19 FYP Ideas for Cyber Security Students (2026)

Ezitech profile photo

Ezitech

Careers & Internships article by Ezitech — 70 FYP Ideas for Computer Science Students (2026)

The best FYP ideas for cyber security students build something that defends, detects or proves: a monitoring system, a scanner, a secure login or a forensics tool, all tested in your own lab. Below are 19 cyber security project ideas for BS Cyber Security and BSCS students, each with a tech stack and a difficulty level.

For ideas in other fields, see our 70 FYP ideas for CS students or try the FYP idea generator.

Jump to: Stay legal · Detection and defence · Web and app security · Identity and cryptography · Network, IoT and forensics · What scores well · FAQ

Only test systems you own or have written permission to test. In Pakistan, the Prevention of Electronic Crimes Act 2016 (PECA) makes unauthorised access to an information system an offence, and doing it for a university project does not change that. Build your own lab and attack that. Everything in the table below is free:

Tool What it is for in your lab
VirtualBox Running several virtual machines on one laptop
Kali Linux The attack and testing tools
Metasploitable, DVWA, OWASP Juice Shop Deliberately vulnerable targets to practise on
Wazuh or Security Onion Monitoring and alerting for the defence side
Wireshark and Zeek Capturing and analysing network traffic

Defensive projects also tend to be easier to defend in a viva: you can show an attack happening in your lab and your system catching it.

Detection and defence FYP ideas

# Idea What it does Tech stack Difficulty
1 SIEM-lite for small offices Collects Windows and Linux logs in one place and alerts on brute-force logins, new admin accounts and disabled antivirus Wazuh or the ELK stack, Python Hard
2 Honeypot network with an attack dashboard Runs low-interaction honeypots on a cloud VM and shows where attacks come from and which commands attackers try Cowrie, Docker, Grafana Medium
3 Ransomware early-warning agent Watches for sudden mass file renames and high-entropy writes, and stops the process before many files are encrypted Python, Windows file system events Hard
4 Malicious document analyser Scores PDF and Office files for malicious macros, embedded scripts and suspicious links before anyone opens them Python, oletools, pdfid, scikit-learn Medium
5 DNS tunnelling detector Spots data being smuggled out through DNS queries by looking at query length, randomness and frequency Zeek, Python, scikit-learn Hard
6 Login anomaly detector for a university portal Flags logins from unusual locations, devices or times and asks for an extra verification step Node.js or Laravel, Redis, a simple ML model Medium

Web and application security FYP ideas

Most real breaches in small businesses start with a weak web app. These projects find the problems before attackers do.

# Idea What it does Tech stack Difficulty
7 Secure code scanner for PHP and Laravel Finds SQL injection, XSS and weak authentication patterns that are common in student and small-business PHP code Python, Semgrep rules, PHP parser Medium
8 Android app privacy auditor Decompiles an APK and reports dangerous permissions, embedded trackers and hard-coded keys jadx, Androguard, Python Medium
9 Lookalike domain monitor Generates lookalike versions of a brand’s domain, checks which ones are registered and alerts the brand owner Python, dnstwist, WHOIS and DNS lookups Easy
10 API security tester Tests your own APIs against the OWASP API Security Top 10, such as broken object-level authorisation Python, OpenAPI, OWASP ZAP Medium
11 Secrets leak scanner with rotation guide Finds API keys and passwords committed to Git repositories and walks the owner through rotating them Python, Gitleaks, GitHub API Easy

Identity, cryptography and privacy FYP ideas

# Idea What it does Tech stack Difficulty
12 Passwordless login with passkeys Replaces passwords on a sample university portal with passkeys and measures what attacks it stops WebAuthn, Node.js, React Medium
13 Verifiable e-voting for student elections Lets students vote in secret while anyone can check that every vote was counted correctly Node.js, homomorphic encryption or mix-nets, React Hard
14 Encrypted file sharing with expiring links Encrypts files in the browser before upload, so the server never sees the content, and links expire after a set time Web Crypto API, Node.js, S3-compatible storage Medium
15 Steganography detector Detects data hidden inside images shared over email or social media Python, statistical steganalysis, CNN Medium

Network, IoT and forensics FYP ideas

# Idea What it does Tech stack Difficulty
16 Home router and camera security checker Scans devices on your own network for default passwords, open ports and outdated firmware Python, Nmap, CVE data Medium
17 Rogue Wi-Fi access point detector Detects fake access points that copy the campus Wi-Fi name to steal logins Python, Scapy, a Wi-Fi adapter with monitor mode Medium
18 Cyber range for students Docker-based vulnerable labs with automatic scoring, so a department can run its own CTF practice Docker, CTFd, Python Medium
19 Digital forensics timeline builder Turns browser history, event logs and file timestamps from a disk image into one searchable timeline Python, The Sleuth Kit, Elasticsearch Hard

Related: Cybersecurity career in Pakistan · AI agent security risks

What makes a cyber security FYP score well

  1. A threat model. Who is the attacker, what do they want and what can they already do? Every feature should answer a threat on this list.
  2. A lab anyone can rebuild. Document your virtual machines, network layout and versions so an examiner could repeat your tests.
  3. Measured results. Detection rate, false positives and time to detect, from attacks you ran in the lab.
  4. Responsible handling. No real users’ data in your tests, and if you find a real vulnerability, report it privately to the owner.
  5. A live demo. Run an attack during the defence and show your system catching or blocking it.

Our guides on the FYP proposal, FYP documentation and viva questions help with the write-up.

Frequently asked questions

What are good FYP ideas for cyber security students?

Strong cyber security FYPs build a defence or a detection tool and prove it works in a lab, for example a SIEM for small offices, a honeypot network, a malicious document analyser or passwordless login with passkeys. Defensive projects are easier to demo and safer to build.

Is it legal to use hacking tools for my FYP?

The tools themselves are legal, but using them against a system without permission is not. Pakistan’s Prevention of Electronic Crimes Act 2016 makes unauthorised access an offence, so test only in your own lab or on systems whose owner has given written permission.

Do I need a cloud server for a cyber security FYP?

Usually not. Most projects run on a laptop with VirtualBox and a few virtual machines. A small cloud server is useful for projects like honeypots that need real internet traffic.

Can I combine AI and cyber security in my FYP?

Yes. A malicious document analyser, a DNS tunnelling detector or a login anomaly detector all use machine learning. Report the false positive rate as well as accuracy, because a tool that raises too many false alarms is ignored in practice.

What should a cyber security FYP report include?

A threat model, the lab architecture, the attacks you tested, measured results such as detection and false positive rates, the limitations of your system and a short section on ethics and legal limits.

Turn the idea into a finished project

Security projects still need a working app around them: dashboards, logins and a database. How Ezitech can help:

FYP ideas by degree: Software engineering · AI · Cyber security · IT · Computer science (70 ideas)

More FYP help: FYP idea generator · FYP proposal format · FYP documentation · FYP viva questions

Leave a Reply