Security engineering
What the discipline is, the policy/mechanism/assurance/incentives framework, security goals, design principles, and how attacks are classified.
Revision site — 7 modules, 45 topics
A study site for CSEC3616 / CSEC5616 / INFO3616, generated from the unit's own decks, notes and tutorials. The lecture is the authority throughout — where a page draws on anything outside it, the page says so.
BeginCASE 01-01What security engineering isWhat the discipline is, the policy/mechanism/assurance/incentives framework, security goals, design principles, and how attacks are classified.
Psychological acceptability, cognitive bias, influence techniques, social engineering, and the usability and strength of passwords.
Access matrices, DAC and MAC, ACLs and capabilities, Unix permissions, platform and hardware isolation, Bell-LaPadula and Biba.
Divisibility, modular arithmetic, extended Euclid, Fermat and Euler, discrete logarithms, groups, rings, fields and GF(2^n).
Classical ciphers, confusion and diffusion, stream ciphers and the one-time pad, Feistel structures, DES, AES, modes of operation and CSPRNGs.
Trapdoor functions, RSA and its attacks, hybrid encryption, Diffie-Hellman, elliptic curves and post-quantum cryptography.
Hash resistance properties and the birthday attack, SHA-2 and SHA-3, message authentication codes and HMAC, authenticated encryption with GCM and CCM, and digital signatures.
Entity authentication, challenge-response, replay and freshness, session key establishment, key distribution centres, Needham-Schroeder and Kerberos.
A networking refresher through the TCP/IP layers, what an attack on a network looks like, and then the cryptographic protocols layer by layer: OAuth and OpenID, TLS 1.2 and 1.3, and IPSec with its security associations, AH, ESP, IKEv2 and the two modes.
What Assignment 1 tests, and the unit virtual machine.