Due by class means due at the time class starts. For example, if your section’s class starts at 1:00pm, then “Monday by class” means 1pm on Monday. This gives our TA an opportunity to spot-check the submissions and fix any submission issues when everyone’s together.
Schedule
-
- Week
- Dates
- Lecture & Activities
- Vulnerability of the Day
- Due or Released
- Reading
-
- 1
- Aug 24 — Aug 28
- Course Overview,
Introduction:
What is Secure?
Security Principles & Lifecycle - Integer Overflow
- CWE-190 CWE-120
-
- 2
- Aug 31 - Sep 05
- Web Security Overview,
DVWA activity
Penetration Testing - Buffer Overflow, SQL injection, Cross-Site Scripting (XSS)
- Fuzzer released.
- CWE-89 CWE-79
-
- 3
- Sep 07 - Sep 11
- No class Monday Sep 07 (Labor Day)
Requirements: Misuse & Abuse Cases
Requirements & planning activity - Cross-site request forgery (CSRF), OS command injection
- Fuzzer iteration 0 due Sunday EOD
- CWE-352 CSRF Description CWE-78
-
- 4
- Sep 14 - Sep 18
- Planning: risk assessment,
Environment: file system permissions,
Design: threat modeling. - Path traversal, log overflow
- Fuzzer iteration 1 due Sunday EOD
- CWE-22 CWE-400 CWE-779 CWE-770
-
- 5
- Sep 21 - Sep 25
- Threat modeling activity
Design: distrustful decomposition,
Implementation: defensive coding practices (part 1) - XML embedded DTDs
- Fuzzer iteration 2 due Sunday EOD.
- CWE-827 CWE-776 CWE-611
-
- 6
- Sep 28 - Oct 02
- Implementation: defensive coding practices (part 2),
Catch up. - Hardcoded credentials
- File Permissions myCourses Quiz AND Practice Quiz due Wed Sep 30 by class. In-Class Exam 1 Fri Oct 02 Takehome exam released with in-class exam.
- CWE-798 CVSS v3 Spec
-
- 7
- Oct 05 - Oct 09
- Vulnerability assessment: CVSS.
CVSS activity. - Time of Check Time of Use (TOCTOU), Log neutralization
- Takehome portion of exam due Monday by class. Input Handling project released.
- CWE-367 CWE-117 CWE-93 CAPEC-93
-
- 8
- Oct 12 - Oct 16
- No classes Oct 12&13
Cryptography: authentication, public & symmetric keys, SSH, SSL, PGP.
Side-channel attacks. - Hashing without salt
- Input Handling project parts 0, 1, 2 due Friday EOD.
- CWE-759 Salting Guide
-
- 9
- Oct 19 - Oct 23
- Cryptography: continued.
Supply-chain attacks. - Poor PRNG seed protection, Insecure PRNG algorithms
- Input Handling project all parts due Friday EOD. IPC Project released
- CWE-338 OAuth Spec CWE-470
-
- 10
- Oct 26 - Oct 30
- Deployment & Distribution: patching, security managers.
Usability and Security; OAuth activity. - Regex DOS, Java reflection abuse
- IPC Project due Sunday by EOD.
-
- 11
- Nov 02 - Nov 06
- Catch up / Exam Review Wed / Exam 2 Fri Nov 06.
-
- 12
- Nov 09 - Nov 13
- Insider Threat.
- Compression bombs. Uncontrolled format string.
- Case Study recon Wed Apr 08.
- CWE-409 Compression Bombs
-
- 13
- Nov 16 - Nov 20
- Networking: OSI model.
- Cache poisoning
- Case Study Chapter 1 due Wed by class; review in class
- CWE-134 CAPEC-141 Video: DNS Cache Poisoning
-
- 14
- Nov 23 - Nov 27
- No classes Nov 25-27
Networking: continued. - Dynamic library side-loading
- Case Study Chapter 2 review is canceled unless Monday is free.
-
- 15
- Nov 30 - Dec 04
- Mon Nov 30: Last day of class. Case Study presentations.
- All makeup work due by Monday.
-
- Thur Dec 10
- 4:15pm-6:45pm In-person, in GOL-1640 (unless you have arranged otherwise with Prof. Basham)