CPSC 436s - Computer Security (2025W2)
About
| Instructor | Mike Feeley |
| TAs |
- Saurav
- Hanson
- Soo Yee
- Aditya
|
| Lectures |
Wednesday and Friday, 11-12:30 in
MCML 166
|
| Office Hours |
|
This wide-ranging topics course covers fundamental concepts in computer
security and privacy. Students will learn about the fundamental techniques
that are used to secure and protect computer systems, as well as the ways
in which attackers can subvert security. They'll learn to play the roles
of both the attacker and the defender, enabling them to better understand
the tradeoffs and responsibilities inherent in building secure
systems.
Quick links
- Piazza - Used for discussions and lecture notes.
- PrairieLearn - Used for assignments and exams.
Prerequisites
-
CPSC 313
- Computer Hardware and Operating Systems
-
CPSC 317
- Introduction to Computer Networking
CPSC 313 provides an understanding of computer systems, particularly
operating systems, while CPSC 317 provides an understanding of networks
and distributed systems. CPSC 436S builds on these fundamentals to explore
security concerns in operating systems, networks and applications.
Textbook (Optional)
Either:
-
Security in Computing: 5th Edition
Charles P. Pfleeger and Shari Lawrence Pfleeger
(ISBN-13: 978-9352866533)
-
Security in Computing: 6th Edition
Charles P. Pfleeger, Shari L. Pfleeger and Lizzie Coles-Kemp
(ISBN-13: 978-0137891214)
Assessment
| Component | Percentage |
| Assignments (10) | 25% |
| Clicker questions | 3% |
| In-class activities | 7% |
| Midterm (1) | 25% |
| Final exam | 40% |
This class features assignments in a "capture-the-flag" style, in which
students will aim to break the security of a given system and extract a
secret value. It will also feature in-class activities (worksheets or
collaborative exercises) as well as one midterm exam and final exam.
Setup instructions
This course will require students to run and debug programs on
x86_64 Linux. If you run another operating system, you
will need to virtualize a Linux environment for this course. The CS
servers may work, but it is useful for learning to have an environment
that you have full control over. Students using Arm machines (in
particular, M-series Apple processors) will need to do some additional
setup to emulate an x86 box for this course.
Even you're running Linux already, it is good practice to have an isolated
environment for security research. None of the samples you will be
provided in this course will be malicious (we hope that goes without
saying), but some isolation goes a long way to prevent data loss as a
result of a mistake.
Modules
CPSC 436S is structured as a series of ten modules, approximately one per
week. Each module consists of lecture materials, textbook readings,
assignments, and in-class worksheet activities. The course schedule is
subject to change.
-
Authentication and Access Control
- Determine the security policies of a system.
- Identify and compare the three main types of authentication.
- Understand how brute-force attacks work and how to avoid them.
- Define what access control is and how to implement it.
-
Cryptography I: Symmetric Encryption
- Understand what cryptography is and its terminology.
- Explain what an attack is and what makes a system secure.
- Identify classical cryptography schemes such as Caesar Cipher, Vernam Cipher, and Enigma Machine.
- Define and exemplify Symmetric Encryption.
- Describe the DES algorithm steps.
- Analyse the advantages and disadvantages of DES, AES, and the RC family encryption schemes.
-
Cryptography II: Asymmetric Encryption
- Define and exemplify Asymmetric Encryption.
- Describe the Diffie-Hellman algorithm to establish keys.
- Understand the steps for the El Gamal Algorithm, and why it is correct and secure.
- Understand the steps for the RSA Algorithm, and why it is correct and secure.
-
Cryptography III: Hash, Digital Signatures, and TLS
- Identify the uses and properties of a hash function.
- Understand the steps of two hash functions: DJB2 and SHA-1.
- Identify the uses and properties of a Digital Signature.
- Understand the steps of two digital signatures based on the El Gamal and RSA cryptosystems.
- Describe the major components of Transport Layer Security.
- Understand the role of Certificate Authorities in securing TLS.
-
System/Network Security I: Web Security
- Identify security risks on the user/client side of a network.
- Connect how a browser can be attacked with its effects on the user.
- Understand how false content is used to attack users and how to prevent it.
- Exemplify attacks that target the user.
- Explain how common web design mistakes can lead to security flaws allowing attackers to obtain data.
- Summarize the common attacks using email, including spam and phishing.
-
System/Network Security II: Networks and Firewalls
- Describe the main vulnerabilities of a network, and evaluate which OSI layer they affect.
- Define what a firewall is and how it is implemented.
- Enumerate the several types of firewalls, and explain their advantages and features.
- Compare the types of firewalls and analyze which one might be better for a specific situation.
- Exemplify technologies similar to a firewall, such as NAT, DLP, and VPN.
- Summarize the main attacks a network can suffer and analyze how they may affect communication.
- Understand how a port scanning application works and how it can be useful for an attacker.
-
System/Network Security III: System Security and Denial of Service
- Review how a wireless network works, and enumerate its main weak points.
- Compare the two main WiFi protocols, WEP and WPA.
- Critique the WEP protocol and identify its flaws.
- Understand what a DoS attack is and the harm it can make.
- Enumerate the different types of DoS attacks.
- Associate how DNS, routing, and TCP/IP protocols can be used in DoS attacks.
- Exemplify the best methods to cope with DoS attacks.
-
Software Security I: Reverse Engineering and Vulnerabilities
- Understand how program errors and faults can result in security failures.
- Identify the most common flaws in programs and how to avoid them.
- Exemplify the real-world consequences of several security failures resulting from program flaws.
- Differentiate malicious code from nonmalicious programming oversights.
- Explain how malicious code works and spreads.
- Recognize the consequences of malicious code to users, companies, and the world.
-
Software Security II: Binary Exploitation and Mitigations
- Understand techniques used to exploit software programs.
- Identify appropriate techniques for given classes of vulnerabilities.
- Describe mitigation strategies and how they can increase exploitation difficulty.
- Compare mitigation strategies and their tradeoffs.
- Exemplify the real-world impacts of vulnerabilities, exploits and mitigations.
-
Timely topics: Cloud Computing, AI, Blockchain security (time permitting)
- Enumerate Cloud Computing concepts, models, and offerings.
- Identify security risks when using a cloud provider.
- Differentiate FIdM, SAML, OAuth, and OpenID.
- Differentiate modern AI systems and their respective vulnerability classes.
- Determine what types of weaknesses may be present in an AI system and any applicable attacks.
- Understand common weaknesses in blockchain contracts.
- Exemplify real-world losses caused by vulnerabilities and exploits in blockchain applications.
Academic integrity
The academic enterprise is founded on honesty, civility, and integrity. As
members of this enterprise, all students are expected to know, understand,
and follow the codes of conduct regarding academic integrity. At the most
basic level, this means submitting only original work done by you and
acknowledging all sources of information or ideas and attributing them to
others as required. This also means you should not cheat, copy, or mislead
others about what is your work; nor should you help others to do the
same. For example, it is prohibited to:
- Share your past assignments and answers with other students.
- Work with other students on an assignment when an instructor has not
expressly given permission.
- Spread information through word of mouth, social media, websites, or
other channels that subverts the fair evaluation of a class exercise, or
assessment.
All assignment instructions, quiz questions and answers, discussion
questions, announcements, lecture slides, and any other materials provided
to you by the Teaching Team or in the textbook are for use in this course
by students who are currently enrolled in it. It is unacceptable to share
any of these materials beyond our course, including by posting on file-
sharing websites. Please respect the Teaching Team and textbook authors'
intellectual property, and follow copyright law.
Note: The use of generative AI tools, including ChatGPT and other similar
tools, to complete or support the completion of any form of assignment or
assessment in this course is not allowed and would be considered academic
misconduct. ChatGPT and other similar tools are not substitutes for your
learning. These tools can produce harmful misinformation, and are readily
capable of producing material that is plagiarized from other sources on
the Internet. If you submit any material that is copied without
attribution, you will be considered to have committed academic misconduct
whether the material comes directly from the source, or is “generated” by
such a model.
Adapted from
Academic Integrity at UBC