CS155 Computer and Network Security

Course Syllabus

Spring 2024

 
Lecture 1:
Mon 4/ 1/24
(DB)
Course overview   [pdfpptx]
Readings:

Part 1: System Security
 
Lecture 2:
Wed 4/ 3/24
(DB)
Control hijacking attacks: exploits   [pdfpptx]
Readings:
 
Lecture 3:
Mon 4/ 8/24
(DB)
Control hijacking attacks: defenses   [pdfpptx]
Readings:
 
Lecture 4:
Wed 4/10/24
(ZD)
Principle of least privilege, access control, and operating systems security   [pdfkey]
Readings:
 
Lecture 5:
Mon 4/15/24
(DB)
Isolation and sandboxing   [pdfpptx]
Readings:
 
Lecture 6:
Wed 4/17/24
(inv)
Testing for Vulnerabilities: guest speaker (Brandon Azad, Apple)   [pdf]
Readings:
 
Lecture 7:
Mon 4/22/24
(DB)
Processor and microarchitecture security: Intel SGX and the Spectre attack   [pdfpptx]
Readings:

Part 2: Web Security
 
Lecture 8:
Wed 4/24/24
(DB)
Web Security Model   [pdfkey]
Readings:
 
Lecture 9:
Mon 4/29/24
(ZD)
Web Attacks   [pdfkey]
Readings:
 
Lecture 10:
Wed 5/ 1/24
(ZD)
Web Defenses   [pdfkey]
Readings:
 
Lecture 11:
Mon 5/ 6/24
(DB)
Brief overview of cryptography   [pdfpptx]
Readings:
  • The BREACH attack: encryption and compression don't mix, by Gluck, Harris, and Prado
 
Lecture 12:
Wed 5/ 8/24
(DB)
HTTPS: goals and pitfalls   [pdfpptx]
Readings:

Part 4: Network Security and Privacy
 
Lecture 13:
Mon 5/13/24
(ZD)
Internet Protocols   [pdfkey]
Readings:
 
Lecture 14:
Wed 5/15/24
(ZD)
Internet Security   [pdfkey]
Readings:

Part 3: Mobile Security and other topics
 
Lecture 15:
Mon 5/20/24
(DB)
Android and iOS: mobile platform security architecture   [pdfkey]
Readings:
 
Lecture 16:
Wed 5/22/24
(inv)
Topics in Android security: guest speaker (Chris Steipp, Meta)   [pdf]
Readings:
 
Holiday:   
Mon 5/27/24
Memorial Day — No Lecture
 
Lecture 17:
Wed 5/29/24
(ZD)
DoS Attacks and Network Defenses   [pdfkey]
Readings:
 
Lecture 18:
Mon 6/ 3/24
(ZD)
Privacy, Anonymity, and Censorship   [pdfkey]
Readings:
 
Lecture 19:
Wed 6/ 5/24
(inv)
Final invited lecture: Christoph Kern, Google