CMSC414: Computer and Network Security

Spring 2015


Home Syllabus Schedule Projects Resources Piazza

Schedule

Date Topic Readings & handouts
Jan 27 Introduction (slides) Required reading:
  • "Reflections On Trusting Trust", Ken Thompson, (pdf)
  • Chapter 1 of [Anderson]

Optional:
  • Example used in class: "Analysis of an Electronic Voting System", Kohno et al. (pdf)
Software Security
Jan 29 Buffer overflow attacks (slides) Required reading:
  • "Smashing the Stack for Fun and Profit", Aleph One (pdf)
Feb 3 Buffer overflow attacks and defenses (slides) Required reading:
  • "StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks" (pdf)
Optional but very useful:
Feb 5 Memory safety: attacks and defenses (slides) Optional reading:
Feb 10 Malware: Viruses (slides) Optional reading:
  • "Hunting for Metamorphic" (pdf)
Feb 12 Virus case studies &
Worms (slides)
Required reading:
  • "How to 0wn the Internet in Your Spare Time" (pdf)
Optional reading:
  • "A History of Computer Viruses - The Famous 'Trio'" (pdf)
Feb 17 Snow day
Feb 19 Virus case studies &
SQL Injection (slides)
Optional reading:
  • "SQL Injection Attacks by Example" (www)
Feb 24 Web security: XSS & CSRF (slides) Required reading:
  • "Web security: Are you part of the problem?" (www)
  • "Cross-Site Request Forgery: An Introduction..." (pdf)
Feb 26 Principles of secure software design (slides) Required reading (defines the design principles in the slides):
  • "Secure Programming for Linux and Unix HOWTO", Chapters 7.1-7.10 (www)
Mar 3 Principles of secure software implementation (slides) Optional reading:
  • vsftpd's design (www)
Mar 5 Snow day
Mar 10 Midterm recap and open problems in software security
Mar 12 Midterm 1
Mar 17 Spring break
Mar 19 Spring break
Cryptography
Mar 24 Midterm recap and
Intro to cryptography
Mar 26 Symmetric key crypto:
Encryption and decryption
Required reading:
Mar 31 Symmetric key crypto:
MACs
(same notes as above)
Apr 2 Symmetric key crypto:
Hash functions and authenticated encryption
(same notes as above)
Apr 7 Power outage
Apr 9 Public key crypto:
Encryption, decryption, and digital sigs
Required reading: Suggested Reading:
  • Twenty Years of Attacks on the RSA Cryptosystem (pdf)
Apr 14 Proving who you are: PKIs
(same notes as above)
Apr 16 Proving who you are: TLS/SSL, certificates (cont'd), user authentication
Required reading:
  • TLS/SSL and certificates slides
  • User authentication notes
Suggested reading:
Apr 21 Midterm recap and open problems in cryptography (slides) Suggested reading:
  • "An Empirical Study of Cryptographic Misuse in Android Applications" (pdf)
  • "Differential Power Analysis" (pdf)
  • "Lest We Remember: Cold Boot Attacks on Encryption Keys" (pdf)
Apr 23 Midterm 2
Network Security
Apr 28 Networking background (slides)
Apr 30 TCP: background and security (slides) Optional reading:
  • Misbehaving TCP Receivers Can Cause Internet-Wide Congestion Collapse (pdf)
May 5 Naming & DNS security (slides) Highly suggested reading:
  • An Illustrated Guide to the Kaminsky DNS Vulnerability (www)
May 7 Anonymity (notes) Optional reading:
  • "The Dining Cryptographers Problem" (pdf)
  • "Untraceable Electronic Mail, Return Addresses, and Digital Pseudonyms" (pdf)
  • "Tor: The Second-Generation Onion Router" (pdf)
May 12 Underground economies & closing (slides) Optional reading:
  • Click Trajectories: End-to-end analysis of the spam value chain (pdf)
  • Show me the money: Characterizing spam-advertised revenue (pdf)

Credit: Some of the slides contain material from other security class offerings, particularly Mike Hicks' and Vern Paxson's. I highly recommend checking out their courses, as well.

Web Accessibility