Number of hours
- Lectures 24.0
- Projects -
- Tutorials 12.0
- Internship -
- Laboratory works -
- Written tests -
ECTS
ECTS 3.0
Goal(s)
- Being able to understand the threats and vulnerabilities and manage a security policy
- Operating Systems
- networks infrastructures
- Applications and software engineering
- Protocols and security property
- Business Processes
- What actions to avoid / limit
- Guide to good practice and usage
- Security Policy for information systems / Audit
- Methodology
Sebastien VIARDOT
Content(s)
The module is largely based on the assignments to be made, consisting of fault analysis, the responses needed to limit the impacts (anticipation and reaction), and propose experiments to implement them.
The topics covered in the framed sessions are :
- Introduction to the course, legal warning, assignments presentation.
- Lab : Docker and vagrant, and setting up a security challenge
- Good and bad use of crypto
- Authentication methods
- Certificates PKI, Kerberos, oauth2, case, SSO
- PKI Certificate Lab
- Blockchain
- Local vulnerability and good practices
- identification (3 factors), solutions. Identity theft
- media confidentiality - encryption / access
- Access rights and best practices
- Exploits and answers
- Hardware flaw, illustration via meltdown and spectrum (if not otherwise processed)
- Buffer overflow lab
- Network failures and good practices
- Snort Lab
- WEB security
- WEB security lab
- Protocol verification
- Protocol verification lab
Having taken the following courses (or equivalent) is recommended:
- Operating System Design Project - Foundations
- Operating system and concurrent programming
- Security of systems and networks
CONTINUOUS CONTROL (CC):
Evaluation type:
Work to be done (alone or in pairs) on a vulnerability analysis and an experiment + Peer evaluation. A total of 2 works to be done and 6 peer reviews to be done.
NORMAL SESSION:
No written examination in limited time in normal session, evaluation in continuous control.
RETRIEVAL SESSION (E2):
Type of examination: Work equivalent to render individually on the analysis of a new vulnerability + written or oral following the number of students catching up.
Specific room:
Duration: 2h if it is a writing, 1h if it is an oral.
Authorized documents: none
Prohibited documents (eg books, all documents): all
N1=CC
N2=E2
The course exists in the following branches:
- Curriculum - Embedded Systems & Connect. Devices - Semester 9
Course ID : 5MMSSI9
Course language(s):
The course is attached to the following structures:
- Team Computer security
You can find this course among all other courses.