← CSE508 course

CSE508: Network Security

Spring 2022

InstructorAmir Rahmati
Office HoursThu/Thu 11:15 -- 12
Office Hour LocationNCS 359
Class LocationNCS 120
Class TimeTue/Thu 9:45 -- 11:05
PrerequisitesMature understanding of networked systems.
TATBD
TA Office HoursTBD
TA Office Hour LocationTBD
PiazzaLink

Grading

Paper Responses20%
Midterm Exam25%
Final Exam25%
Research Project30%

Class Calendar

Readings

There is a mandatory readings for each class. It is your responsibility to read the paper and write a ~400 word critical response.

Your most important task is to demonstrate that you've read the paper and thought carefully about the topic.

Paper responses are due before the start of class via Blackboard.

Research Project

Your course project should address an important, interesting open problem related to network security. It's up to you to find a good topic, but I'm happy to discuss your project ideas individually and help you refine them.

Resources

We will setup a git repository for each group to upload their code and documents. If you need any additional resources, talk to me or one of the TAs and we do our best to accommodate you.

Group Assignment

I recommend working in groups of 3 or 4. The larger the group, the more I'll expect you to accomplish.

Project Proposal

Your proposal should consist of a 3-4 page description of your project that includes the following:

Literature Review

Complete and submit a literature review for your project. Literature reviews should consist of a 2-4 page analysis of works related to your project's area. Your review should not simply be a laundry list of related projects. It should synthesize the works into areas and themes, discuss how it relates to the research question you are exploring, discuss the knowns and unknowns in the space, and highlight any disagreements and controversies.

For a more detailed explanation on how to do a literature review, read this.

Progress Report

Write a concise status report (no more than three pages) answering the following questions:

You're also welcome to come see me if you need advice.

Presentation

The last Week of class is set aside for the CSE 508 Security Symposium. Each group will prepare a presentation for the event and present their results in the format of a conference session.

Final Report

Your group's final project report should be written in the style of a workshop or conference submission, like most of the papers we read this semester. Please include at least the following:

See also: Advice on writing technical articles.

The length of your report should not exceed 8 typeset pages, excluding bibliography and well-marked appendices. There is no limit on the length of appendices, but graders are not required to read them. The text must be formatted in two columns, using 10 point Times Roman type on 12 point leading, in a text block of 6.5” by 9”. We strongly encourage you to use LaTeX and the USENIX template files, and Overleaf might be a helpful collaboration platform.

Ethics, Law, and University Policies

To defend a system, you need to be able to think like an attacker, and that includes understanding techniques that can be used to compromise security. However, using those techniques in the real world may violate the law or the university’s rules, and it may be unethical. Under some circumstances, even probing for weaknesses may result in severe penalties, up to and including expulsion, civil fines, and jail time. Our policy in the class is that you must respect the privacy and property rights of others at all times, or else you will fail the course.

Acting lawfully and ethically is your responsibility. Carefully read the Computer Fraud and Abuse Act (CFAA), a federal statute that broadly criminalizes computer intrusion. This is one of several laws that govern “hacking.” Understand what the law prohibits — you don’t want to end up like this guy. The EFF provides helpful advice on vulnerability reporting and other legal matters. If in doubt, we can refer you to an attorney.

Please review the Divison of Information Technology policies on responsible use of technology resources, as well as the code of student responsibility. As members of the university, you are required to abide by these policies.