|
|
184.216 Internet Security
Vorlesung mit Uebung (2.0)
Lecturers
InetSec Advisors ;-)
Christian Platzer
Engin Kirda, Institut Eurecom, Sophia Antipolis
Tutors
Bernhard "Perfect Prime" Miller (InetSec 2 Master Guru)
Markus "Hex Cypher" Kammerstetter (InetSec 2 Master Guru, former tutor, still advising ;-) )
News
- 22.06.2010 We have enabled the registration for the next exam on Wed. June 30th 2010! You must register via TUWIS++ to participate in the exam!
- 22.06.2010 Results for the exam are in. Find them on bandit in your home directory! For questions, come to our office on Friday, June 25th (12-1pm).
- 11.06.2010 We have enabled the registration for the written exam on Wed. June 16th 2010. You must register via TUWIS++ to participate in the exam!
- 09.06.2010 The written exam will take place next Wednesday (June 16th 2010, 12:00) in EI 10.
- 09.06.2010 The lab is over! Congrats to all students who have solved challenges and proved their skills!
- 26.05.2010 Challenge six is online. Have fun smashing the stack!
- 12.05.2010 The fifth challenge is online. Enjoy!
- 29.04.2010 After a 10 hour pause for fixing problems in our grading scripts, challenge4 is back online. Happy XSS-ing!
- 28.04.2010 Challenge4 is online. XSS anyone ?
- 21.04.2010 Challenge3 is online. Happy injecting!
- 14.04.2010 Challenge2 is online now. Have fun!
- 24.03.2010 Challenge1 has started. Happy sniffing!
- 16.03.2010 The registration service is back online. Go here to register before the deadline (March 31st).
- 10.03.2010 We fixed a few issues keeping you from logging into the lab environment. Sorry for the inconveniences!
- 04.03.2010 Lab registration has started.
- 01.03.2010 Weekly lecture will start on Wednesday, March 10th 2010, 12:00 (c.t.) in EI 10
- 01.03.2010 The preliminary meeting (Vorbesprechung) will be held on Wednesday, March 3rd 2010, 12:00 (c.t.) in EI 10
- 28.02.2010 It's summer semester 2010, let's get rolling!!
Abstract
Internet security has become part of everyday life where
security problems impact practical aspects of our
lives. Even though there is a considerable corpus of knowledge about
tools and techniques to protect networks, information about what are
the
actual vulnerabilities and how they are exploited is not generally
available. This situation hampers the effectiveness of security
research and practice. Understanding the details of network attacks is
a prerequisite for the design and implementation of secure systems.
This course presents the principal protocols and applications
that are used in the Internet today, discussing in detail the related
vulnerabilities and how they are exploited. For each vulnerability,
possible protection and detection techniques are examined. The course
includes a number of practical lab assignments where participants are
required to
apply their knowledge as well as a discussion of the
current research in the field. Students will learn how the security of
networks can be violated and how such attacks can be detected and
prevented.
The course aims to make the students "security aware" and gain a basic
understanding about security issues. For students who are
interested in advanced security topics and practical assignments, we offer the
Advanced Internet Security class in the winter semester.
Topics
- TCP/IP security (spoofing, hijacking, sequence number
guessing, denial-of-service attacks)
- Web security (SQL injection, parameter injection,
parameter tampering, etc.)
- Network discovery/vulnerability scanning: techniques and
tools (portscans, ping sweeps)
- Distributed systems security
- Firewalls and traffic filtering
- Intrusion Detection Systems
- Buffer Overflows
- Operational Practices
- Architectural Principles and Testing
Prerequisites
- basic operating system knowledge (Linux/Unix, Windows)
- interest for technical security issues
- good programming knowledge (e.g., Java, Web scripting, HTML advantageous)
- basic database knowledge (SQL)
- basic network knowledge (TCP/IP, VO and UE Computer Networks is recommended, VO and UE
Verteilte Systeme is a must!)
Location
EI 10 Fritz Paschke HS, Elektrotechnisches Institutsgebäude.
Dates and Times
Weekly, 12:00-14:00 c.t. (that is, we start at 12:15, 90 minutes)
Preliminary meeting (Vorbesprechung): Wednesday, March 3rd 2010
Regular, weekly lecture: Wednesday, starting March 10th 2010
Slides
03.03.2010, Introduction slides
10.03.2010, Security and Networking Basics slides
17.03.2010, TCP/IP Security (1) slides
24.03.2010, TCP/IP Security (2) slides
14.04.2010, Web Security (1) slides, OWASP Top10
21.04.2010, Web Security (2) slides
28.04.2010, Internet Applications slides
05.05.2010, Testing slides
12.05.2010, Cryptogrphy slides
19.05.2010, no lecture!
26.05.2010, Buffer Overflows slides
02.06.2010, Language Security slides
09.06.2010, no lecture!
16.06.2010, Exam
Practical Challenges (Assignments)
This year, the students will "need" to solve a set of practical challenges
(assignments) in the lab part of the course. The practical part of the course aims to prepare the students for more
advanced topics and programming done in the Internet Security 2 course.
For more information on the challenges and the grading, check this page.
The currently open challenge is challenge 6.
Examination
Written exam (English). About 15 questions, 75 minutes time, no course material allowed.
The date for the next exam is 30.06.2010, starting at 12:00 c.t, in EI 10 Fritz Paschke HS (same place as the lecture).
Good luck!
Registration Registration will start on 04.03.2010 and will continue until 31.03.2010.
Use this link to register for this course and get an account, once registration has started.
Last Modified: Tue Jun 22 18:38:40 CEST 2010
|
|
|