CMSC414: Computer and Network SecuritySpring 2014, Section 0201 |
| Home | Syllabus | Schedule | Projects | Resources | Piazza |
| Date | Topic | Readings & handouts |
|---|---|---|
| Jan 28 | Introduction | Required reading:
Optional:
|
| Software Security | ||
| Jan 30 | Buffer overflow attacks |
|
| Feb 4 | Buffer overflow attacks cont'd |
|
| Feb 6 | Memory safety defenses | Required reading:
|
| Feb 11 | Malware | Optional reading: |
| Feb 13 | Snow day | |
| Feb 18 | Virus case studies & SQL Injection | Optional reading:
|
| Feb 20 | Web security (XSS, CSRF) | Required reading: |
| Feb 25 | Principles of secure software development | Required reading:
|
| Feb 27 | Open questions in software security | |
| Mar 4 | Midterm | |
| Cryptography | ||
| Mar 6 | Midterm recap & Intro to cryptography | |
| Mar 11 | Symmetric key crypto: Concepts and Encryption | |
| Mar 13 | Symmetric key crypto: Message integrity | |
| Mar 18 | Spring break | |
| Mar 20 | Spring break | |
| Mar 25 | Public key crypto: Encryption and decryption | Suggested Reading:
|
| Mar 27 | Public key crypto: Digital signatures | |
| Apr 1 | Authentication: Public Key Infrastructures | |
| Apr 3 | PKIs (cont'd), challenge/response, and authenticated key exchange | |
| Apr 8 | Authentication: Proving who you are | |
| Apr 10 | Anonymity (And an analysis of the heartbleed bug) | Suggested reading: |
| Apr 15 | Midterm recap & Anonymous communication (cont'd) | Recommended reading:
|
| Apr 17 | Midterm | |
| Apr 22 | Midterm recap & Tor & Crypto pitfalls | Recommended reading:
|
| Network Security | ||
| Apr 24 | Networking background | |
| Apr 29 | Networking background (cont'd) & TCP attacks | |
| May 1 | TCP attacks (cont'd) | Optional reading:
|
| May 6 | Naming & DNS security | Highly suggested reading:
|
| May 8 | Firewalls & VPNs | |
| May 13 | Underground economies & closing. | Optional reading: |