| Person in charge: | Jordi Nin Guerrero (nin |
| Other: | Jaime M. Delgado Merce (jaime |
| ECTS Credits | Department | Type | Requirements | Teaching Languages | ||||
|---|---|---|---|---|---|---|---|---|
| 6.0 | AC |
|
Pre-correquisit SO
Pre-correquisit XC |
|
||||
Professors
| ||||||||
| Weekly hours dedication | T : 3.0 | P : 0.0 | L : 1.0 | AA : 5.6 | AD : 0.4 |
Threats, risk analysis, protection mechanisms, security of communications, security forensics, politicies, recovery, legal aspects, ...
Basics of cryptography. Public key. Electronic signatures.
Certificates. Directories. Protocols.
Malicious Code: Viruses, Trojan horses, worms, spyware, etc. Access Control.
Firewalls. Virtual Private Networks. Secure network protocols. Intrusion detection systems.
Security on the web. Secure application protocols. Electronic commerce.
Collection of evidence. Analysis.
| Activity | Evaluative Activity | T | P | L | AA | AD |
| Activity | Evaluative Activity | Theory hours | Problem hours | Lab hours | Independent Learning Hours | Directed Learning Hours |
| Development of theme 1. Introduction. | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 6.0 | 0.0 | 0.0 | 4.0 | 0.0 | 10.0 | |||
| Vulnerabilities in web applications | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 0.0 | 0.0 | 3.0 | 2.0 | 2.0 | 7.0 | |||
|
Alumn: Understanding the secure programming techniques described in the session. Understanding the webscarab and webgoat applications included in the OWASP linux distribution | ||||||||
| Development Topic 2. Cryptography. | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 7.0 | 0.0 | 0.0 | 8.0 | 0.0 | 15.0 | |||
|
Alumn: Learning the concepts and objectives associated with this item. Goals:Contents
| ||||||||
| Security in wireless networks | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 0.0 | 0.0 | 2.0 | 2.0 | 0.0 | 4.0 | |||
|
Alumn: Understanding the protocol WEP. Being able to use the tools Airodump linux, aircrack and Aireplay | ||||||||
| Development of item 3. Infrastructure PKI. | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 8.0 | 0.0 | 0.0 | 9.0 | 1.0 | 18.0 | |||
|
Alumn: Learning the concepts and objectives associated with this item. Goals:Contents
| ||||||||
| Using digital certificates and apache (HTTPS) | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 0.0 | 0.0 | 2.0 | 2.0 | 0.0 | 4.0 | |||
|
Alumn: Being able to create a X.509 certificate with openssl and install it on an Apache web server to configure HTTPS | ||||||||
| PKCS: Public-Key Cryptography Standard | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 0.0 | 0.0 | 2.0 | 2.0 | 0.0 | 4.0 | |||
|
Alumn: Understanding the different formats of the PKCS messages. Being able to create PKCS messages using the linux tool openssl | ||||||||
| First partial exam | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 1.0 | - | - | 4.0 | - | 5.0 | |||
| Development of item 4. Security in operating systems. | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 5.0 | 0.0 | 0.0 | 5.0 | 0.0 | 10.0 | |||
| Malware analysis | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 0.0 | 0.0 | 2.0 | 2.0 | 0.0 | 4.0 | |||
|
Alumn: Understanding the different forms to analyze a malicious code. Being able to properly use the analysis tool IDAPro | ||||||||
| Development of item 5. Internet security | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 8.0 | 0.0 | 0.0 | 9.0 | 1.0 | 18.0 | |||
|
Alumn: Learning the concepts and objectives associated with this item. Goals:Contents
| ||||||||
| Iptables i snort | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 0.0 | 0.0 | 3.0 | 2.0 | 0.0 | 5.0 | |||
|
Alumn: Understanding how the iptables command works as well as its internal operations based on tables and chains. Being able to create snort rules | ||||||||
| Documentation about malicious code. | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 0.0 | 0.0 | 0.0 | 10.0 | 0.0 | 10.0 | |||
|
Alumn: Being able to find high quality information about malware. Learning how to filter relevant information. Being able to correctly cite the information sources used. Goals:Contents
| ||||||||
| Development of item 6. Security applications. | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 6.0 | 0.0 | 0.0 | 6.0 | 0.0 | 12.0 | |||
|
Alumn: Learning the concepts and objectives associated with this item. Goals:Contents
| ||||||||
| Second partial exam | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 1.0 | - | - | 4.0 | - | 5.0 | |||
| Development issue 7. Security forensics. | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| 3.0 | 0.0 | 0.0 | 3.0 | 0.0 | 6.0 | |||
|
Alumn: Learning the concepts and objectives associated with this item. Goals:Contents
| ||||||||
| Final exam lab | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| - | - | 1.0 | 2.0 | - | 3.0 | |||
| Final Exam | T | P | L | AA | AD | Total | ||
|---|---|---|---|---|---|---|---|---|
| - | - | - | 8.0 | 2.0 | 10.0 | |||
| Total per type | T | P | L | AA | AD | Total |
| 45.0 | 0.0 | 15.0 | 84.0 | 6.0 | 150.0 |
This course should give an overview and a technical view of the problems and possible solutions to computer systems and networks security. For this reason, it covers many topics and has a great descriptive component.
However, the teaching methodology will use examples and problems for introducing the concepts to which students attain the necessary skills. Also, we will try to encourage interactivity with students considering real situations in class to discuss possible solutions.
Moreover, the laboratory will complete the skills and knowledge acquired in theory / problems class.
Theory (75%) - Laboratory (20%) - Generic competence (5%).
The laboratory mark is obtained from the grades of each practice (40%) and the laboratory final exam (60%).
The theory grade will be the final exam grade (EF) if it is higher than the average of two exams (P1 and P2), or otherwise, 30% of the average of partial exams and 70% of the final exam. In other words, the theory grade will be MAX (EF, 0.3*Par+0.7*EF), where Par=(P1+P2)/2.
The grade for the generic competence is obtained from the evaluation of the activity "Documentation about malicious code".