CPSC 436s - Computer Security (2025W2)

About

InstructorMike Feeley
TAs
  • Saurav
  • Hanson
  • Soo Yee
  • Aditya
Lectures Wednesday and Friday, 11-12:30 in MCML 166
Office Hours
Wed 2:30-4 in ICCS 393

This wide-ranging topics course covers fundamental concepts in computer security and privacy. Students will learn about the fundamental techniques that are used to secure and protect computer systems, as well as the ways in which attackers can subvert security. They'll learn to play the roles of both the attacker and the defender, enabling them to better understand the tradeoffs and responsibilities inherent in building secure systems.

Prerequisites

CPSC 313 provides an understanding of computer systems, particularly operating systems, while CPSC 317 provides an understanding of networks and distributed systems. CPSC 436S builds on these fundamentals to explore security concerns in operating systems, networks and applications.

Textbook (Optional)

Either:

Assessment

ComponentPercentage
Assignments (10)25%
Clicker questions3%
In-class activities7%
Midterm (1)25%
Final exam40%

This class features assignments in a "capture-the-flag" style, in which students will aim to break the security of a given system and extract a secret value. It will also feature in-class activities (worksheets or collaborative exercises) as well as one midterm exam and final exam.

Setup instructions

This course will require students to run and debug programs on x86_64 Linux. If you run another operating system, you will need to virtualize a Linux environment for this course. The CS servers may work, but it is useful for learning to have an environment that you have full control over. Students using Arm machines (in particular, M-series Apple processors) will need to do some additional setup to emulate an x86 box for this course.

Even you're running Linux already, it is good practice to have an isolated environment for security research. None of the samples you will be provided in this course will be malicious (we hope that goes without saying), but some isolation goes a long way to prevent data loss as a result of a mistake.

Modules

CPSC 436S is structured as a series of ten modules, approximately one per week. Each module consists of lecture materials, textbook readings, assignments, and in-class worksheet activities. The course schedule is subject to change.

  1. Authentication and Access Control

  2. Cryptography I: Symmetric Encryption

  3. Cryptography II: Asymmetric Encryption

  4. Cryptography III: Hash, Digital Signatures, and TLS

  5. System/Network Security I: Web Security

  6. System/Network Security II: Networks and Firewalls

  7. System/Network Security III: System Security and Denial of Service

  8. Software Security I: Reverse Engineering and Vulnerabilities

  9. Software Security II: Binary Exploitation and Mitigations

  10. Timely topics: Cloud Computing, AI, Blockchain security (time permitting)

Academic integrity

The academic enterprise is founded on honesty, civility, and integrity. As members of this enterprise, all students are expected to know, understand, and follow the codes of conduct regarding academic integrity. At the most basic level, this means submitting only original work done by you and acknowledging all sources of information or ideas and attributing them to others as required. This also means you should not cheat, copy, or mislead others about what is your work; nor should you help others to do the same. For example, it is prohibited to:

All assignment instructions, quiz questions and answers, discussion questions, announcements, lecture slides, and any other materials provided to you by the Teaching Team or in the textbook are for use in this course by students who are currently enrolled in it. It is unacceptable to share any of these materials beyond our course, including by posting on file- sharing websites. Please respect the Teaching Team and textbook authors' intellectual property, and follow copyright law.

Note: The use of generative AI tools, including ChatGPT and other similar tools, to complete or support the completion of any form of assignment or assessment in this course is not allowed and would be considered academic misconduct. ChatGPT and other similar tools are not substitutes for your learning. These tools can produce harmful misinformation, and are readily capable of producing material that is plagiarized from other sources on the Internet. If you submit any material that is copied without attribution, you will be considered to have committed academic misconduct whether the material comes directly from the source, or is “generated” by such a model.

Adapted from Academic Integrity at UBC