!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> CSE 127

CSE 127: Computer Security

Syllabus

Unless explicitly marked as Optional, all readings are considered required.


Date
Topic
Mar 30
Introduction
Apr 1
Threat Modeling and Risk
Read by today: Thompson, Reflections on Trusting Trust
Mickens, This World of Ours
Apr 6
Control Flow Vulnerabilities: Buffer Overflows
Read by today: Aleph One, Smashing the Stack for Fun and Profit.
Optional: Richard Bonichon's Basic exploitation techniques slides
Apr 8
Control Flow Vulnerabilities: Format strings, Integers and Heap
Read by today: van der Veen et al, Memory Errors: The Past, the Present, and the Future
Optional: sploitfun, Understanding glibc malloc.
Apr 13
Control Flow Vulnerabilities: Defenses and evolution
Read by today: Erlingsson et al, Low-level Software Security by Example
Optional: Szekeres et al, Eternal War in Memory
Apr 15
Control Flow Vulnerabilities: ROP and CFI
Optional: Shacham, The Geometry of Innocent Flesh on the Bone and Abadi et al, Control Flow Integrity.
Apr 20
System security I: Isolation and Privilege
Jaeger, Security in Ordinary Operating Systems
Apr 22
System security II: Side channels (also slides excerpted from Schwarz and Lipp)
Anderson, Security Engineering, Chap 19, Side Channels
Apr 27
Crypto I
Security Engineering, Chapter 5
Apr 29
Midterm: on Canvas
May 4
Crypto II: Key distribution
May 6
Web Security I
Deian Stefan's lecture notes on CSRF, XSS and SQLi, SQL injection
May 11
Web Security II
May 13
Cancelled
May 18
Network Security I
May 20
Network Security II
May 25
User Authentication
May 27
Malware I
June 1
Malware II/Cybercime
June 3
Privacy, Law and Ethics
June 8
Final Exam: On canvas (Tuesday, June 8th, 8am-10pm Pacific), 90mins long