CS155 Computer and Network Security

Course Syllabus

Spring 2025

 
Lecture 1:
Mon 3/31/25
(DB)
Course overview   [pdfpptx]
Readings:

Part 1: System Security
 
Lecture 2:
Wed 4/ 2/25
(DB)
Control hijacking attacks: exploits   [pdfpptx]
Readings:
 
Lecture 3:
Mon 4/ 7/25
(DB)
Control hijacking attacks: defenses   [pdfpptx]
Readings:
 
Lecture 4:
Wed 4/ 9/25
(ZD)
Principle of least privilege, access control, and operating systems security   [pdfkey]
Readings:
 
Lecture 5:
Mon 4/14/25
(DB)
Isolation and sandboxing   [pdfpptx]
Readings:
 
Lecture 6:
Wed 4/16/25
(inv)
Testing for Vulnerabilities: guest speaker (Brandon Azad, Apple)   [pdf]
Readings:
 
Lecture 7:
Mon 4/21/25
(DB)
Processor and microarchitecture security: Intel TDX and the Spectre attack   [pdfpptx]
Readings:

Part 2: Web Security
 
Lecture 8:
Wed 4/23/25
(ZD)
Web Security Model   [pdfkey]
Readings:
 
Lecture 9:
Mon 4/28/25
(ZD)
Web Attacks   [pdfkey]
Readings:
 
Lecture 10:
Wed 4/30/25
(ZD)
Web Defenses   [pdfkey]
Readings:
 
Lecture 11:
Mon 5/ 5/25
(DB)
Brief overview of cryptography   [pdfpptx]
Readings:
  • The BREACH attack: encryption and compression don't mix, by Gluck, Harris, and Prado
 
Lecture 12:
Wed 5/ 7/25
(DB)
HTTPS: goals and pitfalls   [pdfpptx]
Readings:

Part 3: Application security
 
Lecture 13:
Mon 5/12/25
(DB)
Security of machine learning systems
Readings: coming
 
Lecture 14:
Wed 5/14/25
(inv)
Cloud security: guest speaker (Ulfar Erlingsson, Google)
Readings: coming

Part 4: Network Security and Privacy
 
Lecture 15:
Mon 5/19/25
(ZD)
Internet Protocols   [pdfkey]
Readings:
 
Lecture 16:
Wed 5/21/25
(ZD)
Internet Security   [pdfkey]
Readings:
 
Holiday:   
Mon 5/26/25
Memorial Day — No Lecture
 
Lecture 17:
Wed 5/28/25
(ZD)
DoS Attacks and Network Defenses   [pdfkey]
Readings:
 
Lecture 18:
Mon 6/ 2/25
(ZD)
Privacy, Anonymity, and Censorship   [pdfkey]
Readings:

Part 5: Special Topics
 
Lecture 19:
Wed 6/ 4/25
(inv)
Final invited lecture: TBD