CS155 Computer and Network Security

Course Syllabus

Spring 2023

 
Lecture 1:
Mon 4/ 3/23
(DB)
Course overview   [pdfpptx]
Readings:

Part 1: System Security
 
Lecture 2:
Wed 4/ 5/23
(DB)
Control hijacking attacks: exploits   [pdfpptx]
Readings:
 
Lecture 3:
Mon 4/10/23
(DB)
Control hijacking attacks: defenses   [pdfpptx]
Readings:
 
Lecture 4:
Wed 4/12/23
(ZD)
Principle of least privilege, access control, and operating systems security   [pdfkey]
Readings:
 
Lecture 5:
Mon 4/17/23
(DB)
Isolation and sandboxing   [pdfpptx]
Readings:
 
Lecture 6:
Wed 4/19/23
(inv)
Testing for Vulnerabilities: guest speaker (Ned Williamson, Google)   [pdf]
Readings:

Part 2: Web Security
 
Lecture 7:
Mon 4/24/23
(ZD)
Web Security Model   [pdfkey]
Readings:
 
Lecture 8:
Wed 4/26/23
(ZD)
Web Attacks   [pdfkey]
Readings:
 
Lecture 9:
Mon 5/ 1/23
(ZD)
Web Defenses   [pdfkey]
Readings:
 
Lecture 10:
Wed 5/ 3/23
(DB)
Brief overview of cryptography   [pdfpptx]
Readings:
  • The BREACH attack: encryption and compression don't mix, by Gluck, Harris, and Prado
 
Lecture 11:
Mon 5/ 8/23
(DB)
HTTPS: goals and pitfalls   [pdfpptx]
Readings:
 
Lecture 12:
Wed 5/10/23
(DB)
Processor and microarchitecture security: Intel SGX and the Spectre attack   [pdfpptx]
Readings:

Part 3: Mobile Security
 
Lecture 13:
Mon 5/15/23
(DB)
Android and iOS: mobile platform security architecture   [pdfkey]
Readings:
 
Lecture 14:
Wed 5/17/23
(inv)
Topics in Android security: guest speaker (Chris Steipp, Meta)   [pdf]
Readings:

Part 4: Network Security and Privacy
 
Lecture 15:
Mon 5/22/23
(ZD)
Internet Protocols   [pdfkey]
Readings:
 
Lecture 16:
Wed 5/24/23
(ZD)
Internet Security   [pdfkey]
Readings:
 
Holiday:   
Mon 5/29/23
Memorial Day — No Lecture
 
Lecture 17:
Wed 5/31/23
(ZD)
DoS Attacks and Network Defenses   [pdfkey]
Readings:
 
Lecture 18:
Mon 6/ 5/23
(ZD)
Privacy, Anonymity, and Censorship   [pdfkey]
Readings:
 
Lecture 19:
Wed 6/ 7/23
(inv)
Final invited lecture: Niels Provos, Head of Security at Lacework