Management System in the Programming Language C/C++ - IT Assignment Help

Download Solution Order New Solution
Assignment Task
 
 

Task
The software development is for 30% of your module mark. You will produce a secure prototype of a student record management system in the programming language C/C++, accessed through a web interface. This will test the following module level outcomes.
Have a thorough understanding of the principles and issues involved in designing secure software and be able to utilise them in the construction of complex software
Have a thorough understanding of the main attack vectors commonly used to attack software and be able to design and implement software that reduces the likelihood of those vulnerabilities being exploitable
Design and implement concurrent and distributed software which operates in hostile environments
Design and implement secure software that utilises the underlying security model of the OS and hardware.
CW2: Software Development
The software you are writing is a CGI program written in C/C++. This means that it is running on a web server and it will be accessed through a web interface. The function of the software is a student record management system. Lecturers will use it to view a list of the students for their modules and they will be able to view the marks for those students and change them. A separate person called the administrator will be responsible for deciding which lecturers oversee which modules. They will also add students to modules; for simplicity, the students will not have accounts with which to add themselves to modules.
Here are the functional and non-functional requirements for the software development. You will be marked on your understanding of potential attack vectors against secure software and on the principles of designing secure software, and on how well you design and implement software that reduces the likelihood of those vulnerabilities being exploitable.
Functional Requirements
FR1 There are two kinds of users: lecturers and administrators. Both can register an account and set a password.
FR2 Lecturers can see a list of their modules and a list of the students on each module. They can also enter and change marks.
FR3 Administrators can assign lecturers to modules and students to modules. There is only one administrator account.
FR4 The process of logging in should use two-factor authentication. The user must enter a second password sent by email after the main password has been entered. The email address to be used is the one entered when registering the account. If you are not able to install the relevant mail library, you can simulate the process of emailing by appending to a “mail spool” text file representing all the emails that have been sent.
FR5 The administrator account, in addition to the protections of FR4, must also be authenticated by a “hardware” token, which should be implemented as a piece of challenge-response software.
Non-Functional Requirements
NFR1 You may use your own web server running on your own machine if you wish. However, the department has provided the SOTS server, which you can use instead. Your login details will be the same username and password you use for Moodle and Google Suite.
NFR2 The system must be developed in C/C++. You may use CGI to interact with the web pages. You may use the C/C++ CGI libraries, which have been installed on SOTS, if you are using SOTS. Here is one of many tutorials on them:
https://www.tutorialspoint.com/cplusplus/cpp_web_programming.htmNFR3 The system must be robust and secure. Specifically, it should be capable of mitigating many kinds of attacks covered in the module, as detailed in the marking scheme. SSL must not be the sole means of preventing these attacks.
NFR4 The system must be designed with maintainability, security and reliability in mind and according to best practice in designing and implementing secure software. Defensive software practices should be used throughout
NFR5 Your code should be commented and have sensible and consistent naming
NFR6 The system should be responsive and easy to use
NFR7 You may use cryptographic libraries if you wish.
NFR8 Your report must explain why you believe you have satisfied NFR3, NFR4, NFR6.
NFR9 Your report must explain why you believe you have satisfied FR1, FR2, FR3, FR4, FR5.
 



This IT Assignment has been solved by our IT Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+Students in Australia, UK & US by helping them to score HD in their academics. Our Experts are well trained to follow all marking rubrics & referencing style.
    
Be it a used or new solution, the quality of the work submitted by our assignment Experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.