0% found this document useful (0 votes)
13 views11 pages

Practical

The document outlines a practical workbook plan for BCA (4th Semester) students at B.V. Patel Institute of Computer Science, focusing on network security through various case studies. Each case study presents real-world incidents related to network security issues, such as unauthorized access, phishing attacks, and the importance of encryption. Students are tasked with answering questions related to these incidents to demonstrate their understanding of key security principles and protocols.

Uploaded by

patelbhumi1911
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views11 pages

Practical

The document outlines a practical workbook plan for BCA (4th Semester) students at B.V. Patel Institute of Computer Science, focusing on network security through various case studies. Each case study presents real-world incidents related to network security issues, such as unauthorized access, phishing attacks, and the importance of encryption. Students are tasked with answering questions related to these incidents to demonstrate their understanding of key security principles and protocols.

Uploaded by

patelbhumi1911
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

B.V.

Patel Institute of Computer Science 2025-2026

Practical Workbook Plan

BCA (4th Semester)


CS:CY4005_Fundamentals of Network Security

Case Study Enrolment No:


No. 1
Case Study “CityCare Hospital” uses a computerized system to store patient details such as medical reports, personal information,
billing records, and appointment schedules. Doctors, nurses, and administrative staff access the system using unique login
IDs.

Incident Description
During a routine audit, the hospital IT team discovered several security issues:

1 Unauthorized Access: A temporary staff member was able to view


sensitive patient records, including medical history and contact
details, even though this information was not required for their job
role.
2 Incorrect Medical Records: A doctor reported that a patient’s blood
group and allergy information had been changed in the system
without authorization. This created a serious risk during medical
treatment.
3 System Downtime: One morning, the hospital system became
unavailable for several hours due to heavy traffic and server overload.

During this time, Doctors could not access patient reports, Billing operations were delayed and Emergency services were
affected

Answer the following questions based on that.

1. Identify the three security principles affected in this case study.


2. Which incident relates to loss of data privacy?
3. Which issue indicates unauthorized modification of data?
4. Which problem shows a failure of system accessibility?
5. Why is integrity important in a hospital system?
6. Suggest two controls to protect patient information.

Objective(s) To illustrate the concepts confidentiality, integrity, and availability.

Pre- Fundamentals of Computer Network


requisite
CO(s) to be CO1
achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References for Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
solving the
problem

Assessment

Parameter Marks
Understanding of
Concepts (5 Marks)
Output (5 Marks)

Signature & Date

1
B.V. Patel Institute of Computer Science 2025-2026

Case Study: 2 Enrolment No:

Case Study A well-known e-commerce company provides online shopping services to millions of users through its computer network.
Customers use the website and mobile app to browse products, place orders, and make online payments. The company depends
heavily on its network and servers for continuous service.

Incident Description (Real Event)


During a major festival sale, the company suddenly faced network failure. Users complained that: The website was not loading,
Payments were failing and Orders could not be placed.

The IT team noticed that the servers were receiving millions of fake requests per second from systems located in different
countries. These requests overloaded the network and server resources.

Answer the following questions based on that.

1. Which security attack is involved in this case study?


2. Which security principle was mainly violated?
3. Why were legitimate users unable to access the website?
4. Was customer data stolen in this attack?
5. Mention two preventive measures to avoid such attacks.
6. Give two real-life impacts of this attack.

Objective(s) To understand the concept of different network security attack.

Pre- Fundamentals of Computer Network


requisite
CO(s) to be CO1, CO2
achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
problem
Assessment
Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

2
B.V. Patel Institute of Computer Science 2025-2026

Case Study: 3 Enrolment No:

Case Study A national-level bank provides online banking services such as fund transfer, balance inquiry, and account management through
its secure computer network. Customers access these services using usernames, passwords, and one-time passwords (OTP).

Several customers reported unauthorized transactions from their bank accounts. Some users noticed that money was transferred
without their knowledge, even though they had not shared their passwords.
On investigation, the bank’s security team found that attackers had secretly gained access to user login information by sending
fake emails and messages that looked like official bank communication.

Answer the following questions based on that.

1. Which security attack is discussed in this case study?


2. Which security services were compromised?
3. How did attackers obtain user credentials?
4. Why is phishing dangerous in online banking?
5. Mention two preventive measures against phishing attacks.

Objective(s) To understand the concept of different network security attack

Pre- Fundamentals of Computer Network


Requisite
CO(s) to be CO1, CO2
Achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
Problem
Assessment
Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

3
B.V. Patel Institute of Computer Science 2025-2026

Case Study: 4 Enrolment No:

Case A university conducts online examinations where students log in, receive question papers, and submit answers through a web-
Study based system. The data exchanged between students and the university server is highly confidential and must be protected from
attackers on the network.

Before the exam begins, the question paper is uploaded to the university server. When a student logs in at the exam time, the
question paper is sent over the internet.
If the data is sent in readable form, an attacker monitoring the network could:
Read the question paper before the exam and Modify answers during submission.

Answer the following questions based on that.

1. Why is encryption used in the online examination system?


2. What happens during encryption?
3. What is decryption?
4. What would happen if encryption was not used?
5. Which security principles are satisfied in this case study?

Objective(s) To understand the concept of different network security attack

Pre- Fundamentals of Computer Network


Requisite
CO(s) to be CO1, CO2
Achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
Problem
Assessment
Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

4
B.V. Patel Institute of Computer Science 2025-2026

Case Study: 5 Enrolment No:

Case A government portal provides online services such as student scholarships, tax filing, and document submission. Users access the
Study portal through a web browser by entering sensitive information like username, password, and personal details. Since this data
travels over the internet, strong security is required.

When a user opens the government website, the browser and server must establish a secure connection before any data is
exchanged. At this stage, the system uses the RSA algorithm to securely share encryption keys and protect sensitive
information.
If RSA is not used, attackers could intercept login credentials and confidential documents.

Answer the following questions based on that.

1. Where is the RSA algorithm used in this case study?


2. Why is RSA suitable for this application?
3. Which key is used to encrypt data in RSA?
4. Which key is used to decrypt data?
5. Which security principle is mainly achieved using RSA here?

Objective(s) To understand the concept of Publick key, private key, encryption and decryption

Pre- Fundamentals of Computer Network


Requisite
CO(s) to be CO2, CO3
Achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
Problem
Assessment

Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

5
B.V. Patel Institute of Computer Science 2025-2026

Case Study: Enrolment No:


6
Case An online shopping website called ShopEase allows customers to purchase products using debit cards, credit cards, and net
Study banking. Customers enter sensitive information such as login credentials, card number, CVV, and OTP while making payments.

Initially, ShopEase did not use SSL encryption. When customers entered their payment details, the data traveled over the
internet in plain text. A malicious attacker connected to the same public Wi-Fi network (for example, in a café) used a packet-
sniffing tool to capture network traffic.
As a result, the attacker was able to read usernames, passwords, and card details, leading to financial fraud and loss of customer
trust.

Answer the following questions based on that.

1. Why was SSL required for the website?


2. What would an attacker see if SSL was implemented?
3. How does SSL protect sensitive information during transmission?

Objective(s) To understand the different types of network security protocols.

Pre- Fundamentals of Computer Network


requisite
CO(s) to be CO2, CO3, CO4
achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
problem
Assessment

Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

6
B.V. Patel Institute of Computer Science 2025-2026

Case Study: 7 Enrolment No:

Case “SmartBank” provides online banking services such as fund transfer, balance enquiry, and bill payments through a web portal and
Study mobile application. Customers access the system using usernames and passwords over the internet.
Whenever a customer logs into the banking website, the browser establishes a secure connection with the bank’s server. During
this process:

• The server first proves its identity to the client using a digital certificate
• A secure session is created before any sensitive data is exchanged
• Login credentials and transaction details are converted into unreadable form while traveling over the network
• Any unauthorized modification of data during transmission is automatically detected
• Once the session ends, the encryption keys are discarded

Answer the following questions based on that.

1. Which security protocol is illustrated in this case study?


2. Why is server authentication important in this case?
3. How is data protected while traveling over the network?
4. What happens if data is altered during transmission?
5. Which cryptographic techniques are used in this process?
6. Which layer of the network does this security mechanism operate on?
7. Mention two real-world applications where this protocol is used.

Objective(s) To understand the different types of network security protocols.

Pre- Fundamentals of Computer Network


requisite
CO(s) to be CO2, CO3, CO4
achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
problem
Assessment

Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

7
B.V. Patel Institute of Computer Science 2025-2026

Case Study: Enrolment No:


8
Case “ShopEase” is an online shopping website where users browse products, create accounts, add items to a cart, and make online
Study payments. Customers enter sensitive information such as login credentials, address details, and card information through web
forms.

When a customer opens the website, the browser first checks the identity of the web server before allowing data exchange. Once
verified:
• All information entered by the user is converted into an unreadable format before being sent over the network
• A secure communication session is established between the browser and the server
• Any attempt to modify the data during transmission is detected immediately
• Users see a lock symbol in the browser indicating a trusted connection

Answer the following questions based on that.

1. Which protocol is used to provide security in the given web communication case?
2. Why is server authentication important in this case study?
3. How is user data protected during transmission?
4. What happens if transmitted data is altered by an attacker?
5. Which security protocol is used internally by HTTPS?

Objective(s) To understand the different types of network security protocols.

Pre- Fundamentals of Computer Network


requisite
CO(s) to be CO2, CO3, CO4
achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
problem
Assessment

Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

8
B.V. Patel Institute of Computer Science 2025-2026

Case Study: 9 Enrolment No:

Case A university conducts online examinations where students upload their answer sheets through a web portal. Each submission must
Study be completed within the official exam time to be considered valid.
When a student uploads an answer sheet, the system immediately sends the document to a trusted third-party service. This
service:
• Records the exact date and time of submission
• Generates a unique digital proof linked to the document
• Ensures that the recorded time cannot be altered later
• Allows the university to verify when the document was submitted, even in case of disputes

During result processing, the university verifies the recorded submission time to confirm that all answer sheets were uploaded
within the allowed examination window.

Answer the following questions based on that.

1. What security mechanism is illustrated in this case study?


2. Why is a trusted third party required in this system?
3. What information is linked with the submitted document?
4. Which security does provide by identified protocol?
5. Mention two real-life applications of identified protocol service.

Objective(s) To understand the different types of network security protocols.

Pre- Fundamentals of Computer Network


requisite
CO(s) to be CO2, CO3, CO4
achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
problem
Assessment

Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

9
B.V. Patel Institute of Computer Science 2025-2026

Case Study: Enrolment No:


10
Case A university provides an online portal for student admissions. Through this portal, students fill application forms, upload
Study documents, make fee payments, and submit applications before a deadline.

When a student accesses the admission portal, the browser first verifies the identity of the university server. After verification, a
secure session is established before any information is exchanged.

During the application process:


• Personal details and academic records are protected from unauthorized viewing
• Uploaded documents cannot be altered once submitted
• All data exchanged between the student and server is protected while traveling over the network

At the time of final submission:


• The system records the exact date and time of submission using a trusted service
• A unique proof is generated for each application
• The university later verifies this recorded time to confirm that the submission was done before the deadline

Throughout the process, only authorized staff members can access or verify student data, and the system remains accessible during
peak admission hours.

Answer the following questions based on that.


1. Which security principles are followed in this case study?
2. How is student data protected while traveling over the network?
3. Which protocol ensures secure web communication in this system?
4. Which protocol is responsible for encryption and secure session creation?
5. Why is time recording important during application submission?
6. Which security service does time stamping mainly support?
7. What happens if submitted data is altered during transmission?
8. Mention two other real-life applications where this combination is used.

Objective(s) To understand the different types of network security protocols.

Pre- Fundamentals of Computer Network


requisite
CO(s) to be CO2, CO3, CO4
achieved
Nature of Handwritten on A4 size blank papers with the bunch in proper black file.
workbook
submission
References Textbook: Atul Kahate, “Cryptography and Network Security: Second Edition”, McGraw Hill Education.
for solving
the
problem
Assessment

Parameter Marks
Understanding of Concepts (5
Marks)
Output (5 Marks)

Signature & Date

10
B.V. Patel Institute of Computer Science 2025-2026

11

You might also like