Network Security in Practice

Master seminar · HPI

Zum Kurs

Project seminar for the master programmes CybSec, CS, ITSE, DE, SSE and DH. The information below is for winter semester 2026/27.

Modern IT infrastructures are becoming increasingly complex and interconnected. Cloud services, mobile and IoT devices, distributed applications, and, more recently, AI-based systems have significantly expanded the attack surface of organizations. At the same time, attackers increasingly use automation and AI to discover vulnerabilities, conduct social engineering, and scale attacks. Organizations therefore invest substantial resources in technologies and processes for preventing, detecting, investigating, and responding to cyberattacks. However, understanding security concepts in theory is only one part of the challenge: How do security technologies actually work in practice? What can they detect or prevent, where do they fail, and how can they be improved?

The goal of this seminar is to investigate practical security problems, technologies, and emerging research directions through a combination of literature study, technical analysis, experimentation, and prototyping. Students are expected to work in a small team of up to two members on a topic from the following areas:

  • Network Scanning, Discovery, and Security Monitoring
  • Tunneling and Virtual Private Network (VPN)
  • AI for Cybersecurity
  • Data-driven threat detection
  • Cyber Threat Intelligence
  • Web and API Security
  • Email Security
  • IoT, Edge, and Cyber-Physical Security
  • Mobile Security (Mobile OS, App, Network, etc.)
  • Machine Learning, AI, and LLM for Cybersecurity
  • Agentic AI for Security Automation
  • ML/AI System Security
  • LLM and Generative AI Security
  • Security of AI Agents
  • Enterprise AI Security and AI Observability
  • Red Teaming and Security Testing of AI Systems
  • A topic proposed by you

The topics above intentionally describe broad research areas rather than fixed assignments. Each team should identify concrete research question(s) and define appropriate practical component(s), such as implementing a prototype, evaluating existing tools, reproducing research results, analyzing a real-world dataset, or conducting experiments in a controlled environment.

Important notes

  • Due to limited capacity, the seminar can accommodate a maximum of 12 students. If you are interested in participating, please find a partner and send an email to cheng AT hpi.de, preferably including the topic or research area you are interested in. Places will generally be assigned on a first-come, first-served basis.
  • Details about the introductory session, seminar schedule, presentations, and deadlines will be announced separately.
  • This seminar does not authorize attacks against third-party systems. All experiments and security testing must be conducted on systems, environments, and resources for which you have explicit authorization. Participation in this seminar does not justify or authorize any malicious or unauthorized activity on the Internet.

Requirements

  • Good knowledge in
    • networking technologies (TCP/IP, routing, …)
    • operating systems and software engineering
    • security basics (e.g., the lectures “Internet Security – Weaknesses and Targets” and “Informationssicherheit”)
  • Good hands-on technical skills
    • Basic programming/scripting experience
  • The ability to independently read and analyze research papers and technical documentation
  • An interest in experimenting with security technologies and building prototypes

Further readings

  • William R. Cheswick, Steven M. Bellovin, “Firewalls and Internet Security”, second edition, Addison-Wesley, 2003.
  • Andrew S. Tanenbaum, “Computer Networks”, fourth edition, Prentice Hall PTR, 2003.
  • Charlie Kaufman, Radia Perlman, and Mike Speciner, “Network Security: Private Communication in a Public World”, second edition, Prentice Hall PTR, 2002.
  • Dafydd Stuttard, Marcus Pinto, “The Web Application Hacker’s Handbook: Discovering and Exploiting Security Flaws”, Wiley & Sons, 2007.
  • OWASP, OWASP Top 10
  • OWASP, Web Security Testing Guide (WSTG)
  • OWASP, API Security Top 10
  • OWASP, Top 10 for Large Language Model Applications
  • OWASP, GenAI Security Project
  • MITRE ATT&CK
  • MITRE D3FEND
  • MITRE, ATLAS – Adversarial Threat Landscape for Artificial-Intelligence Systems
  • NIST, Cybersecurity Framework (CSF)
  • NIST, Computer Security Incident Handling Guide
  • NIST, AI Risk Management Framework (AI RMF)
  • NIST, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations
  • Google, Secure AI Framework (SAIF)
  • ENISA publications on Artificial Intelligence and Cybersecurity

Students are additionally expected to identify and study recent research papers, technical reports, open-source projects, and industry systems relevant to their selected topic.

Grading

The final evaluation will be based on: report, presentation, design, implementation, participation in the seminar.

  • Intermediate (40%)
    • Lightning talk: 10% (Prüfungstermin: 07.12.2026)
    • Presentation (research): 20%
    • Practice (implementation): 10%
  • Final (40%)
    • Presentation (design + architecture + experiments + analysis): 20%
    • Practice (implementation): 20%
  • Technical report (20%)
    • Project management, final deliverable, report, …
  • Your active participation, creative/innovative ideas, or successful implementations will be appreciated with bonus points.
  • The above-mentioned evaluation principles are only for reference and subject to change. The concrete evaluation may slightly differ from team to team depending on the selected topic(s) and other relevant factors.

Important dates (WS 2026/27)

The seminar will start right on the first day of WS 2026/27. Regular meetings will be held every week or upon request.

  • 12.10.2026 – Introduction (Campus II, P-E.12)
  • CW 42–43, 2026: Team building, topic assignment and literature recommendation (per email)
  • 26.10.2026 – Enrolment deadline + discussion meeting (topics, organization and plan)
  • CW 44–49, 2026: Weekly team meetings (literature, tools and scenarios)
  • 07.12.2026 – Get-together (lightning talk)
  • CW 50, 2026 – CW 02, 2027: Weekly team meetings (progress report & scenario implementation, per email)
  • 11.01.2027 – Phase I: Presentation & demonstration (scenario)
  • CW 03–07, 2027: Weekly team meetings (project implementation)
  • 15.02.2027 – Phase II: Presentation & demonstration (integrated project)
  • 28.03.2027 – Submission deadline (report & final deliverables)

Contacts

  • Feng Cheng (Campus II, O1-E.07, 0331 5509-519)
  • Pejman Najafi (Campus II, O1-E.06, 0331 5509-3959)

Format

  • Master seminar
  • Bachelor seminar

Institution

  • HPI

Semester

Alle Kurse