No required textbook. Reading materials will be provided on the course website and/or distributed in class.
This course requires a basic understanding of computer systems and computer security. Please consider taking these courses first:
Your final grade for this course will be based on the following scheme:
| Date | Topics | Notice(s) | Readings |
|---|---|---|---|
| Overview of Security Principles | |||
| Wed. 09/23 |
Introduction [Slides] |
Online |
(Classic)
The Security Mindset (Classic) Why Information Security is Hard – An Economic Perspective |
| Part I: Network/Internet Security | |||
| Mon. 09/28 |
Internet Protocols [Slides] |
In-person |
(Classic)
Censys: A Search Engine Backed by Internet-Wide Scanning (Classic) Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices |
| Wed. 09/30 |
Ecosystems [Slides] |
Online [Team-up! by 09/30] |
(Classic)
A Longitudinal, End-to-End View of the DNSSEC Ecosystem (Classic) Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed |
| Mon. 10/05 |
Applications [Slides] |
In-person |
(Classic)
The Science of Guessing: Analyzing an Anonymized Corpus of 70 Million Passwords (Recent) Analyzing the End-to-end Life Cycle and Effectiveness of Phishing ... |
| Wed. 10/07 |
- | [No class] | Checkpoint I Presentation Prep. |
| Mon. 10/12 |
Term-Project | In-person | Checkpoint Presentation I |
| Part II: Computer Systems Security | |||
| Wed. 10/14 |
Memory Safety | Online |
(Basic)
Hacking Blind (Classic) Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks (Classic) AddressSanitizer: A Fast Address Sanity Checker |
| Mon. 10/19 |
OS Security I | In-person |
(Classic)
Setuid Demystified (Classic) Capsicum: Practical Capabilities for UNIX |
| Wed. 10/21 |
OS Security II | Online |
(Classic)
syzkaller - Kernel Fuzzer (Classic) The Flask Security Architecture: System Support for Diverse Security Policies |
| Part III: Isolation and (Software-induced) Breaks | |||
| Mon. 10/26 |
Isolation | In-person |
(Classic)
Efficient Software-based Fault Isolation (Classic) Shilding Applications from an Untrustsed Cloud with Haven |
| Wed. 10/28 |
Rowhammer | Online |
(Classic)
Flipping Bits in Memory Without Accessing Them (Recent) Exposing the Graceless Degradation in DNNs Under Hardware Fault Attacks |
| Mon. 11/02 |
Side-Channels | In-person |
(Classic)
FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack (Recent) Spectre Attacks: Exploiting Speculative Execution |
| Wed. 11/04 |
- | [No class] | Checkpoint II Presentation Prep. |
| Mon. 11/09 |
Term-Project | In-person | Checkpoint Presentation II |
| Part IV: Software/Web Security | |||
| Wed. 11/11 |
- | [No class] | Veterans Day |
| Mon. 11/16 |
Malware | In-person |
(Classic)
AEG: Automatic Exploit Generation (Recent) Continuous Learning for Android Malware Detection |
| Wed. 11/18 |
Web Security | Online |
(Classic)
Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites (Classic) All Your iFRAMEs Point to Us |
| Part V: Trustworthy ML | |||
| Mon. 11/23 |
Attacks | In-person |
(Classic)
Towards Deep Learning Models Resistant to Adversarial Attacks (Classic) Membership Inference Attacks From First Principles |
| Wed. 11/25 |
- | [No class] | Thanksgiving Break |
| Mon. 11/30 |
Defenses | In-person |
(Recent)
(Certified!!) Adversarial Robustness for Free! (Classic) Deep Learning with Differential Privacy |
| Wed. 12/02 |
Term-Project | In-person | Final Presentations (Showcases) |
| Finals Week (12/07 - 12/11) | |||
| Mon. 12/07 |
- |
[No Lecture] [Final Exam] |
Final Exam (take-home, on Canvas). |
| Wed. 12/09 |
- | [No Lecture] | Submit your final project report (on Canvas). |