2808ICT - Information And Security Management - SQL Injection Testing - Database Backup Strategy - IT Assignment Help

Download Solution Order New Solution
2808ICT - Information And Security Management - SQL Injection Testing - Database Backup Strategy - IT Assignment Help
Assignment Task:

Assignment 

Student Grading System Implementation

Remarkable University is implementing a new student grading system. The scenario is the same as Assignment 1.

You will need to implement the database, create users and grant privileges to the users, perform SQL injection testing, and develop backup strategies for the database.

Things To Work On:
1. A pdf report detailing your work including (but not limited to):

1) Explanations of your database design choices, and screenshots of your database structure and data
2) Descriptions of user privileges (using access matrix) with explanations, and screenshots of the SQL commands you used
3) Descriptions of your SQL injection test (in steps) with screenshots and explanations of your observations
4) Descriptions of your backup strategies with clear justifications
5) An Implementation History as follows


2. An ER diagram (pdf) for the database design

3. An SQL script including all the commands for database implementation, user creation, and privilege granting You will receive up to 1% for the presentation of your report

PART A. Database Implementation

1. Database Design

Use the sample data provided in the Appendix and design the database using ER diagrams.

The sample data do not reflect the table structure in the database and you will need to revise the structure of the tables. You need to describe the improvement you made and explain your design choices.

The sample data are not complete either. For example, they do not describe the teaching and managing relationships: academic staff teach courses and admin staff manage courses and enrolments. You need to create those data if required. In particular,
• An academic staff may teach many courses
• A course must be taught by one or more academic staff
• Courses and enrollments must be managed by one or more admin staff
• A student can enroll in one or more courses
• A grade must correspond to an enrollment
• A student may have multiple enrollments in the same course

You also need to present the new tables after your improvement and data completion.


2. SQL Implementation

Create the tables based on your ERD and insert the provided data using a SQL script, including proper datatypes and integrity constraints.

PART B. Users and Privileges


1. Create Users

Create a sufficient number of users (at least six) to demonstrate different sets of privileges. For example, at least two students, two academic staff with different privileges and at least two admin staff in charge of courses and enrolment respectively.


2. Assign Table-level Privileges

Assign privileges to each user. Explain why such roles need to have the access on certain tables. There are some pre-defined rules:

• Staff should have restricted access according to their roles/positions. For example, admin staff managing enrollment can modify only enrollment information, and admin staff managing courses can only modify course information
• Academic staff and students can see information about courses but cannot edit it.
• Academic staff can see the names and genders of the students but not their birthdays or phone numbers.


3. Create Views and Related Privileges

Create at least two views with one of them including a join of two or more tables. Explain your choice and explain the importance of the views. Assign the views to appropriate users.

• Students should only see the grades that belong to themselves (and read only).
• Academic staff can only see the enrolment of the courses they teach.
• Academic staff can only modify grades of the course they teach.


PART C. SQL Injection Test

You will use the Web interface we provide to access the database you developed. In particular, you will try to modify the tables with SQL injection.

1. Download the index.html file from the course website (the file is located within the “Injection.zip” container). It provides the Web form interface for entering the student information. Save the file in the htdocs directory under the xampp directory. You can access the directory by clicking Explorer on the XAMPP control panel.


2. Do the same for the main.php file (also located within the “Injection.zip” container). It is a PHP script used to connect to the database.
Note that it makes the following assumptions:
a. It connects to the database as the root user whose password is empty.
b. The database name is “Assignment2”.
c. The table name is “student” and the column names and order are: student_id, first_name, last_name, DOB, sex, phone.
If your database has a different setting, you need to make appropriate changes to the main.php file. You should not make other changes to the file.

3. Open the Web form from the browser at address: localhost/index.html. You can also access it by clicking Admin and replace “dashboard” with “index.html”.

(If you get an Error 403, change the permission of both files index.html and main.php so that they can be read by anyone.)

4. You will enter some input into the form and try to modify the database (e.g., delete the grade table). If you receive the following error message, then your SQL injection is NOT successful. You will have to keep trying.


5. Explain what you are trying to input and what are the expected results.

6. Replace the main.php file in the htdocs directory with pdo_main.php (also located within the “Injection.zip” container), and rename it to main.php. This is a version with SQL injection protection. Try the same inputs on which you succeeded previously. Describe your observations and try to explain the difference.


PART D. Database Backup Strategy

Suppose the Database Administrator wants to also use a cloud-based storage service to conduct and store regular backups. Define a backup and retention strategy:

1. Why is a backup strategy important?
2. Which portions of the database should be backed up, and how often?
3. For each portion that is backed up, how many backups should be retained before the newest backup overwrites the oldest?

Implement backup and recovery (export and import). Provide the .sql file from the export, drop the database, and provide screenshot after the recovery.

This IT Assignment has been solved by our IT Assignment Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.

Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.