加勒比久久综合,国产精品伦一区二区,66精品视频在线观看,一区二区电影

合肥生活安徽新聞合肥交通合肥房產(chǎn)生活服務(wù)合肥教育合肥招聘合肥旅游文化藝術(shù)合肥美食合肥地圖合肥社保合肥醫(yī)院企業(yè)服務(wù)合肥法律

代寫INFO3616、代做Python語言程序
代寫INFO3616、代做Python語言程序

時間:2024-08-29  來源:合肥網(wǎng)hfw.cc  作者:hfw.cc 我要糾錯



The University of Sydney
School of Computer Science
Senior Lecturer - Security
INFO3616/CSEC3616/CSEC5616 — S2 2024
Assignment - 1
This is an individual assignment.
This assignment worths 10% of the final marks of the course.
Submit your final report as a PDF and codes as a zip file in Canvas.
You should explain any details of how to run your code in report.
Final Report and Code: Due by Week 5, Sunday the 1st of September, 2024 11:59 PM
*** IMPORTANT ***: In your answer sheet DO NOT repeat the questions. Simply include
the question number and your answer only. If you include question text in your answer sheet,
your TurnItIn score will be high and there will be additional checks. This will cause a delay in
releasing your marks. We will also impose a penalty of 10% of the total marks.
1 Security Goals (20 marks)
Analyse the following real-world IT-related incidents and data breaches where specific security goals
were compromised. For each scenario, identify the compromised security goal (e.g., Confidentiality,
Data/Message Integrity, Authenticity, Authorisation, Accountability, Non-repudiation, Deniability,
Availability, Privacy) and explain how the incident compromised that goal.
You will have to do your research by referring to various news articles and incident reports to
understand what happened in each incident. We have given some sample links to get you started but
feel free to investigate more and understand what happened in each incident. Most of the questions
will have more than one correct answer, depending on how you look at them. We will accept them if
your explanation is correct and related to the incident.
Provide clear and concise explanations for each scenario, as shown in the example.
Example 1 - CrowdStrike Falcon update failure 2024 - Link
Compromised Security goal: Availability
Explanation: Windows machines with the CrowdStrike Falcon Sensor installed went into
the boot loop with BSOD (Blue Screen of Death), making them unusable and compromising
availability.
1
Example 2 - Optus data breach 2022 - Link
Compromised Security goal: Confidentially
Explanation: Personal information of the Optus customers, such as driver’s licence number,
passport number, and address, was harvested by an attacker using an unauthenticated API
endpoint. Optus was in breach of keeping their customer’s data confidential. Here, arguments
can be made for security goals such as authorisation and privacy - but they are secondary to
confidentiality.
2 marks for each. 1 mark for correctly naming the security goal and one mark for the
explanation.
i Twitter account hijacking, 2020, Link.
ii Struxnet, 2010, Link.
iii Medicare and Pharmaceutical Benefits Scheme (PBS) data released by the Australian Department
of Health, 2016, Link 1, Link 2.
iv SolarWinds Supply Chain Attack, 2020, Link.
v Attack on Dyn DNS Provider, 2016 Link.
vi Poly Network Hack, 2021, Link 1, Link 2.
vii Silk Road Takedown, 2013, Link 1, Link 2.
viii Colonial Pipeline Cyberattack, 2021, Link.
ix Ashley Madison Breach, 2015, Link.
x Unisuper Google Could Incident, 2024, Link 1, Link 2, Link 3.
2 Social Engineering (20 marks)
ZenithTech, a prominent financial services firm, has been experiencing a surge in activity due to the
launch of a new investment platform. During this time, Sarah, an operations manager, receives a call
from someone claiming to be Chris, a representative from their external auditing firm. Shortly after,
she also receives an email supposedly from the company’s internal audit department.
Chris: "Hello Sarah, I’m Chris from your external audit firm. We’re conducting a quick review
of the new investment platform’s security protocols. Could you provide the access logs and system
architecture diagrams?”
Sarah: "I wasn’t aware of this audit. Shouldn’t this request come through our IT security team?”
Chris: "I understand your concern, Sarah. Due to the urgency of this review, we’ve been asked to
directly contact key personnel. I’ve already spoken to Michael from your internal audit team, and he’ll
send you an email confirming my request.”
2
Email:
Subject: Verification of External Auditor Request
Dear Sarah,
This is to verify that Chris is an authorized member of our external audit firm and is requesting
the necessary information for a security review. Please assist him with the requested documents.
Best regards,
Michael Johnson - Internal Audit Department
Later, Sarah discusses this situation with her colleague, James.
Sarah: "James, I got a call from an external auditor named Chris and an email from Michael
confirming it. But something doesn’t feel right. What do you think?”
James: "That’s odd. Did you verify the email’s authenticity? Maybe it’s best to check with Michael
directly.”
i Identify and describe two cognitive biases the attacker is attempting to exploit. (6 marks)
ii What additional indicators should Sarah look for to recognize this as a potential vishing attack?
List and explain two red flags. (4 marks)
iii As a security manager, what steps would you implement at ZenithTech to prevent such vishing
attempts? Provide two recommendations. (4 marks)
iv If Sarah had shared the sensitive information, what immediate actions should ZenithTech take to
mitigate potential risks? Explain three steps. (6 marks)
3 Social Engineering in Practice (20 marks)
You are a given a Twitter profile of a fictitious person.
https://x.com/frankgraphicsGP
Your task is to conduct some reconnaissance on the profile and guess the password used by this
subject to zip a file. Write a Python program that takes keyword list as the input create a list of
possible word combinations that may be used by this subject as a password.
For example, if you find possible keywords to be “blue”, “car”, the Python program should be able
to generate a list like and programmatically try to unzip the given file by entering generated passwords.
blue
car
blueblue
bluecar
carblue
carcar
3
Hint: The correct password contains lower case letters and digits. The length of the password is less
than 20 characters.
Include any details of how to run your code and the contents of the unzipped file in the PDF report
and submit your code in the code submission link given in Canvas.
4 Access Control (20 marks)
a) Definitions
i Explain: is authentication a necessary ingredient for authorisation? Give an example that proves
your argument. (2 marks)
ii It is conventional wisdom that passwords to encrypt a hard drive should be longer than passwords
for online login to websites. Explain why. (2 marks)
iii Explain what a Security Policy Model is. **2 sentences are enough. (2 marks)
iv Access control is often categorised into two general forms (which we called two ends of a spectrum).
What are they, and how are they different from each other? (2 marks)
v Modern CPUs have support for access control. Explain two key ideas of the common x86
architecture. (2 marks)
b) Security Policy Models
Figure 1 shows a mapping between users and clearances, and between required clearances and objects.
The clearance level increases as Basic, Confidential, Secret, Top Secret, and Ultimate Secret. Only
these mappings are defined; no other rule sets exist.
Explain if the the following statements are right or wrong, and say why.
i “In a Bell LaPadula model, Bob can read the file battle_plans.txt.” (2 marks)
ii “In a Biba model, Bob can read the file mars_habitat_plan.txt.” (2 marks)
iii “In a Bell LaPadula model, Alice can enlist the help of Elise to obtain the content of the
mars_habitat_plan.txt.” (2 marks)
iv “In a Bell LaPadula model, Alice can write to all the files as she wishes.” (2 marks)
v “In a Biba model, Elise can write to all the files as she wishes.” (2 marks)
4
ClearanceUser
BasicAlice
ConfidentialBob
SecretCharlie
Top SecretDavid
Ultimate SecretElise
Required ClearanceObject
Confidentialweekly_threat_report.txt
Ultimate Secretmars_habitat_plan.txt
Basicnext_week_press_brief.txt
Top Secretbattle_plans.txt
Figure 1: Access Tables
5 Linux Access Control (20 marks)
Below questions are associated with the provided Azure VM.
a) Basic Access Control
Below questions can be answers by Linux One liners. Provide the answer to each question and
include the command you used. Make sure that you include the command as letters/characters
(than screenshots/images), so that the markers can copy/paste command and check whether it is
working.
i What is the User ID (UID) of the user gimly. (1 mark)
ii What is the Group ID (GID) of the group hobbits. (1 mark)
iii Find which group the user legolas belongs to. (1 mark)
iv Find all the users in the group humans. (1 mark)
v Does the user frodo have sudo access? There are multiple ways to do this. Answers requiring
more than one command is also accepted. (1 mark)
b) File Permissions
For i-iii, use the linux find command with correct options and make sure that you command do not
generate any permission denied messages or other error messages. Include the commands you used in
your answer.
i Find all the files owned by user legolas. (1 mark)
ii Find all the files associated with the group elves. (1 mark)
iii Find all the files owned by user gimly. (1 mark)
iv In ii) you will find a file owned by legolas and having the group as elves. Is the next statement
is true about the file. “arwen can write to the file”. Explain your answer. (2 marks)
v In iii) you will find a file owned by gimly and having the group as dwarves. Is the next statement
is true about the file. “isildur can write to the file”. Explain your answer. (2 marks)
c) SUID Bit
5
i Find all the files own by root and having the group as humans. Similar to above your command
must not generate any permission denied messages or other error messages. (2 marks)
ii The search in i) will return two files. Explain the difference in permission strings of these two files.
(3 marks)
iii Explain and demonstrate how the permission setting in one of the files can create a security
vulnerability. (Hint: You will have to run the files and use the whoami command.) (3 marks)

請加QQ:99515681  郵箱:99515681@qq.com   WX:codinghelp




 

掃一掃在手機打開當(dāng)前頁
  • 上一篇:代寫ECON0013、代做Python/c++語言程序
  • 下一篇:代寫COMP30026、C++設(shè)計程序代做
  • 無相關(guān)信息
    合肥生活資訊

    合肥圖文信息
    2025年10月份更新拼多多改銷助手小象助手多多出評軟件
    2025年10月份更新拼多多改銷助手小象助手多
    有限元分析 CAE仿真分析服務(wù)-企業(yè)/產(chǎn)品研發(fā)/客戶要求/設(shè)計優(yōu)化
    有限元分析 CAE仿真分析服務(wù)-企業(yè)/產(chǎn)品研發(fā)
    急尋熱仿真分析?代做熱仿真服務(wù)+熱設(shè)計優(yōu)化
    急尋熱仿真分析?代做熱仿真服務(wù)+熱設(shè)計優(yōu)化
    出評 開團工具
    出評 開團工具
    挖掘機濾芯提升發(fā)動機性能
    挖掘機濾芯提升發(fā)動機性能
    海信羅馬假日洗衣機亮相AWE  復(fù)古美學(xué)與現(xiàn)代科技完美結(jié)合
    海信羅馬假日洗衣機亮相AWE 復(fù)古美學(xué)與現(xiàn)代
    合肥機場巴士4號線
    合肥機場巴士4號線
    合肥機場巴士3號線
    合肥機場巴士3號線
  • 短信驗證碼 目錄網(wǎng) 排行網(wǎng)

    關(guān)于我們 | 打賞支持 | 廣告服務(wù) | 聯(lián)系我們 | 網(wǎng)站地圖 | 免責(zé)聲明 | 幫助中心 | 友情鏈接 |

    Copyright © 2025 hfw.cc Inc. All Rights Reserved. 合肥網(wǎng) 版權(quán)所有
    ICP備06013414號-3 公安備 42010502001045

    se01亚洲视频| 久久婷婷一区| 欧美日韩中字| 国产激情综合| 欧亚一区二区| 五月天综合网站| 91成人午夜| 日本aⅴ免费视频一区二区三区| 一本不卡影院| 久久视频社区| 亚洲国产精品一区| 丝袜美腿亚洲一区二区图片| 精品国产午夜肉伦伦影院| 国产精品2区| 久久精品免费看| 蜜臀久久久久久久| 亚洲电影在线| 免费看日产一区二区三区| 一区二区三区四区在线观看国产日韩| 美女福利一区| 天海翼精品一区二区三区| 78精品国产综合久久香蕉| 亚洲欧美日韩国产一区二区| 久久精品综合| 大奶一区二区三区| 亚洲电影一级片| 欧美日韩一视频区二区| 97成人超碰| 日韩欧美国产精品综合嫩v| 美女被久久久| 国产农村妇女毛片精品久久莱园子 | 羞羞视频在线观看欧美| 欧美aa一级| 中文字幕成在线观看| 亚洲欧美日韩精品一区二区 | 日韩av网站在线免费观看| 麻豆精品视频在线| 久久91导航| 亚洲啊v在线| 久久uomeier| 日本久久黄色| 97视频热人人精品免费| 久久不射中文字幕| 亚洲欧美日韩专区| 久久成人精品| 老**午夜毛片一区二区三区| 国产亚洲在线| 欧美一级专区| 色男人天堂综合再现| 日韩中文字幕亚洲一区二区va在线| 国产日韩在线观看视频| 成人豆花视频| 亚洲免费专区| 亚洲+变态+欧美+另类+精品| 国产一区99| 日韩电影在线观看电影| 日韩最新av| 精品日韩在线| 欧美色婷婷久久99精品红桃| 久久精品导航| 好看的日韩av电影| 国产精品三上| 免费成人在线观看| 国产一二三在线| 色老太综合网| 欧美a一区二区| 一区二区三区国产精华| 国产欧美精品| 亚洲超碰在线观看| 99精品电影| 香蕉av一区二区| 美女网站久久| 欧美无毛视频| 久久婷婷五月综合色丁香| 麻豆国产91在线播放| 国产欧美激情| 福利在线一区| 国产精品av久久久久久麻豆网| 日本一区二区三区视频在线看| 四虎国产精品永久在线国在线 | 日本一区二区在线看| 欧美男人天堂| www.一区| 国内精品久久久久久久影视蜜臀| 日韩一区二区中文| 欧美一区视频| 国产精品一区二区三区av | 欧美日韩a区| 欧美一级大片在线视频| 日韩一区免费| 亚洲网站视频| 四季av一区二区凹凸精品| 欧美亚洲综合视频| 国产精品一区二区99| 大型av综合网站| 欧美网站在线| 另类专区亚洲| 日本网站在线观看一区二区三区 | 99精品免费网| 亚洲国产网址| 99热精品久久| 91欧美大片| 老司机精品视频一区二区三区| 日本一区二区三区中文字幕| 久久亚洲道色| 久久国产直播| av中文资源在线资源免费观看| 国产亚洲综合精品| 欧美综合社区国产| 国产精品一区二区精品| 91精品国产调教在线观看| 亚洲少妇一区| 日本免费一区二区三区等视频| 成人精品一区二区三区电影| 中文精品电影| 欧美日中文字幕| 三级在线看中文字幕完整版| 亚洲三级观看| 久久精品123| 日韩精品中文字幕第1页| 国产激情综合| 2023国产精品久久久精品双| 日本一区二区三区视频在线| 国产在线不卡一区二区三区| 国产99亚洲| 亚洲高清国产拍精品26u| 日韩欧美天堂| 老司机午夜精品视频在线观看| 久久久久久网| 国产免费av一区二区三区| 国产综合激情| 欧美另类激情| 鲁大师精品99久久久| 欧亚一区二区| 99精品国产一区二区三区2021| 欧美在线导航| 亚洲va中文在线播放免费| 同性恋视频一区| 老牛影视一区二区三区| 欧美喷水视频| 日韩视频不卡| 99精品在线免费观看| 先锋资源久久| 日本vs亚洲vs韩国一区三区二区 | 999视频精品| 欧美美女福利视频| 粉嫩久久久久久久极品| 免费看男女www网站入口在线| 国产精品久久久久久久久久齐齐| 日韩和欧美一区二区| 欧美日韩一二三四| 日韩高清电影一区| 久久一区二区三区喷水| 日本在线一区二区| 国产主播一区| 亚洲有吗中文字幕| 老牛嫩草一区二区三区日本| 久久99国内| 波多野结衣久久精品| 国产精品丝袜在线播放| 日韩经典一区| 激情视频一区二区三区| 国产精品草草| 另类国产ts人妖高潮视频| 日韩av影院| 日韩伦理福利| 欧美一区二区三区激情视频| 青青草精品视频| 男人天堂欧美日韩| 日韩一级淫片| 四虎地址8848精品| 午夜精品婷婷| 国产一区二区三区91| 三级在线观看视频| 欧美成人69av| 国产探花在线精品| 日韩在线综合| 欧美 日韩 国产精品免费观看| 欲香欲色天天天综合和网| 成人在线免费观看91| 麻豆国产一区二区| 亚洲免费在线| 岛国精品一区| 日本欧美大码aⅴ在线播放| 制服诱惑一区二区| 国产成人tv| 麻豆国产91在线播放| 免费成人你懂的| 女同一区二区三区| www.久久爱.com| 日韩久久精品| 牛夜精品久久久久久久99黑人| 国产欧美一级| 石原莉奈在线亚洲二区| 国产精品任我爽爆在线播放| 乱一区二区av| 久久电影tv| 亚洲黄页一区| 黄色欧美网站| 欧州一区二区三区|