FIT1093 Cybersecurity Tools and Techniques
FIT1093 Overview
- Monash University
- Semester 2, 2026
- Level 1 unit
- Workshops and applied sessions
- One test, three assignments
FIT1093 Cybersecurity Tools and Techniques is Monash University's first-year introduction to the tools and techniques used to design secure systems.
- Assessed by An in-class test and three assignments
- Core idea Match every security goal to its tool
- Hardest step Modular arithmetic by hand, without a calculator
- Watch for Readable screenshots and the Week 12 demonstration
How FIT1093 is assessed
| Component | Weight | Format |
|---|---|---|
| In-Class Test | 40% | Application of cryptography, held in the Week 7 workshop. The sample paper allows 75 minutes, is closed book with no calculators, has 10 multiple-choice and 4 short-answer questions, and covers Weeks 1 to 6. |
| Assignment 1 | 20% | Individual written report on symmetric key cryptography, submitted as one PDF of at most 15 pages; due Friday 21 August 2026. |
| Assignment 2: User Authentication and Access Control | 25% | Two written reports due Friday 9 October 2026, worth 8% and 12%, and a 10-minute demonstration in the Week 12 applied session worth 5%. |
| Assignment 3 | 15% | Web hacking challenge; submission opens Friday 16 October and is due Monday 2 November 2026. |
Current FIT1093 dates
| Date | Item | Control |
|---|---|---|
| A | s | s |
| A | s | s |
| A | s | s |
| A | s | s |
Dates are as published in the current course materials. Confirm exact deadlines and submission settings in the live LMS.
What FIT1093 covers
Follow the unit from the four security goals through symmetric and public-key cryptography, signatures, user authentication and access control, to the protocols that combine them.
Security Goals, Threats and Attack Types
Week 1. The security problem, confidentiality, integrity, authentication and availability, threats, vulnerabilities, attacks and controls, passive and active attacks, and the weakest link, timeliness and effectiveness principles.02Classical Ciphers and the One-Time Pad
Week 2. Kerckhoffs' principle, the Caesar cipher as arithmetic mod 26, substitution and frequency analysis, transposition and the rail fence, confusion and diffusion, and the one-time pad with the danger of key reuse.03Block Ciphers and Modes of Operation
Week 2. Block cipher correctness and pseudorandomness, the Feistel structure of DES, AES rounds, key length and brute force, and the ECB, CBC and counter modes compared.04Hash Functions and Message Authentication Codes
Week 3. One-way and collision-resistant hashing, the pigeonhole principle and birthday bound, MAC unforgeability, CMAC and HMAC, and why encryption alone does not give integrity.05Number Theory Behind Public-Key Cryptography
Week 4. The key distribution problem, trapdoor one-way functions, primes and GCDs, modular inverses and division, square-and-multiply exponentiation, and the factorisation and discrete logarithm problems.06Diffie-Hellman, ElGamal and RSA Encryption
Week 5. Diffie-Hellman key exchange and its man-in-the-middle attack, ElGamal encryption, RSA key generation, encryption and decryption, certificates, and hybrid encryption.07Digital Signatures and Non-Repudiation
Week 6. Signing and verification algorithms, unforgeability and non-repudiation, RSA hash-and-sign, ElGamal signatures, and why the hash must be one-way.08Password and Biometric Authentication
Week 8. Knowledge, possession and biometric factors, multi-factor authentication, dictionary attacks, salting and slow hashing, and FAR and FRR as the threshold changes.09Access Control, Linux Permissions and Firewalls
Week 8. Subjects, objects and access rights, owner, group and others permissions on files and folders, SUID, least privilege, and firewall rules for public and internal ports.10Security Protocols: TLS, IPsec and Bluetooth
Week 9. Certificates and the TLS handshake, the record protocol, forward secrecy and TLS 1.3, IPsec for virtual private networks, and Bluetooth Secure Connections pairing.The unit synopsis sets out its scope: how widely used ciphers and authentication schemes operate and where they typically fail, how to apply them against threats to confidentiality and integrity, how to evaluate user authentication and access control, and how software vulnerabilities are exploited, found and fixed.
It finishes by looking at recent developments and future trends in cybersecurity.
The first half of the semester is cryptography. Week 1 frames the security problem as several parties with different interests, some of them malicious, and names the four goals the rest of the unit protects: confidentiality, integrity, authentication and availability.
Weeks 2 and 3 cover symmetric tools, from the Caesar cipher and the one-time pad to block ciphers such as AES, their modes of operation, hash functions and message authentication codes. Weeks 4 to 6 build public-key cryptography from its number theory, through Diffie-Hellman, ElGamal and RSA, to digital signatures.
The second half turns to systems. Week 7 holds the in-class test and introduces post-quantum cryptography.
Week 8 covers user authentication by passwords, devices and biometrics, together with access control in the Linux file system.
Week 9 shows how protocols such as TLS, IPsec and Bluetooth Secure Connections combine the earlier tools, and Weeks 10 to 12 cover web application security, database security and privacy, and an invited industry lecture.
Teaching combines online pre-class lectures with a weekly two-hour workshop and a weekly two-hour applied session, where students run cryptographic and security tools on their own laptop in the unit's Ubuntu Linux virtual machine.
Assessment is an in-class test worth 40% on the cryptography weeks and three assignments worth 20%, 25% and 15%. The test rewards careful hand calculation without a calculator, and the assignments reward complete, readable evidence of each command and result.
Worked example · free
Agree a Diffie-Hellman key modulo 17 and confirm both sides match
- 2Alice's public key: 3 squared is 9, and 9 squared is 81, which is 4 × 17 + 13, so A = 13.
- 2Bob's public key: 3 to the 4th is 13 from the line above, and 13 × 9 = 117 = 6 × 17 + 15, so B = 15.
- 1Alice computes 15 to the 4th mod 17. Since 15 ≡ −2, this is (−2) to the 4th = 16.
- 1Bob computes 13 to the 6th mod 17. Since 13 ≡ −4, this is 4 to the 6th = 4096 = 240 × 17 + 16, which is 16 again.
Key terms
- Confidentiality
- The security goal that secret data stays secret, protected by restricting access and by encryption so that intercepted data reveals nothing.
- Kerckhoffs' Principle
- The design rule that a cipher's security should rest on a secret key rather than a secret algorithm, so the algorithm can be published and analysed.
- Block Cipher
- An algorithm that encrypts one fixed-length block of plaintext under a secret key, such as AES with its 128-bit blocks.
- Mode of Operation
- A method for using a block cipher on messages longer than one block, such as ECB, CBC or counter mode.
- Collision Resistance
- The hash property that finding two different messages with the same digest is computationally infeasible.
- Message Authentication Code
- A tag computed from a message and a shared secret key that lets the receiver detect modification or fabrication.
- Discrete Logarithm Problem
- The task of recovering the exponent a from g to the power a modulo a prime p, believed infeasible for large numbers.
- Non-repudiation
- The signature property that a signer cannot credibly deny a document, because only their private key could have produced the signature.
- False Acceptance Rate
- The share of impostor attempts that a biometric system wrongly accepts, used as its measure of security against impersonation.
FIT1093 FAQ
What does Cybersecurity Tools and Techniques cover at Monash?
It introduces the main tools for designing secure systems: symmetric and public-key encryption, hashing, message authentication codes and digital signatures, then user authentication, Linux access control, security protocols such as TLS, web application security, database security and emerging topics.
How is this Monash cybersecurity unit assessed?
Through four components from the 2026 handbook: an in-class test worth 40% held in the Week 7 workshop, Assignment 1 worth 20%, Assignment 2 worth 25% including a live demonstration, and Assignment 3, a web hacking challenge, worth 15%.
Can I use a calculator in the in-class test?
The sample paper says no electronic devices are allowed, including physical calculators, and the test is closed book. Practise modular arithmetic by hand, reducing after every multiplication and using square-and-multiply for powers.
Is there much mathematics in the unit?
There is a focused amount. Week 4 covers primes, greatest common divisors, modular inverses and fast modular exponentiation, and Weeks 5 and 6 apply them in Diffie-Hellman, ElGamal and RSA. The numbers in workshops and the sample test are small enough to handle on paper.
What happens if I miss the Assignment 2 demonstration?
The specification says missing the Week 12 demonstration gives zero for the demonstration and for Tasks 3 and 4 unless special consideration is approved. Reports submitted late or under an extension move the demonstration to a supplementary session in November.
Do I need my own laptop for the applied sessions?
Yes. Applied sessions run on your own laptop, inside the unit's Ubuntu Linux virtual machine, which you set up beforehand, using the installation instructions released in Week 1, because the practical tasks and Assignment 2 run inside it.
Can I use generative AI in the assignments?
The assignment instructions require you to declare each generative AI tool you used, saying where and for what. Assignment 2 also asks for a readable link or PDF of the conversation, and a missing or unreadable link limits the marks to half.
How to prepare for the assessments
Treat the unit as a map from each security goal to the tool that protects it, and keep that map on one page you add to every week. For the cryptography weeks, practise by hand: work every workshop calculation again with numbers of your own, reduce modulo n after every multiplication, and check each answer by reversing it, decrypting what you encrypted or verifying what you signed.
Learn the definitions in pairs that are easy to confuse, such as threat and vulnerability, passive and active attacks, hash and MAC, unforgeability and non-repudiation, and FAR and FRR, and be able to say in one sentence what separates each pair. Use the weekly multiple-choice quizzes as a check rather than a score; they do not count toward the grade but are discussed in the workshop.
For the assignments, run every command in the virtual machine yourself, capture readable screenshots as you go, and rehearse the Assignment 2 demonstration from memory on a fresh test user before Week 12.
Your AI Cybersecurity tutor for FIT1093
Stuck on a hard FIT1093 question? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Cybersecurity Tools and Techniques question and get a clear, step-by-step explanation grounded in how the course is actually taught and assessed. Read this whole study guide free, then take your hardest questions to Sia.