Internet Security
Bachelor lecture · HPI
About the course
Bachelor lecture with exercises (4 SWS, 6 ECTS, taught in English, limited to 30 participants). The information below is from the most recent run in winter semester 2021/22.
The lecture “Internet Security” shall be seen as a door-opener in the field of network and Internet security. You will learn and understand basic principles and approaches of cyber attack and defense.
This lecture does not teach you about being a hacker. Instead, it teaches you how to investigate and prevent possible vulnerabilities in (IT) systems. You will further be enabled to determine which consequences a failure of a certain system has, or which consequences a lack of thorough preparation may put upon a security system or an organization as a whole. The lecture focuses strongly on practical parts and exercises.
Topics covered
- Motivation and types of cyber attacks
- Enablers and vulnerabilities – human and technical
- Malware – what is a virus, worm, trojan, …
- Software security – reverse engineering
- Operating systems and their security mechanisms
- Sandboxing and virtualization
- “Think like hackers”
- Reconnaissance
- Application security
- Update distribution – risks and challenges
- “Being the blue team”
- Network security
- Intrusion detection
- Risk analysis
- Cryptography
- Law, ethics and remarks
This lecture is a prerequisite for continuing with the seminar “CTF: Cops and Robbers”, which provides even more insights into cybersecurity topics in a team-based manner.
Requirements
To be able to survive in the world of technical specifications, applications, protocols and requirements, a proper understanding of its fundamentals is needed. This understanding is provided in the recommended lecture “Internet- und WWW-Technologien”. If you think you have received the qualifications for participation in another way, feel free to reach out to us to discuss.
During the lecture you will need knowledge of several programming languages like Python, C and Assembly. Additionally, you will need to be able to configure networks and have a good understanding of the different layers of a typical network as well as related Linux tools. A recap of the most important topics and an introduction to these languages is provided; students not already familiar with them should expect a slightly higher workload in the first weeks.
In order to solve the practical exercises you will need Linux (for example in a VM) running on your laptop. We recommend Kali Linux or a similar pentesting distribution.
Format
The lecture consists of highly interactive sessions requiring students’ participation. In those sessions, the theoretical backgrounds and the underlying technologies are explained; the new knowledge is then applied in practical, hands-on sessions. Typically there is one lecture per week, plus an exercise session in which new tasks are presented, past tasks are discussed, or students present their findings. Tutors are available in fixed weekly time slots to help with the practical exercises.
Literature
- Meinel/Sack: Grundlagen der Digitalen Kommunikation
- Meinel/Sack: Internetworking – Technische Grundlagen und Anwendungen
- Tanenbaum: Computer Networks
- Stallings/Brown: Computer Security: Principles and Practice
- Cheswick/Bellovin/Rubin: Firewalls and Internet Security. Repelling the Wily Hacker
- Kaufman/Perlman/Speciner: Network Security: Private Communication in a Public World
- Egan/Mather: Executive Guide to Information Security: Threats, Challenges, and Solutions
- Stuttard/Pinto: The Web Application Hacker’s Handbook – Discovering and Exploiting Security Flaws
- Koziol/Litchfield/Aitel/Anley/Eren/Mehta/Hassel: The Shellcoder’s Handbook – Discovering and Exploiting Security Holes
Grading
The evaluation is split into two parts, both at the end of the semester but not on the same day:
- Theoretical exam (about 40%): a 90-minute written exam that tests the theoretical understanding.
- Practical exam (about 60%): a day-long exam with a real-world scenario in which students show the practical skills learned in the exercises.
To obtain examination admission, you need 50% of the points in every group of two consecutive assignments and have to attend at least 75% of all lecture sessions.
Semesters
All courses- WS 2021/22FinishedInternet SecurityBachelor lecture · HPI
- WS 2019/20FinishedInternet SecurityBachelor seminar · HPI