System Security

This course aims at introducing basic concepts and techniques for the development of secure systems. It is

This course is part of the Laurea Magistrale in Computer Science and Information Technology at Ca’ Foscari, Venice. It is a blended course of the Ca’ Foscari e-learning program and combines traditional classroom teaching with online classes, tutoring and challenges.

For students that started before 2022: This course is mapped to [CM0493] Security 1  and [CM0475] Security 1 (6 out of 12 CFU).

IMPORTANT NOTE: In this course you will learn some attack techniques. Remember that trying attacks on real systems is against law and you might be prosecuted. Only do experiments with the test hosts and users provided in the labs.

News

  • Course stars on Wednesday 18 September 2024!

Assessment

  • Written exam giving a base score;
  • Challenges giving bonus on the base score.

Course material and books

All of the slides will be made available online here. The course is mainly based on:

  • William Stallings, Lawrie Brown. Computer Security: Principles and Practice, 4th Edition. Pearson, 2018. (chapters 1, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 22, 27)

online resources

  • The official moodle page contains:
    • recordings of classes (only for eligible students)
    • instruction to join the virtual meeting point for the course in Slack
  • Examples and practical case studies are made available as docker images

Program

  • [18/09/2024] Introduction and basic concepts (slides)
  • [20/09/2024] Security design principles (slides)
  • [25/09/2024] Introduction to cryptography (slides)
  • [27/09/2024] Cryptography lab (online class)
  • [02/10/2024] User Authentication (slides)
  • [04/10/2024] Password cracking lab (online class)
  • [09/10/2024] Access control (slides)
  • [11/10/2024] Unix access control lab (online class)
  • [16/10/2024] Malware 1 (slides)
  • [18/10/2024] Malware 2 (slides)
  • [23/10/2024] Denial of service (slides)
  • [25/10/2024] Database security (slides)
  • [30/10/2024] SQL injection challenge (online class)
  • [06/11/2024] Buffer and stack overflow (slides)
  • [08/11/2024] Buffer overflow challenge (online class)
  • [13/11/2024] Intrusion detection (slides)
  • [15/11/2024] Software security (slides)
  • [20/11/2024] Software security challenge  (online class)
  • [27/11/2024] Operating system security (slides)
  • [29/11/2024] Trusted computing (slides)
  • [04/12/2024] Security APIs (slides)
  • [06/12/2024] Security API challenge (online class)
  • [11/12/2024] Formal methods for security (slides) (examples)
  • [13/12/2024] Formal analysis lab (online class)
  • [TBA] Side-channel (slides)
  • [TBA] Side-channel lab (online class)