Internal research assignment · Issued 28 September 2026 · Project Aegis · Confidential
HookB Internship Research Assignment · Cybersecurity & AWS

Project Aegis

Project Aegis — R&D security research assignment

Research and design a reusable AWS security and controlled-access architecture for unreleased documentation, prototypes, test pages and beta applications.

StagiaireChantal Nicasia
Prepared byHookB SMB Solutions
Research areaAWS Security & Access Control

Internal R&D assignment
Research environment: intern.okib.app/project-aegis
Project Aegis is a fictional project name used to anonymise the underlying unreleased R&D use case.

1. Context

A. Assignment context

HookB develops several software ideas, prototypes and beta products simultaneously. During R&D, these resources may contain unreleased concepts, documentation, test interfaces and technical information.

Core rule: Unreleased does not mean unlisted. Unreleased means access-controlled. Knowing or receiving a URL must not automatically provide permanent access.

For this assignment, the fictional internal R&D solution is called Project Aegis. Your task is to research and propose how HookB can protect Aegis and later reuse the same architecture for other projects.

B. More context — what are we trying to protect?

You do not need to know AWS before starting this assignment. The purpose is to learn the relevant AWS building blocks, understand what each one does, and then decide how they could work together.

Imagine HookB is developing several unreleased products at the same time. For each product there may be documentation, an HTML prototype, a beta application, screenshots, test data and internal notes. Today it is easy to upload an HTML page to S3 and share a CloudFront link. The problem is that anyone who receives that link may be able to forward it to somebody else.

We need a reusable protection layer. A known team member might sign in and retain access until we revoke it. A temporary tester might instead receive a one-time invitation that can only be redeemed once and expires if unused. After redemption, the tester should receive a temporary session so the website works normally for a limited period. When that session expires, access must stop. Simply knowing the URL must never be enough.

Your research should therefore answer three beginner-level questions first: Who is the visitor? (authentication), what is that visitor allowed to see? (authorization), and how does AWS safely deliver the private files? Only after understanding those three questions should you design the complete flow.

Start with these AWS resources

Do not assume every service above belongs in the final solution. Part of the assignment is determining which services are necessary, which overlap, and what the simplest secure first version should be.

2. Proposed content structure

The project may contain different protected areas:

protected/project-aegis/ ├── docs/ ├── prototype/ └── beta/

Important: the folder name protected is only an organizational convention. It is not itself a security control.

3. Required access models

Persistent access

Authenticated users

Known team members or recurring testers authenticate using Amazon Cognito or another justified AWS mechanism. Permissions should determine which project and which areas they may access.

Temporary access

Temporary testers

A tester without a permanent account receives a single-use invitation/code. The invitation expires, becomes unusable after successful redemption, and creates only a short-lived authorized session.

Example authorization: User A may access docs and prototype, but not beta. User B may access only beta. A forwarded URL should not bypass these permissions.

4. Research questions

1

Amazon Cognito

What does Cognito provide for authentication, users, sessions, MFA/OTP and tokens? What does it not provide for our proposed single-use invitation workflow?

Research notes…
2

S3 vs CloudFront

Why should the S3 content remain private? Compare direct S3 presigned URLs with serving a protected website through CloudFront.

Research notes…
3

One-time invitations

Design a method for generating, storing, validating, redeeming and revoking one-time invitation codes. Consider Lambda and DynamoDB. Should codes be stored as plaintext or hashes?

Research notes…
4

Temporary sessions

After a code is redeemed, how should a tester receive access for 15 minutes, 1 hour, 24 hours or another configured period without entering a code for every HTML, CSS, JS or image request?

Research notes…
5

Authorization

How can the system enforce project-level and area-level permissions such as Aegis/docs versus Aegis/beta?

Research notes…
6

Audit & revocation

What should be logged? How can HookB revoke a user's access, invalidate an invitation, or terminate future access after a project is closed?

Research notes…

5. Security checklist

Evaluate whether your proposed design satisfies each requirement.

6. Threat scenarios

Explain what your architecture does in each case.

Scenario

Shared link

A tester sends the Aegis beta URL to a friend.

Scenario

Reused invitation

Someone attempts to redeem an already-used access code.

Scenario

Expired access

A tester returns after the temporary session has expired.

Scenario

Direct S3 attempt

Someone discovers the underlying S3 object path.

Scenario

Unauthorized area

A docs-only user manually changes the URL to /beta/.

Scenario

Leaked code

An invitation code is exposed before the intended tester uses it.

7. Required deliverables

8. Design constraint

Do not over-engineer it.
This is an R&D protection system for multiple small projects. Security matters, but the proposed solution should remain practical, low-cost and reusable.

Your recommendation should clearly identify which controls are essential for the first version and which can be introduced later.

9. Final recommendation

At the end of the research, provide your recommended request flow. For example, determine whether the final design should resemble:

Browser ↓ CloudFront ↓ Authentication / Authorization ↓ Private R&D content

Do not simply copy this example. Research whether it is technically correct, identify the AWS components needed, and propose your own final architecture.

10. Completion

Stagiaire

Chantal Nicasia

Date completed: __________________

Review

HookB SMB Solutions

Reviewed: _______________________

Research submission

Complete the required deliverables, prepare your architecture recommendation and submit the research for HookB review.

Project Aegis · Internal R&D Security Research · Stagiaire: Chantal Nicasia
Do not distribute project materials or credentials outside the authorized research scope.