Assessment Guidelines
Assessment Guidelines
ITNE2002
Networking and Information
Security
Semester 2, 2024
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No: 20829
Assessment Overview
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No: 20829
Referencing guides
You must reference all the sources of information you have used in your assessments. Please use the
IEEE referencing style when referencing in your assessments in this unit. Refer to the library’s
referencing guides for more information.
• https://elearning.vit.edu.au/pluginfile.php/473840/block_html/content/VIT%20Library%20Refer
encing%20-%20IEEE%20-%2007042020.pdf
Academic misconduct
VIT enforces that the integrity of its students’ academic studies follows an acceptable level of
excellence. VIT will adhere to its VIT Policies, Procedures and Forms where it explains the importance
of staff and student honesty in relation to academic work. It outlines the kinds of behaviours that are
"academic misconduct", including plagiarism.
Late submissions
In cases where there are no accepted mitigating circumstances as determined through VIT Policies,
Procedures and Forms, late submission of assessments will lead automatically to the imposition of a
penalty. Penalties will be applied as soon as the deadline is reached.
• Extensions of the due date for an assessment, other than an examination (e.g. assignment
extension).
• Special Consideration (Special Consideration in relation to a Completed assessment, including
an end-of-unit Examination).
Students wishing to request Special Consideration in relation to an assessment the due date of which has
not yet passed must engage in written emails to the teaching team to Request for Special Consideration
as early as possible and prior to start time of the assessment due date, along with any accompanying
documents, such as medical certificates.
Contract Cheating
Contract cheating usually involves purchasing an assignment or piece of research from another party. This
may be facilitated by a fellow student or friend or purchased on a website. The unauthorized use of
generative Artificial Intelligence (AI) is also considered cheating. Other forms of contract cheating
include paying another person to sit an exam in the student's place.
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No: 20829
Contract cheating warning:
• By paying someone else to complete your academic work, you don’t learn as much as you
could have if you did the work yourself.
• You are not prepared for the demands of your future employment.
• You could be found guilty of academic misconduct.
• Many of for pay contract cheating companies recycle assignments despite guarantees of
“original, plagiarism-free work” so similarity is easily detected by TurnitIn.
• Penalties for academic misconduct include suspension and exclusion.
• Students in some disciplines are required to disclose any findings of guilt for academic
misconduct before being accepted into certain professions (e.g., law).
• You might disclose your personal and financial information in an unsafe way, leaving
yourself open to many risks including possible identity theft.
• You also leave yourself open to blackmail - if you pay someone else to do an assignment for
you, they know you have engaged in fraudulent behaviour and can always blackmail you.
Grades
We determine your grades to the following Grading Scheme:
Grade Percentage
A 80% – 100%
B 70% – 79%
C 60% – 69%
D 50% – 59%
F 0% – 49%
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No: 20829
Assessment Details for Assessment Item 1:
Overview
Assessment tasks Learning Outcome Mapping
Assessment ID Assessment Item When due Weighting ULO# CLO# for BITS
1 Tutorial / Laboratory
Reports Session 4 10%
Part A (Individual) A, B, C, D, F, H,
1,2,3,4
Tutorial / Laboratory I, J, K
Reports Session 9 10%
Part B (Individual)
Introduction
You will submit work in tutorial activities during the study period. This is an individual assessment. This Assessment comprises of two
parts
1. In-class submission
a. This is a short answer or MCQ question and you will be given 1 mark for each week. This session will only appear during
your tutorial session and if you are not able to do it during that time, you will not be getting this session again. There are 9
of these tests and these tests will be starting from session#2.
2. Laboratory classes.
S1
Lab1 in S2 Oracle + Windows 10
Lab2 in S3 Download and install Kali
Lab3 in S4 Use Kali + Nmap to scan open ports (i.e., 8.8.8.8)
Lab4 in S5 Learning about Vulnerable ports in Windows 10 + Windows firewall
Lab5 in S6 Install pfsense
Lab6 in S7 Install and Work with Snort
Lab7 in S8 Work with snort in pfsense
Lab8 in S9 Work with snort rules
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Lab9 in S10 Work with snort rules
a. You have to finish all the assigned tasks and take screenshots of all the activities mentioned in the tasks. When you are
taking the screenshot it should show the date, time, and your account details. (HINT: you can you snipping tool to take the
screenshot with the date and time). The reports should have all the necessary screen shots from your PC with the working
solutions.
Submission Instructions
All submissions are to be submitted through Turnitin. Drop-boxes linked to Turnitin will be set up in Moodle. Assessments not submitted through cloud
application will not be considered. Submissions must be made by the end of sessions 4 and 9 respectively.
The Turnitin similarity score will be used to determine any plagiarism of your submitted assessment. Turnitin will check conference websites, Journal articles,
online resources, and your peer’s submissions for plagiarism. You can see your Turnitin similarity score when you submit your assessments to the
appropriate drop-box. If your similarity score is of concern, you can change your assessment and resubmit. However, re-submission is only allowed before the
submission due date and time. You cannot make re-submissions after the due date and time have elapsed.
Furthermore, you are not allowed to use AI-based content generation software, and the Turnitin AI score will be used to mark the document. Make sure all the
screenshots are timestamped, and your account details are visible in those screenshots.
Note: All work is due by the due date and time. Late submissions will be penalized at 20% of the assessment final grade per day, including weekends.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Marking Criteria/Rubric
You will be assessed on the following marking criteria/Rubric:
Excellent (100%) Good (75%) Average (65%) Poor (30%) Plagiarized AI score
category Below Average detected and no
(55%) submission (0%)
Several screenshots are correct, The document is plagiarized, or
Tutorial/Laboratory All the screenshots are Most of the screenshots are Some of the screenshots
and those are from the students
Most of the screenshots
AI content exceeds the given
correct, and those are from correct, and those are from are correct, and those are working VMs. (3.85) are not correct OR the thresholds
Part A the students working VMs the students working VMs from the students working screenshots are copied
7 marks (7) (5.25) VMs (4.55) from third parties. (2.1)
In class Activities 7-9 answers are correct (3) 5-6 answers are correct (2) 1-4 answers are correct (1) 0 answers are correct (0)
3 marks
Tutorial/Laboratory All the screenshots are Most of the screenshots are Some of the screenshots Several screenshots are Most of the screenshots The document is plagiarized, or
correct, and those are from correct, and those are from are correct, and those are correct, and those are from are not correct OR the AI content exceeds the given
Part B the students working VMs the students working VMs from the students the students working VMs. screenshots are copied thresholds
(7) (5.25) working VMs (4.55) (3.85) from third parties. (2.1)
7 marks
In class Activities 7-9 answers are correct (3) 5-6 answers are correct (2) 1-4 answers are correct 0 answers are correct (0)
(1)
3
marks
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Assessment Details for Assessment Item 2:
You must use the Kali VM and Windows 10 VM configured in Session 5 with open ports to complete this assessment.
Use the nmap in Kali tool to analyze the vulnerabilities and the open ports from the Windows 10 VM, and make a report about the following:
1. A detailed Scan report of Kali and your view about the report.
2. What are the services related to the opened ports in Windows VM? You must give the usage of those services as well.
3. Vulnerability of every port/service mentioned in Step 2. Moreover, you must explain what the threats to an organization are due to those open ports.
4. How to mitigate those vulnerabilities.
The report should be 1000 words and should contain all the necessary screenshots taken from your VMs. Note that the screenshots should show the username
of your PC as your student ID. (refer to labs 1 and 2)
Submission Instructions
All submissions are to be submitted through Turnitin. Drop-boxes linked to Turnitin will be set up in Moodle. Assessments not submitted through cloud
application will not be considered. Submissions must be made by the end of sessions 7 respectively.
The Turnitin similarity score will be used to determine any plagiarism of your submitted assessment. Turnitin will check conference websites, Journal articles,
online resources, and your peer’s submissions for plagiarism. You can see your Turnitin similarity score when you submit your assessments to the
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
appropriate drop-box. If your similarity score is of concern, you can change your assessment and resubmit. However, re-submission is only allowed before the
submission due date and time. You cannot make re-submissions after the due date and time have elapsed.
Furthermore, you are not allowed to use AI-based content generation software, and the Turnitin AI score will be used to mark the document. Make sure all the
screenshots are timestamped, and your account details are visible in those screenshots.
Note: All work is due by the due date and time. Late submissions will be penalized at 20% of the assessment final grade per day, including weekends.
Marking Criteria/Rubric
You will be assessed on the following marking criteria/Rubric:
Criteria Excellent (100%) Good (75%) Average (65%) Below Average Poor (30%) Plagiarized
(50%) AI score
detected and
no
submission
(0%)
Scan Report of Detailed and Accurate Adequate scan Limited scan report Incomplete or The document is
plagiarized, or AI
Kali (8 marks) comprehensive scan identification of report with some inaccurate scan content exceeds
report generated open ports. highlighting inaccuracies or report the given
thresholds
using nmap. major findings missing
and open ports, information
Services Used Clear identification Accurate Basic Partial or Inaccurate or The document is
plagiarized, or AI
by Open Ports and analysis of identification of identification of inconsistent incomplete content exceeds
(5 marks) services running on services associated services running identification of identification of the given
thresholds
open ports, with with open ports. on open ports. services. services
detailed descriptions associated with
and potential open ports.
security
implications.
Vulnerability Thorough Good analysis of Basic Limited assessment Incomplete or The document is
plagiarized, or AI
of Each Port to assessment of vulnerabilities identification of of vulnerabilities, inaccurate content exceeds
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Windows PC vulnerabilities linked to open vulnerabilities with some assessment of the given
thresholds
(2 marks) associated with each ports. associated with inaccuracies. vulnerabilities.
open port. open ports.
Mitigation Comprehensive and Clear and practical Basic mitigation Limited or generic Inadequate or The document is
plagiarized, or AI
Strategies (3 effective mitigation mitigation strategies mitigation impractical content exceeds
marks) strategies proposed recommendations suggested. recommendations mitigation the given
thresholds
for addressing provided. offered. strategies
identified proposed
vulnerabilities.
Overall Well-structured Clear and Adequate report Disorganized or Incoherent or The document is
plagiarized, or AI
Quality of the report. organized report providing basic incomplete report poorly written content exceeds
Report (2 with few minor analysis. with significant report lacking the given
thresholds
marks) issues or gaps. clarity, structure,
inconsistencies. or substance.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Assessment Details for Assessment Item 3:
Introduction
In this individual assignment, you are expected to install a commercial proxy server along with an online virus guard. The main objective of this assignment is
to have students install a commercial proxy server to filter traffic based on its authenticity and intention. Specifically, students will install the Squid proxy
server into the pfSense virtual host and configure it as both a proxy server for the LAN environment and an online virus guard.
To accomplish this, students should use pfSense, which was installed in session 5, to install Squid and the CLAM antivirus. The installation process, including
configurations such as Windows proxy configurations, should be recorded via screen recording.
1. Install pfSense and log into pfSense using either Kali Linux or Windows 10 VM.
2. Install Squid on pfSense.
3. Configure firewall rules in pfSense to enable the Squid proxy. The firewall should allow the local network for port address 3184.
4. Configure Squid, including local cache and remote cache, and enable the proxy to work.
5. Disable the NAT interface of the Windows PC and configure the local network of both Windows and pfSense. Set the IP address of the Windows VM
as 192.168.1.100/24 and ensure the pfSense IP address is set to 192.168.1.1/24. Ping from the Windows VM to pfSense and ensure the connectivity
between pfSense and Windows 10 VM.
6. Configure the Windows 10 virtual machine to use the proxy server as 192.168.1.1 and port 3184 and go to the Internet. You can do that by editing
Windows 10 network settings to use a Proxy.
7. Enable and configure the "CALM" Antivirus guard in Squid.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
8. Demonstrate blocking a malicious site from the Windows 10 VM. For that, you have to download an anti-malware test file from
https://www.eicar.org/ from the Windows 10 virtual machine and show that Squid together with CALMAV block that signature file.
9. Students may refer to the below resources to finish this assessment.
When installing the above software packages, you may use any online resource as reference. However, I recommend following the below.
1. pfSense:
o pfSense Official Documentation: Official documentation covering installation, configuration, and troubleshooting.
o YouTube - Lawrence Systems: Lawrence Systems offers detailed tutorials and walkthroughs on pfSense configuration and
features.
2. Squid Proxy Server:
o Squid Official Documentation: Official documentation with guides, configuration examples, and FAQs.
o Configure Squid Proxy: Configuring the SquidGuard Package
o GitHub - Squid Proxy Server Configuration Examples: GitHub repository with Squid proxy server configuration examples
and scripts.
3. CLAMAV Antivirus on squid:
o CALM Antivirus Official Website: Visit the official website for information on CLAM antivirus features and solutions.
o https://squidclamav.darold.net/ provides detailed documentation about configuring CLAM with Squid.
Submission Instructions
This is a video Submission.
The video must be recorded as a screen recording and the recorded video has to be submitted through the link provided in Moodle. When you are recording the video,
your face should be there. That can be simply done by recording the video as a Zoom meeting desktop sharing.
Note: All work is due by the due date and time. Late submissions will be penalized at 20% of the assessment final grade per day, including weekends.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Marking Criteria/Rubric
You will be assessed on the following marking criteria/Rubric:
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Assessment Details for Assessment Item 4
Note: * denotes ‘Hurdle Assessment Item’ that students must achieve at least 40% in this item to pass the unit.
Introduction
In this assessment, students are required to configure the following topology and perform several attacks to demonstrate the robustness of the
constructed network. Students have complete freedom to use their preconfigured servers to create the network, but they must assign the IP addresses
and configurations exactly as given in the topology diagram.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
When creating the network topology, students MUST follow the activities listed below:
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
c. Installing software to pfSense (8 marks)
i. Squid
ii. Snort
iii. Clam antivirus.
iv. Firewall
d. Executing above tests and the outputs (5 marks)
i. Block pingswip in pfSense
ii. Blacklist www.facebook.com
iii. Firewall configuration to block ping message.
4. Finally, students should demonstrate using a Zoom or Teams meeting among themselves (if the student unable use Zoom or Teams record themselves,
they can use OBS Studio). Each student should present their contribution towards the project, and the meeting should be screen recorded. The recorded
video should be submitted through Moodle, ensuring that the video is turned on during the presentation. (15 Marks)
Submission Instructions
Document:
The report should be 1500 words. All submissions are to be submitted through Turnitin. Drop-boxes linked to Turnitin will be set up in Moodle. Assessments
not submitted through cloud application will not be considered. Submissions must be made by the end of sessions 12 and 13 respectively.
The Turnitin similarity score will be used to determine any plagiarism of your submitted assessment. Turnitin will check conference websites, Journal articles,
online resources, and your peer’s submissions for plagiarism. You can see your Turnitin similarity score when you submit your assessments to the
appropriate drop-box. If your similarity score is of concern, you can change your assessment and resubmit. However, re-submission is only allowed before the
submission due date and time. You cannot make re-submissions after the due date and time have elapsed.
Furthermore, you are not allowed to use AI-based content generation software, and the Turnitin AI score will be used to mark the document. Make sure all the
screenshots are timestamped, and your account details are visible in those screenshots.
Demonstration:
The demonstration must be arranged as a team meeting or Zoom meeting among the students, and all participants must turn on their cameras during the meeting. The
person responsible for the demonstration setup should share the screen, and all members should present their components and demonstrate how they were
implemented. The demonstration should include showing configurations, although not necessarily the installations. The demonstration should be completed within
10 minutes, and the recorded video should be uploaded through Moodle.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Note: All work is due by the due date and time. Late submissions will be penalized at 20% of the assessment final grade per day, including weekends.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
Marking Criteria/Rubric
You will be assessed on the following marking criteria/Rubric:
Criteria Excellent (100%) Good (75%) Average (65%) Below Average Poor (30%) Plagiarize
(50%) d AI score
detected
and no
submission
(0%)
1. Introduction Provides a Offers a clear Provides a basic Offers a limited Provides an The document
is plagiarized,
(3 marks) comprehensive outlining the introduction to the introduction to the inadequate or AI content
clearly outlining the objectives and document but may document, lacking introduction. exceeds the
given
objectives and scope effectively. lack clarity or clarity or thresholds
scope. engagement. coherence.
2. Network Provide a detailed Provide some Provide a basic Attempted to install Very poor The document
is plagiarized,
Topology installations and installations of one installations and and configure Kali, installation and or AI content
Implementatio configurations of or two systems of configurations of Windows 10, and or no exceeds the
given
n (9 marks) Kali, Windows 10, Kali, Windows 10, Kali, Windows 10, pfSense. installation thresholds
and pfSense. and pfSense. and pfSense. information are
given.
3. Installing Successfully installs Installs Squid, Installs few of Installs only one or Very poor The document
is plagiarized,
Software to Squid, Snort, Clam Snort, Clam Squid, Snort, Clam two softwaeds and installation and or AI content
pfSense (8 antivirus, and antivirus, and antivirus, and very limited or no exceeds the
given
marks) configures the configures the configures the configurations done installation thresholds
firewall on pfSense firewall on pfSense firewall on pfSense for Squid, Snort, information are
with precision and with minor issues or with some errors or Clam antivirus. given.
effectiveness. oversights. inconsistencies.
4. Executing Executes tests to Executes and test Executes one of the Attempted to block Very poor The document
is plagiarized,
Tests and block pingswip, pingswip, pingswip, pingswip, attempt or none or AI content
Outputs (5 blacklist blacklisting blacklisting blacklisting of those are exceeds the
given
marks) www.facebook.com www.facebook.com www.facebook.com www.facebook.com successful. thresholds
, and configure the , and configuring , or configuring the , or configuring the
firewall to block the firewall to block firewall to block firewall to block
ping messages ping messages. But ping messages. ping messages. But
effectively, was not successful.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829
providing accurate limited information
and clear outputs. are provided.
5. Presentation Delivers a highly Delivers a clear and Delivers a basic Delivers a Delivers an
(15 marks) engaging and well- well-structured presentation, with presentation with inadequate
structured presentation, some issues in significant issues in presentation,
presentation, effectively structure or structure or lacking
effectively communicating the communication communication structure,
communicating the content with clarity. clarity, affecting clarity, or
content with clarity, professionalism and audience professionalism
professionalism, clarity. understanding. , hindering
and enthusiasm. audience
engagement
and
understanding.
10
Victorian Institute of Technology www.vit.edu.au CRICOS Provider No. 02044E, RTO No:
20829