Introduction: What is security ? What isn't security ? Security by obscurity.
Cryptographic Primitives (1): single-key encryption, DES.
Cryptographic Primitives (2): two/multi-key crypto (RSA), crypto-hashes.
Ciphers (1): overview, types, (also: project discussion)
Communication Security: layers: PEM/SSL/IPSec
Key Management: PKIs, storage for secrets (disk, memory).
Catch-up Session: continue with Kerberos, do overview of previous lectures
Access Control (1): AC matrix, undecidability of security
Access Control (2): ACLs, capabilities.
Policies (1): overview, confidentiality, trust, Bell-LaPadula model
Policies (2): integrity, Biba, Clark-Wilson.
Policies (3): Chinese Wall, other hybrids.
Midterm Review
Midterm: on Friday,in class.
Authentication: definition, passwords, biometrics, location.
Information Flow: compiler, runtime mechanisms
Sandboxing: confinement, isolation, covert channels.
Audits: mechanisms, implementations.
Intrusion Detection: models, reponse.
Advanced Topics: Proof-Carrying Code.
Review for Final |