CMSC414: Computer and Network Security

Spring 2014, Section 0201


Home Syllabus Schedule Projects Resources Piazza

Schedule

Date Topic Readings & handouts
Jan 28 Introduction Required reading:
  • "Reflections On Trusting Trust", Ken Thompson, (pdf)
  • Chapter 1 of [Anderson]

Optional:
  • Example used in class: "Analysis of an Electronic Voting System", Kohno et al. (pdf)
Software Security
Jan 30 Buffer overflow attacks
  • "Smashing the Stack for Fun and Profit", Aleph One (pdf)
Feb 4 Buffer overflow attacks cont'd
Feb 6 Memory safety defenses Required reading:
  • "StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks" (pdf)
Optional:
  • "Basic Integer Overflows" (phrack)
  • "Exploiting Format String Vulnerabilities" (pdf)
Feb 11 Malware Optional reading:
  • "Hunting for Metamorphic" (pdf)
  • "A History of Computer Viruses---The Famous 'Trio'" (pdf)
Feb 13 Snow day
Feb 18 Virus case studies &
SQL Injection
Optional reading:
  • "SQL Injection Attacks by Example" (www)
Feb 20 Web security (XSS, CSRF) Required reading:
  • "Web security: Are you part of the problem?" (www)
  • "Cross-Site Request Forgery: An Introduction..." (pdf)
Feb 25 Principles of secure software development Required reading:
  • "Secure Programming for Linux and Unix HOWTO", Chapters 7.1-7.10 (www)
Feb 27 Open questions in software security
Mar 4 Midterm
Cryptography
Mar 6 Midterm recap
& Intro to cryptography
Mar 11 Symmetric key crypto:
Concepts and Encryption
Mar 13 Symmetric key crypto:
Message integrity
Mar 18 Spring break
Mar 20 Spring break
Mar 25 Public key crypto:
Encryption and decryption
Suggested Reading:
  • Twenty Years of Attacks on the RSA Cryptosystem (pdf)
Mar 27 Public key crypto:
Digital signatures
Apr 1 Authentication:
Public Key Infrastructures
Apr 3 PKIs (cont'd), challenge/response, and
authenticated key exchange
Apr 8 Authentication:
Proving who you are
Apr 10 Anonymity
(And an analysis of the heartbleed bug)
Suggested reading:
  • "The Dining Cryptographers Problem" (pdf)
  • "Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms" (pdf)
  • Diagnosis of the OpenSSL Heartbleed Bug (www)
Apr 15 Midterm recap &
Anonymous communication (cont'd)
Recommended reading:
  • Tor: The Second-Generation Onion Router (pdf)
Apr 17 Midterm
Apr 22 Midterm recap &
Tor & Crypto pitfalls
Recommended reading:
  • An Empirical Study of Cryptographic Misues in Android Applications (pdf)
Network Security
Apr 24 Networking background
Apr 29 Networking background (cont'd)
& TCP attacks
May 1 TCP attacks (cont'd) Optional reading:
  • Misbehaving TCP Receivers Can Cause Internet-Wide Congestion Collapse (pdf)
May 6 Naming & DNS security Highly suggested reading:
  • An Illustrated Guide to the Kaminsky DNS Vulnerability (www)
May 8 Firewalls & VPNs
May 13 Underground economies & closing. Optional reading:
  • Click Trajectories: End-to-end analysis of the spam value chain (pdf)
  • Show me the money: Characterizing spam-advertised revenue (pdf)

Web Accessibility