encouraged to check the originality of your work by using the draft
Turnitin links on Aula.
8. Collusion between students (where sections of your work are similar to the
work submitted by other students in this or previous module cohorts) is
taken extremely seriously and will be reported to the academic conduct
panel. This applies to both courseworks and exam answers.
9. A marked difference between your writing style, knowledge and skill level
demonstrated in class discussion, any test conditions and that demonstrated
in a coursework assignment may result in you having to undertake a Viva
Voce in order to prove the coursework assignment is entirely your own work.
This document is for Coventry University students for their own use in completing their
assessed work for this module and should not be passed to third parties or posted on any
website. Any infringements of this rule should be reported to
[Link]@[Link].
[Link] you make use of the services of a proof reader in your work you must keep
your original version and make it available as a demonstration of your
written efforts.
[Link] must not submit work for assessment that you have already submitted
(partially or in full), either for your current course or for another qualification
of this university, with the exception of resits, where for the coursework, you
maybe asked to rework and improve a previous attempt. This requirement
will be specifically detailed in your assignment brief or specific course or
module information. Where earlier work by you is citable, i.e. it has already
been published/submitted, you must reference it clearly. Identical pieces of
work submitted concurrently may also be considered to be self-plagiarism.

Mark allocation guidelines to students (to be edited by staff per assessment)

70%+ Excellent

(A mark above 80% indicates an exceptional piece of work that excels in every respect of the following
criteria)

The overall report is clearly written, with accessible language and demonstrably within the word limit.
All questions are attempted, for which the answers are in the order listed and the logical arguments
are coherent.

Excellent use of relevant evidence to support the technical design choices made and their
comparative analysis. This is accompanied by evidence of independent research for every question.
The legal and ethical aspects of using monitoring technology are clearly recognised and sensibly
expressed. The need for human resource training is also recognised and appropriate sources for
training are identified. Question 6, which requires well-judged commentary, is well attempted and
opinions are carefully expressed with regards to each aspect identified in the coursework. Overall,
there is comprehensive examination of the chosen monitoring, sensor placement and data collection
methodologies, and the assumptions underlying them. All sources are correctly cited in a recognised
format. Irrelevant material is excluded.

The report demonstrates the ability of the student to think independently, originally and critically.

60-69% Very Good

A clear attempt has been made to ensure that the overall report is written clearly, with generally good
language and demonstrably within the word limit. All questions are attempted, for which the answers
are in the order listed and the logical arguments are mostly coherent.

Good use of relevant evidence to support the technical design choices made and their comparative
analysis. There is evidence of independent research for most questions. The legal and ethical aspects
of using monitoring technology are identifiably recognised and expressed. The need for human
resource training is also recognised and some sources for training are identified. Question 6, which
requires well-judged commentary, is attempted with some clear opinions expressed with regards to
each aspect identified in the coursework. Overall, there is good examination of the chosen
monitoring, sensor placement and data collection methodologies, and the assumptions underlying
them. All sources are correctly cited in a recognised format .

The report demonstrates some ability of the student to think independently, originally and critically.
This document is for Coventry University students for their own use in completing their
assessed work for this module and should not be passed to third parties or posted on any
website. Any infringements of this rule should be reported to
[Link]@[Link].
50-59% Satisfactory to Good

An attempt has been made to ensure that the overall report is written clearly and demonstrably
within the word limit. All questions are attempted, for which the answers are in the order listed and
logical arguments are attempted.

General use of relevant evidence to support the technical design choices made and their comparative
analysis. There is some evidence of independent research for questions. At least some legal and
ethical aspects of using monitoring technology are recognised and expressed. The need for human
resource training is recognised and at least a few sources for training are identified. Question 6, which
requires well-judged commentary, is attempted with some opinion expressed with regards to some of
the aspects identified in the coursework. Overall, there is some examination of the chosen
monitoring, sensor placement and data collection methodologies, and the assumptions underlying
them. At least some sources are cited and attempted so in a recognised format.

The report presents some evidence that the student has attempted independent and original thinking.

40-49% Pass

An attempt has been made to ensure that the most parts of the report are legibly written and with
most answers within the word limit. Most questions are attempted, answers for which are in labelled
order and arguments are present.

Some use of relevant evidence to support the technical design choices made and their comparative
analysis. There is some evidence of research for questions. Some knowledge of legal or ethical aspects
is present. The need for human resource training is recognised and some supporting argument made.
Question 6 is addressed with some attempted commentary. Overall, there is acknowledgment of
some of the chosen monitoring, sensor placement and data collection methodologies, and the
assumptions underlying them. Some sources are cited and attempted so in a recognised format.

The report presents some evidence of effort put in by the student towards a thought process for the
assessment.

0-39% Fail

No attempt has been made to ensure that at least some parts of the report are legibly written, with
answers not attempted within the word limit. Three or less questions are attempted, answers for
which are not in order.

There is no evidence of support for any technical design choices made. Legal or ethical aspects are
entirely ignored. The need for human resource training is recognised and some supporting argument
made. Question 6 is not addressed, or no coherent arguments are presented. Overall, there is no
identifiable evidence of any monitoring, sensor placement or data collection methodologies. No
references are presented.

The report presents very little or no evidence of logical effort or thought process towards any of the
six questions.

You might also like