MASTER OF SCIENCE CYBERSECURITY (MCY)
| Module Code | Module Name | Description |
|---|---|---|
|
MCY501 |
Applied Cryptology
|
This module will cover; Foundations – Protocol Building Blocks - Basic Protocols - Intermediate Protocols – Advanced Protocols - Zero-Knowledge Proofs - Zero-Knowledge Proofs of Identity -Blind Signatures - Identity-Based Public-Key Cryptography - Oblivious Transfer - Oblivious Signatures - Esoteric Protocols ; Key Length - Key Management - Electronic Codebook Mode - Block Replay - Cipher Block Chaining Mode - Stream Ciphers - Self-Synchronizing Stream Ciphers - Cipher-Feedback Mode - Synchronous Stream Ciphers - Output-Feedback Mode - Counter Mode - Choosing a Cipher Mode - Interleaving - Block Ciphers versus Stream Ciphers - Choosing an Algorithm . Indicative content includes the detailed examination of symmetric and asymmetric encryption algorithms such as AES, RSA, and ECC, as well as the mechanics of hash functions and digital signatures. The curriculum covers Public Key Infrastructure (PKI) and trust models, alongside critical cryptographic protocols like TLS, SSH, and IPsec. Students will also explore cryptanalysis, side-channel attacks, and the emerging challenges of post-quantum cryptography. |
|
MCY502 |
Security Scripting and Analysis |
This Module Will empower students with the following Cover Introduction To Programming Language Types And Styles; Introduction To Interpreted Languages - Data Types And Variables - Operators And Expressions - Program Structure And Control - Functions And Functional Programming. Analyzing Traffic In Thin Air Network Security Analysis.The module equips students with the programming skills necessary to automate security tasks and analyze complex data sets. Focusing on languages such as Python and Bash, the course teaches students how to write scripts for network scanning, vulnerability parsing, and log analysis. Indicative content focuses on Python and Bash specifically for security professionals, covering techniques for automating network scans using Nmap scripting and manipulating packets with tools like Scapy. Students will learn to parse logs for anomaly detection, utilize regular expressions in forensics, and interact with APIs to gather and integrate threat intelligence. |
|
MCY503 |
Forensics and Incident Response |
This Module will empower students with the following; Incident And Incident Response ; Introduction To Incident - Incident Response Methodology – Steps - Activities In Initial Response Phase After Detection Of An Incident ; Initial Response And Forensic Duplication ; Initial Response & Volatile Data Collection From Windows System - Initial Response & Volatile Data Collection From Unix System - Forensic Duplication: Forensic Duplication: Forensic Duplicates As Admissible Evidence, Forensic Duplication Tool Requirements, Creating A Forensic Duplicate/Qualified Forensic Duplicate Of A Hard Drive ; Storage And Evidence Handling ; File Systems: Fat, NTFS - Forensic Analysis Of File Systems - Storage Fundamentals: Storage Layer, Hard Drives Evidence Handling: Types Of Evidence, Challenges In Evidence Handling, Overview Of Evidence Handling Procedure ; Network Forensics ; Collecting Network Based Evidence - Investigating Routers - Network Protocols - Email Tracing - Internet Fraud ; Systems Investigation And Ethical Issues ; Data Analysis Techniques - Investigating Live Systems (Windows &Unix) - Investigating Hacker Tools - Ethical Issues – Cybercrime |
|
MCY504 |
Mobile and Digital Forensics |
This Module Will Cover The Following; Overview Of Wireless Technologies And Security:Personal Area Networks, Wireless Local Area Networks, Metropolitan Area Networks, Wide Area Networks. Wireless Threats, Vulnerabilities And Security: Wireless Lans, War Driving, War Chalking, War Flying, Common Wi-Fi Security Recommendations, PDA Security, Cell Phones And Security, Wireless Dos Attacks, Networked Devices And Contamination ; Digital Forensics Examination Principles: Previewing, Imaging, Continuity, Hashing And Evidence Locations- Seven Element Security Model- Developmental Model Of Digital Systems- Audit And Logs- Evidence Interpretation: Data Content And Context. Building on general forensic principles, this module specializes in the recovery and analysis of data from mobile devices and non-traditional digital media. It addresses the unique challenges posed by mobile operating systems, encryption implementation, and cloud-based backups. Indicative content includes the study of iOS and Android architectures and file systems, contrasting logical versus physical acquisition methods. Students will also examine mobile artifacts such as SMS, call logs, and GPS data, and learn techniques for bypassing screen locks and encryption. The course also covers cloud forensics, IoT data extraction, and mobile malware forensics. |
|
MCY505 |
Mobile and Wireless Security |
This Module Will empower students with the following; Wireless Network Security Threats And Vulnerabilities ; Introduction To Wireless Technologies, Design Factors, Security Threats And Vulnerabilities Present At The Different Protocol Layers, Family Of Security Protocols And Algorithms Used In The Existing Wireless Networks .The module examines the security architecture of wireless networks and mobile computing environments. It covers the theoretical foundations and practical vulnerabilities of Wi-Fi, Bluetooth, and cellular technologies. Indicative content covers WLAN security standards including WPA2, WPA3, and Enterprise modes, as well as threats like Rogue APs and Evil Twin attacks. The curriculum extends to Bluetooth and NFC security, cellular network security (4G/5G), and mobile application security testing based on the OWASP Mobile Security Testing Guide (MSTG), including the management of BYOD policies and MDM solutions. |
|
MCY506 |
Risk Assessment and Security Audit |
This Module Will Cover The Following: –Information Security Risk Assessment Overview- Drivers, Laws And Regulations- Risk Assessment Frame Work – Practical Approach. ; Data Collection ; The Sponsors- The Project Team- Data Collection Mechanisms- Executive Interviews- Document Requests- It Assets Inventories- Profile & Control Survey consolidation. ; Data Analysis ; Compiling Observations- Preparation Of Catalogs- System Risk Computation- Impact Analysis Scheme- Final Risk Score. ; Risk Assessment ; System Risk Analysis- Risk Prioritization- System Specific Risk Treatment- Issue Registers- Methodology- Result- Risk Registers- Post Mortem. ; Security Audit Process ; Pre-Planning Audit- Audit Risk Assessment- Performing Audit- Internal Controls- Audit Evidence- Audit Testing- Audit Finding- Follow-Up Activities |
|
MCY507 |
Malware Analysis |
This Module Will empower students with the following; MALWARE BASICS ; General Aspect Of Computer Infection Program , Non Self Reproducing Malware, How Does Virus Operate?, Virus Nomenclature, Worm Nomenclature, Recent Malware Case Studies ;BASIC ANALYSIS ; Antivirus Scanning, X86 Disassembly. This advanced technical module focuses on dissecting malicious software to understand its behavior and origin using reverse engineering techniques. Indicative content covers both static analysis, utilizing file headers and hashing, and dynamic analysis through sandboxing and process monitoring. Students will gain proficiency in x86/x64 assembly language and the use of disassembly and debugging tools such as IDA Pro, Ghidra, and OllyDbg. The course also explores de-obfuscation and unpacking techniques, preparing students to analyze complex threats like ransomware and rootkits. |
|
MCY508 |
Penetration Testing and Vulnerability Assessment |
This Module Will empower students with the following following: Penetration Testing Phases/Testing Process, Types And Techniques, Blue/Red Teaming, Strategies Of Testing, Non Disclosure Agreement Checklist, Phases Of Hacking, Open-Source/Proprietary Pentest Methodologies ; Information Gathering And Scanning ; Information Gathering Methodologies. The module simulates the mindset and techniques of an attacker to identify weaknesses in systems before they can be exploited. Indicative content follows standard penetration testing methodologies (PTES), beginning with reconnaissance and OSINT, moving through network vulnerability scanning, and addressing web application vulnerabilities such as SQLi and XSS (OWASP Top 10). Students will utilize exploitation frameworks like Metasploit and learn techniques for privilege escalation and pivoting, culminating in the professional reporting of findings. |
|
MCY560 |
Dissertation |
The dissertation is a substantial piece of independent research that allows students to demonstrate their mastery of a specific area within cybersecurity. Indicative content involves advanced research methods and ethics, requiring students to conduct a thorough literature review and critical analysis. Students will be responsible for experiment design, data collection, and academic writing. The process concludes with the production of a formal thesis and a defense presentation, demonstrating the student's ability to contribute new insights to the field.. The research finding are expected to be published in peer reviewed journals or conference proceedings |



