Year 2 Summer Prep

UFCE8A-30-3 — Cyber Security Project

This page supports the Year 2 Summer Prep session for the UFCE8A-30-3 Cyber Security Project module. Over the summer, you should think carefully about the project you would like to pursue in your final year and complete a project proposal using the form below, ready for the start of the next academic year.

Essential Resources

Lecture Slides

Lecture Recording

Project Proposal Form

Download the proposal form, rename it to include your name, and complete it over the summer.

Past Projects & Examples

The UWE Library hosts previous dissertations that achieved a first-class mark. As this is the third run of UFCE8A, there are limited past projects for this module — so also review IS Dissertation and Digital Systems Project papers from the BSc Cyber Security and Digital Forensics, BSc Cyber Security Technical Professional, and BSc Computer Science programmes. These have similar requirements and will give you a good insight into what is expected at distinction level.

You will not find a project that covers exactly your topic, but there is a lot to be gained from reading prior work across disciplines — how it is structured, how literature is used, and how findings are analysed and reflected upon.

Note: assess these projects critically. Some were written against different assessment briefs and may not align with the criteria for this module. The assessment criteria has changed for this run, so even past projects from this module should be treated critically.

Dissertation Projects

  • Challenging the Suitability of Email for Sensitive Communication in UK Healthcare: A Cybersecurity and Governance Critique
  • Transformer-Based Audio Deepfake Detection for Scam Related Social Engineering
  • The Challenges and Effects of Generative AI in the Creation and Dissemination of Child Sexual Abuse Material (CSAM): Legal, Ethical and Forensic Perspectives
  • Weaponised Intelligence: The Offensive Use of AI in Modern Cyber Conflict
  • Disinformation Patterns Across Regional Conflicts: A Forensic OSINT Analysis
  • How is English-language online discourse shaped in response to AI-generated disinformation during the Russia–Ukraine conflict?
  • Privacy Leakage on Social Media Platforms: Measuring Risks, Detecting Exposed Identity Data and Designing User-Centric Mitigations
  • Emotional and Mental Impacts of Online Fraud Victimisation on Individuals in England
  • Threat-Modelling a Modern Cambridge Analytica: How a Private Influence Firm Could Exploit Synthetic Media Under Current UK/EU Regulation
  • A Comparative analysis of Cyber Security Frameworks: A literature based evaluation of modern cyber threats
  • The State of Cloud Forensics in UK Court: Could it be improved?
  • “Humans are the Weakest Link”: Examining the Shortcomings of Security Awareness Training and Relevant Frameworks
  • Into the mind of a Hacker: A Proposed Framework on how to psychologically profile a hacker
  • Cross-Border Cybercrime and Human Trafficking: A Critical Evaluation of International Legal Frameworks
  • Russian Disinformation Campaigns and Methods in Social Media
  • The usage and efficiency of Digital Forensics in the Automotive Industry
  • Can AI Be Trusted? A Study on the Accuracy of AI-Driven Vulnerability Recommendations
  • Shared Networks: The Balance Between Cyber Security and Creative Collaboration
  • The AI Revolution in Cybersecurity: Defending Against Emerging Threats
  • The Effects of Vulnerability Management on both Defensive and Offensive security
  • Cybercrime and the Psychology Behind It
  • Internet of Things: How IoT impact law enforcement and the public
  • Is Ethical Artificial Intelligence Possible? A Study into the Ethical Implications of Artificial Intelligence in Cybersecurity
  • Strengthening Cyber Security: A Critical Review of Zero-Day Defences
  • Domestic Abuse in the Digital Age
  • Ransomware Trends and Prevention
  • The (Accidental) Threat from Within: An Exploration into the Unintentional Insider Threat
  • The Impacts and Challenges of Drone Utilization within UK Law Enforcement
  • The Impact of Quantum Computing on Cryptography, AI, and Medical Applications

Applied Projects

  • DigiTriage: A Digital Forensic Triage Tool for Frontline Police Officers
  • OPC UA Command and Control Server
  • Synthetic Influence: A Forensic Workflow for Detecting Political Deepfakes
  • An automated cyber threat dashboard powered by AI threat analysis
  • DataHawk: A forensic tool for extracting, analysing, and reporting data from mobile device databases
  • Implementing and evaluating zero-trust principles in dynamic networks
  • Hidden in Plain Sight: Developing a Lightweight USB Behaviour Monitoring Tool for Threat Detection
  • A Critical Study of Misconfiguration-Driven Security and Forensic Risks in Web-Based POS Deployments for SMEs
  • Self-Healing IoT Mesh Network: Automated Quarantine, Secure Rerouting, and Tamper-Evident Logging
  • Cloud Forensics Challenges and Readiness Framework for Qatari Enterprises
  • AutoForensicReport: A Hybrid Prototype for Generating Court-Accessible Digital Forensic Reports from Examiner Notes for UK Proceedings
  • Bridging the Cyber Security Skills Gap Through Practical Evaluation of Multi-Factor Authentication
  • AntiStalker: A Behavioural Detection Framework for Android Stalkerware to Mitigate Digital Intimate Partner Violence
  • Securing Insecure Implementation of Containerisation
  • Exploitation of mobile devices for purposes of digital forensics
  • Xtreme Forensics — A Critical Digital Forensic Analysis and Procedural Framework for the Flipper Zero
  • Self-Adaptive Containers with Automated Containment and Rollback Mechanisms
  • OSSISTANT: Automating, Assisting and Evidencing OSINT Tasks to Streamline Criminal and Missing Person Investigations
  • Wingman: A LightGBM-Powered Browser Extension for Real-Time Phishing Detection Without Third-Party Dependencies
  • Automotive sECUrity — Hybrid IDS for the Controller Area Network
  • Agentic workflow for Phishing detection
  • Enhancing Security in Over-The-Air Updates: Challenges, Cryptography, and Solutions
  • Vulnerability Reporting: Helping a Business to Understand Their Vulnerability Health Within the Cloud
  • Creation of an Information Asset Register Compliant with ISO 27001 Standard
  • Exploring Moving Target Defence in Automotive Systems Through Dynamic CAN ID Obfuscation
  • Too Sweet to Be True: Adversarial Strategies for Honeypot Detection
  • Securing Communications in Safety Critical Operational Technology
  • Securing the Remote Working Environment Utilising Embedded Systems
  • Creating a Securely Interconnected Campus Network for the College
  • Automating Security Testing in DevOps: A Configurable Script Generation Tool
  • Linux Shell — Parse and interpreted
  • System Hardening — Helping SMEs Improve Their Security
  • A penetration testing onboarding tool
  • Windows operating system automatic diagnosis and hardening tool
  • Cyber Learning in the workplace for non-technical professionals
  • RFID clone detection for high security facilities using two-factor authentication with mobile devices
  • VeNuS — A Network, Vulnerability and Solution Scanning System
  • Sentiment analysis on messages to determine harmful messages
  • Crime Tide — AI-based crime prediction
  • Monitoring of High-Level Events in a Microservices Architecture
  • Configurable Malware Analysis Environment
  • Portable CTF Challenges
  • Offline password cracker
  • Network defender (scan and visually map network; assists with diagnosis, debugging and fixing)
  • Research and analysis of social media data in real-time
  • Visualising and contextualising Bitcoin transactions on the blockchain
  • A blockchain-based Peer-to-Peer file storage application

Mini-Examples of First-Class Work

Recent first-class projects have included comparative systems evaluation, build-and-test software development, and empirical security studies. These examples illustrate common forms of excellent work; they do not limit what you may propose.

Systems evaluation in a safety-critical context (industrial control systems)

An engineering-led appraisal compared secure communication options for nuclear ICS, using requirements derived from standards, a weighted decision method, and a lab testbed to verify latency, protocol compatibility, and cyber-resilience. The work justified a specific hardware encryption appliance through functional, non-functional, and security testing, with limitations and deployment implications made explicit.

How to apply this model: frame a real operational need; derive verifiable requirements; compare credible candidates; build a representative environment; report evidence-based trade-offs; state what is and is not validated.

Software development with experimental security evaluation (automotive CPS)

A prototype implemented Moving Target Defence by dynamically obfuscating CAN identifiers with time-dependent cryptography in a simulated multi-ECU environment. The study balanced security benefits against latency and resource overheads, and validated resistance to spoofing, replay, and flooding attacks with reproducible tests.

How to apply this model: design and implement a novel mechanism; define functional and non-functional requirements; build a controllable simulation; create adversarial test cases; measure performance and security impacts rigorously.

Empirical study of adversary techniques (honeypot detection)

A 14-day deployment of a DShield honeypot captured real interactions and then systematically tested literature-derived detection methods. The analysis identified practical “wear and tear” artefacts and signature behaviours, producing actionable recommendations for more convincing decoys.

How to apply this model: ground the question in current practice; collect real-world data ethically; build a transparent test ontology; evaluate existing techniques; contribute refined detection or evasion artefacts and guidance.

Thematic Topics

Timely, important areas to spark your own project — not a fixed list of titles.

These thematic topics are designed to raise your awareness of timely and important cyber security issues. You are expected to develop your own project, narrow down the questions, and choose either a dissertation-style or an applied route, depending on your interests, your evidence base, and your technical confidence. Read the ethics-scoping guidance below alongside these — each topic carries an ethics note so you can shape a viable project from the outset.

1. Technology-facilitated gender-based violence

Route: dissertation-style only.

An increasingly important privacy, safety, and digital-harms issue. A central concern is the use of AI-generated or manipulated imagery — including deepfake sexual imagery — for harassment, coercion, reputational harm, blackmail, stalking, and domestic abuse, affecting private individuals as well as public figures.

  • Regulation and platform governance of deepfake sexual abuse — critically compare national, international, and platform responses; identify gaps in prevention, reporting, removal, accountability, and victim protection. Contribution: a policy analysis, original framework, or critical argument.
  • Victim-centred response to deepfake abuse — examine how such abuse is enabled, reported, removed, investigated, and prevented, and propose a framework for reporting, evidence preservation, platform removal, and victim support. Contribution: a response framework or awareness-raising artefacts.

Ethics note: dissertation-style only because it must be desk-based. Work entirely from published law, policy, platform documentation, and charity/NGO and academic sources. Do not involve survivors or affected individuals, and never create or handle actual abusive or sexual imagery.

Career paths (UK Cyber Security Council): data protection & privacy; digital forensics.

2. Climate change misinformation and disinformation

Route: dissertation-style or applied.

An information-integrity, public-trust, and societal-resilience issue. The cyber security concern is less whether a claim is true or false, and more how platforms, AI tools, recommender systems, bots, and coordinated campaigns amplify misleading narratives and undermine trust in climate science, policy, and institutions.

  • Governance and mitigation of climate disinformation — investigate how misleading narratives are amplified, and how governments, platforms, media, scientists, and civil society detect, report, and govern these risks. Contribution: an information-integrity framework or awareness artefacts.
  • Detection of climate misinformation narratives — develop or evaluate a detection method, comparing keyword-based, machine-learning, or LLM-assisted classification. Contribution: a prototype classifier or fact-checking dashboard.

Ethics note: use existing, ethically sourced, openly licensed datasets; analyse narratives and content, not identifiable users; and never run a study that exposes real people to misinformation.

Career paths (UK Cyber Security Council): cyber security governance & risk management; digital forensics.

3. Supply-chain risks and cascading risks of digital system failure

Route: dissertation-style or applied.

Modern society depends on critical digital infrastructure — power grids, telecoms, cloud services, data centres, satellites, payment systems. When one system, software dependency, or service fails, the impact can cascade across sectors and borders. This topic concerns software supply-chain risk, secure development, incident response, and system recovery.

  • Cascading digital failure and critical-infrastructure resilience — examine how failures in one domain (power, cloud, telecoms, satellites, submarine cables) cascade into others; analyse hidden dependencies, weak points, and governance gaps. Contribution: a dependency map, risk taxonomy, or resilience framework.
  • Scenario-based assessment of digital infrastructure failure — model a major disruption (data-centre outage in a heatwave, cable failure, GNSS disruption, cloud outage); examine impacts, stakeholders, and recovery gaps. Contribution: a scenario model, tabletop exercise, or response playbook.

Ethics note: mostly analytical and technical, and therefore low-risk — document analysis, dependency modelling, tabletop exercises, and testbeds you control. If you consult experts, treat it as low-risk professional interviews and complete the checklist. Do not probe real third-party or production systems.

Career paths (UK Cyber Security Council): governance & risk management; incident response; secure system architecture & design; audit & assurance.

Scoping Your Project to Stay Ethics-Light

Design the ethics in from the start — it shapes what project is realistic.

You can produce distinction-level work without a heavy ethics process. Before you settle on a project, think about how you will get your evidence: the fastest and safest route is a design that does not require recruiting people or handling personal data. This section explains how to keep your project within a light-touch ethical review — and the lines you must not cross. Settle this at proposal stage, complete the Pre-Ethics Review Checklist early, and discuss it with your supervisor before you collect any data.

The light-touch path: design out human participants

Most excellent projects on this module need no human participants at all. Strong evidence can come from:

  • Secondary and public sources — published research, legal and policy texts, regulator and platform documentation, court rulings, standards, NGO and charity reports.
  • System building and lab evaluation — prototypes, tools, testbeds, simulations, and adversarial testing against systems you own or control.
  • Document, policy, and framework analysis — comparing, critiquing, and synthesising existing work into something new.
  • Openly licensed datasets — established, ethically sourced datasets, used in line with their licence and terms.

If your project involves no human participants, you answer “No” to the human-participants question on the Pre-Ethics Review Checklist and no further checks apply. This is the smoothest path through the process.

If you do involve people, keep it low-risk

Some projects benefit from limited input from people — for example, a few interviews with professionals about their expert practice. This is allowed, but it still requires ethical approval from your supervisor before you collect any data, and you must keep it genuinely low-risk:

  • Competent adults only — no under-18s.
  • No vulnerable groups — e.g. victims or survivors, patients, or anyone who cannot freely give informed consent.
  • Voluntary informed consent, a clear right to withdraw, confidentiality, and secure handling and disposal of data.
  • Non-sensitive questions only — professional opinion, not personal experiences of harm.

Before your supervisor can sign this off, you will need to prepare and complete all of the following. These are pre-requisites for ethical approval from projects involving human participants:

  • A Participant Information Sheet — explaining the study, its purpose, what participants will do, how data will be used, their rights, and how to withdraw.
  • A Consent Form — signed by each participant, confirming informed, voluntary consent.
  • A Data Management Plan — explaining how you will collect, store, handle, and securely dispose of participant data.
  • A copy of your intended interview or survey questions (the full list).
  • Evidence that you will use UWE-approved tools for data collection and storage — check with your supervisor which tools are approved.
  • Possibly a risk assessment document, depending on the sensitivity of your topic.

Submit all this documentation to your supervisor after completing the checklist and initial discussions with your supervisor. Only after review can your supervisor determine whether your project qualifies as low-risk and sign off on ethical approval. You must not collect any data until you have written supervisor approval.

Important: Conducting research without ethical approval from your supervisor or breaching University ethical guidelines is an academic misconduct matter and will result in a referral.

Lines you must not cross

The following will not receive ethical approval on this module — do not design a project around them:

  • Deception research. Do not mislead people, observe them covertly, or run phishing or social-engineering exercises on people who have not consented. Do not post or amplify misinformation or manipulated content to see how people react.
  • Personal or special-category data. Do not collect, scrape, or store data that identifies real individuals. Health data — along with data on ethnicity, religion, politics, sexuality, or sex life — is “special-category” data under UK GDPR and is off-limits at this level. Use synthetic, anonymised, or openly licensed data, and check the licence and terms of service of any source first.
  • Harmful or illegal material. Never create, collect, or handle illegal or abusive content (including sexual deepfakes or intimate-image abuse material), and never test attacks against systems or infrastructure you do not own or have written permission to test.
  • Unflagged security-sensitive work. Topics touching terrorism or extremism, or tools that could be misused, may be classed as security-sensitive and require full approval. If your idea is near this line, raise it with your supervisor early.

How this applies to the thematic topics

  • Technology-facilitated gender-based violence — dissertation-style route only. Work entirely from published evidence: law, policy, platform documentation, charity and NGO reports, and academic literature. Do not involve survivors or affected individuals, and never create or handle actual abusive or sexual imagery.
  • Climate mis/disinformation — for detection work, use existing, ethically sourced, openly licensed datasets; analyse narratives and content, not identifiable users; and never run a study that exposes real people to misinformation.
  • Supply-chain and cascading digital failure — mostly analytical and technical, and therefore low-risk: document analysis, dependency modelling, tabletop exercises, and testbeds you control. If you consult experts, treat it as low-risk professional interviews and complete the checklist. Do not probe real third-party or production systems.

A good rule of thumb: if your idea seems to need people or personal data, ask whether the same research question could be answered from public evidence or a system you build and test. It usually can — and that is almost always the stronger project.