CIS 4360 - Introduction to Computer Security - Fall 2008

 

Textbook

Computer Security by Gollmann, John Wiley, 2nd Edition, 2006.

Notes will be used additionally.

 

Schedule

Questions and interactions with students are welcome. This schedule is tentative.

 

 

Tentative Schedule

Class

Topic

Material

1

Introduction

Introduction:  What is Computer Security.  LINK

2

Introduction

Introduction: Confidentiality, Integrity, Availability  LINK

3

Introduction

Introduction: Design principles for Computer Security  LINK

4

Introduction

Introduction: Computer Criminals  LINK

5

Protection in general purpose Operating Systems

Entity Authentication  LINK

6

Access Controls

Usernames/Passwords, attacks  LINK

7

Access Controls

Cryptographic protection, one-way functions  LINK

8

Cryptography: an introduction

Encryption, Kerchoffs law,  Symmetric key encryption, stream ciphers & block ciphers LINK

9

Cryptography: an introduction

DES, modes of operation,  AES    LINK

10

Cryptography: an introduction

Public Key Cryptosystems: DH, RSA and ElGamal  LINK

11

Cryptography: an introduction

Public Key Cryptosystems: Digital Signatures, RSA, ElGamal and DSS   LINK

12

Access Control

Access Control   LINK

13

Access Control

Access Control   LINK

14

Access Control

Access Control   LINK

15

Security Models

State Machine models, The Bell-LaPadula model   LINK

16

Security Models

The Harrison-Ruzzo-Ullman model, The Chinese Wall model   LINK

17

Security Models

The Biba model, The Clark Wilson model   LINK

18

Security Models

The Information Flow model   LINK

19

The Security Kernel

Rational, Operating system, Integrity   LINK

20

The Security Kernel

Hardware security features, Reference Monitor   LINK

21

Distributed Systems

Introduction, Authentication, Kerberos   LINK

22

Distributed Systems

Kerberos, Security APIs  LINK

23

Distributed Systems

CORBA Security  LINK

24

WWW Security

Background, Browsers, CGI Scripts, Cookies  LINK

25

WWW Security

Certified code, the Sandbox, Intellectual Property Protection  LINK

26

Cryptography

Introduction, Cryptographic Mechanisms, Key establishment protocols  LINK

27

Cryptography

Certificates, strength of mechanisms  LINK

28

Network Security

Introduction TCP/IP Security  LINK

29

Network Security

Network boundaries, Firewalls  LINK

30

Legal and Ethical issues

Legal and Ethical issues  LINK

 

Final Exam

Monday, December 7, 7:30 - 9:30AM.   

 

 


 

Last edited by Mike Burmester, August 17, 2009