Monash University · S2 2026 · FACULTY OF CYBERSECURITY

FIT1093 Cybersecurity Tools and Techniques

- one subject, every graph, every model, every mark
10 Chapters52-page Bible
Our own words - no uploaded lecturer files
Built to mirror S2 2026 · updated this semester
The Complete Study & Assessment Guide · S2 2026

FIT1093 Overview

Cybersecurity Tools and Techniques
— every security goal, the tool that protects it, and the arithmetic behind it
  • Monash University
  • Semester 2, 2026
  • Level 1 unit
  • Workshops and applied sessions
  • One test, three assignments

FIT1093 Cybersecurity Tools and Techniques is Monash University's first-year introduction to the tools and techniques used to design secure systems.

  • Assessed by An in-class test and three assignments
  • Core idea Match every security goal to its tool
  • Hardest step Modular arithmetic by hand, without a calculator
  • Watch for Readable screenshots and the Week 12 demonstration
FIT1093 · Monash University
An independent, AskSia-authored study guide. AskSia is not affiliated with, endorsed by, or sponsored by Monash University; the course code and name are used for identification only.
Assessment

How FIT1093 is assessed

ComponentWeightFormat
In-Class Test40%Application of cryptography, held in the Week 7 workshop. The sample paper allows 75 minutes, is closed book with no calculators, has 10 multiple-choice and 4 short-answer questions, and covers Weeks 1 to 6.
Assignment 120%Individual written report on symmetric key cryptography, submitted as one PDF of at most 15 pages; due Friday 21 August 2026.
Assignment 2: User Authentication and Access Control25%Two written reports due Friday 9 October 2026, worth 8% and 12%, and a 10-minute demonstration in the Week 12 applied session worth 5%.
Assignment 315%Web hacking challenge; submission opens Friday 16 October and is due Monday 2 November 2026.
Current dates · verify in LMS

Current FIT1093 dates

DateItemControl
Ass
Ass
Ass
Ass

Dates are as published in the current course materials. Confirm exact deadlines and submission settings in the live LMS.

Contents · every chapter, one map

What FIT1093 covers

Follow the unit from the four security goals through symmetric and public-key cryptography, signatures, user authentication and access control, to the protocols that combine them.

01

Security Goals, Threats and Attack Types

Week 1. The security problem, confidentiality, integrity, authentication and availability, threats, vulnerabilities, attacks and controls, passive and active attacks, and the weakest link, timeliness and effectiveness principles.
02

Classical Ciphers and the One-Time Pad

Week 2. Kerckhoffs' principle, the Caesar cipher as arithmetic mod 26, substitution and frequency analysis, transposition and the rail fence, confusion and diffusion, and the one-time pad with the danger of key reuse.
03

Block Ciphers and Modes of Operation

Week 2. Block cipher correctness and pseudorandomness, the Feistel structure of DES, AES rounds, key length and brute force, and the ECB, CBC and counter modes compared.
04

Hash Functions and Message Authentication Codes

Week 3. One-way and collision-resistant hashing, the pigeonhole principle and birthday bound, MAC unforgeability, CMAC and HMAC, and why encryption alone does not give integrity.
05

Number Theory Behind Public-Key Cryptography

Week 4. The key distribution problem, trapdoor one-way functions, primes and GCDs, modular inverses and division, square-and-multiply exponentiation, and the factorisation and discrete logarithm problems.
06

Diffie-Hellman, ElGamal and RSA Encryption

Week 5. Diffie-Hellman key exchange and its man-in-the-middle attack, ElGamal encryption, RSA key generation, encryption and decryption, certificates, and hybrid encryption.
07

Digital Signatures and Non-Repudiation

Week 6. Signing and verification algorithms, unforgeability and non-repudiation, RSA hash-and-sign, ElGamal signatures, and why the hash must be one-way.
08

Password and Biometric Authentication

Week 8. Knowledge, possession and biometric factors, multi-factor authentication, dictionary attacks, salting and slow hashing, and FAR and FRR as the threshold changes.
09

Access Control, Linux Permissions and Firewalls

Week 8. Subjects, objects and access rights, owner, group and others permissions on files and folders, SUID, least privilege, and firewall rules for public and internal ports.
10

Security Protocols: TLS, IPsec and Bluetooth

Week 9. Certificates and the TLS handshake, the record protocol, forward secrecy and TLS 1.3, IPsec for virtual private networks, and Bluetooth Secure Connections pairing.

The unit synopsis sets out its scope: how widely used ciphers and authentication schemes operate and where they typically fail, how to apply them against threats to confidentiality and integrity, how to evaluate user authentication and access control, and how software vulnerabilities are exploited, found and fixed.

It finishes by looking at recent developments and future trends in cybersecurity.

The first half of the semester is cryptography. Week 1 frames the security problem as several parties with different interests, some of them malicious, and names the four goals the rest of the unit protects: confidentiality, integrity, authentication and availability.

Weeks 2 and 3 cover symmetric tools, from the Caesar cipher and the one-time pad to block ciphers such as AES, their modes of operation, hash functions and message authentication codes. Weeks 4 to 6 build public-key cryptography from its number theory, through Diffie-Hellman, ElGamal and RSA, to digital signatures.

The second half turns to systems. Week 7 holds the in-class test and introduces post-quantum cryptography.

Week 8 covers user authentication by passwords, devices and biometrics, together with access control in the Linux file system.

Week 9 shows how protocols such as TLS, IPsec and Bluetooth Secure Connections combine the earlier tools, and Weeks 10 to 12 cover web application security, database security and privacy, and an invited industry lecture.

Teaching combines online pre-class lectures with a weekly two-hour workshop and a weekly two-hour applied session, where students run cryptographic and security tools on their own laptop in the unit's Ubuntu Linux virtual machine.

Assessment is an in-class test worth 40% on the cryptography weeks and three assignments worth 20%, 25% and 15%. The test rewards careful hand calculation without a calculator, and the assignments reward complete, readable evidence of each command and result.

Worked example · free

Agree a Diffie-Hellman key modulo 17 and confirm both sides match

Q [6 marks]. The mark allocation on this example is our own practice weighting, not an official university scheme. Alice and Bob use the public prime p = 17 and base g = 3. Alice keeps a = 4 secret and Bob keeps b = 6 secret. Compute both public keys and the shared key from each side, without a calculator.
  • 2Alice's public key: 3 squared is 9, and 9 squared is 81, which is 4 × 17 + 13, so A = 13.
  • 2Bob's public key: 3 to the 4th is 13 from the line above, and 13 × 9 = 117 = 6 × 17 + 15, so B = 15.
  • 1Alice computes 15 to the 4th mod 17. Since 15 ≡ −2, this is (−2) to the 4th = 16.
  • 1Bob computes 13 to the 6th mod 17. Since 13 ≡ −4, this is 4 to the 6th = 4096 = 240 × 17 + 16, which is 16 again.
The public keys are A = 13 and B = 15, and both parties reach the shared key K = 16. An eavesdropper who sees 13 and 15 would have to solve a discrete logarithm to find either secret exponent.
Sia tip — Replace a residue by its negative whenever that makes the number smaller: 15 is −2 and 13 is −4 modulo 17, which turns two awkward powers into mental arithmetic.
Glossary

Key terms

Confidentiality
The security goal that secret data stays secret, protected by restricting access and by encryption so that intercepted data reveals nothing.
Kerckhoffs' Principle
The design rule that a cipher's security should rest on a secret key rather than a secret algorithm, so the algorithm can be published and analysed.
Block Cipher
An algorithm that encrypts one fixed-length block of plaintext under a secret key, such as AES with its 128-bit blocks.
Mode of Operation
A method for using a block cipher on messages longer than one block, such as ECB, CBC or counter mode.
Collision Resistance
The hash property that finding two different messages with the same digest is computationally infeasible.
Message Authentication Code
A tag computed from a message and a shared secret key that lets the receiver detect modification or fabrication.
Discrete Logarithm Problem
The task of recovering the exponent a from g to the power a modulo a prime p, believed infeasible for large numbers.
Non-repudiation
The signature property that a signer cannot credibly deny a document, because only their private key could have produced the signature.
False Acceptance Rate
The share of impostor attempts that a biometric system wrongly accepts, used as its measure of security against impersonation.
FAQ

FIT1093 FAQ

What does Cybersecurity Tools and Techniques cover at Monash?

It introduces the main tools for designing secure systems: symmetric and public-key encryption, hashing, message authentication codes and digital signatures, then user authentication, Linux access control, security protocols such as TLS, web application security, database security and emerging topics.

How is this Monash cybersecurity unit assessed?

Through four components from the 2026 handbook: an in-class test worth 40% held in the Week 7 workshop, Assignment 1 worth 20%, Assignment 2 worth 25% including a live demonstration, and Assignment 3, a web hacking challenge, worth 15%.

Can I use a calculator in the in-class test?

The sample paper says no electronic devices are allowed, including physical calculators, and the test is closed book. Practise modular arithmetic by hand, reducing after every multiplication and using square-and-multiply for powers.

Is there much mathematics in the unit?

There is a focused amount. Week 4 covers primes, greatest common divisors, modular inverses and fast modular exponentiation, and Weeks 5 and 6 apply them in Diffie-Hellman, ElGamal and RSA. The numbers in workshops and the sample test are small enough to handle on paper.

What happens if I miss the Assignment 2 demonstration?

The specification says missing the Week 12 demonstration gives zero for the demonstration and for Tasks 3 and 4 unless special consideration is approved. Reports submitted late or under an extension move the demonstration to a supplementary session in November.

Do I need my own laptop for the applied sessions?

Yes. Applied sessions run on your own laptop, inside the unit's Ubuntu Linux virtual machine, which you set up beforehand, using the installation instructions released in Week 1, because the practical tasks and Assignment 2 run inside it.

Can I use generative AI in the assignments?

The assignment instructions require you to declare each generative AI tool you used, saying where and for what. Assignment 2 also asks for a readable link or PDF of the conversation, and a missing or unreadable link limits the marks to half.

Study strategy

How to prepare for the assessments

Treat the unit as a map from each security goal to the tool that protects it, and keep that map on one page you add to every week. For the cryptography weeks, practise by hand: work every workshop calculation again with numbers of your own, reduce modulo n after every multiplication, and check each answer by reversing it, decrypting what you encrypted or verifying what you signed.

Learn the definitions in pairs that are easy to confuse, such as threat and vulnerability, passive and active attacks, hash and MAC, unforgeability and non-repudiation, and FAR and FRR, and be able to say in one sentence what separates each pair. Use the weekly multiple-choice quizzes as a check rather than a score; they do not count toward the grade but are discussed in the workshop.

For the assignments, run every command in the virtual machine yourself, capture readable screenshots as you go, and rehearse the Assignment 2 demonstration from memory on a fresh test user before Week 12.

Study FIT1093 with AI

Your AI Cybersecurity tutor for FIT1093

Stuck on a hard FIT1093 question? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Cybersecurity Tools and Techniques question and get a clear, step-by-step explanation grounded in how the course is actually taught and assessed. Read this whole study guide free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 111 of your Monash University subjects - and 1,000+ Bibles across every Australian university.
Sia - your FIT1093 tutor, unlimited, worked the way the exam marks it
The full 52-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works
FIT1093 · Cybersecurity Tools and Techniques - independent study guide on the AskSia Library. More Monash University subjects · Microeconomics across all universities