Error message
User error : Failed to connect to memcache server: druportbe01:11211 in dmemcache_object() (line 415 of /production/drupal/dim_prod/drupal/d7cl4/prod/unich/releases/7/web/sites/all/modules/contrib/memcache/dmemcache.inc ).
Single discipline educational activity
Course Sheet Academic Year of enrolment:
Professor and Collaborators:
Hours of classroom activity:
Prerequisites:
Basic knowledge of computer science and mathematics.
Objectives
Contents Security risks.Threats and countermeasures.Symmetric and asymmetric cryptography.
Use of cryptography in security (e.g. authentication, confidentiality, integrity, non-repudiation). Other uses of cryptography (e.g. blockchain).Operating systems and network security.Data and software security.
Extended Syllabus Security risks. Threats and countermeasures.
Cybercrimine. Deep and Dark Web.
Physical and social security.Risks and vulnerabilities classification.
Digital forensics. Legal and normative aspects.Symmetric and asymmetric cryptography.
Key-exchange problems.
Key Distribution Centers approaches. Kerberos.
PKI-based approaches. CRLs and OCSP. Use of cryptography in security (e.g. authentication, confidentiality, integrity, non-repudiation).
X.509 PKI certificates.
Digital signatures.
Certified Email (PEC).
QES (Qualified Electronic Segnature). PKCS#7
Limits of cryptography. Quantum cryptography.Other uses of cryptography (e.g. blockchain).
Blockchain and Distributed Ledger.
Bitcoin and other cryptocurrencies.
Smart contracts.
Operating systems and network security.
User management and authorization.
Password and identity management.
SPID (Sistema Pubblico di Identità Digitale).TCP/IP networks.
Network attacks (spoofing, flooding, poisoning, denial of service).
Firewall and proxy.
Virtual Private Networks (VPN) using IPSec and SSL.
Web and cloud security. HTTPS.
Data security.
Backup types and strategies.
Digital preservation.
Business continuity and disaster recovery.
Privacy and user profiling.
EU GDPR (General Data Protection Regulation).
Software security.
Malicious software (virus, worm, spyware, trojan, ransomware, etc.).
Buffer overflow.
SQL injection and Cross-site scripting (XSS)
Security testing.
Recommended Bibliography - Lecture notes
- Crittografia pratica. Bruce Schneier, Niels Ferguson. Apogeo.
- Introduction to computer security. Matt Bishop. Addison-Wesley
- Sicurezza delle reti: Applicazioni e standard – 3/Ed. William Stallings. Pearson Education
- Il Futuro della Cybersecurity in Italia: Ambiti Progettuali Strategici. Laboratorio Nazionale di Cybersecurity CINI - Consorzio Interuniversitario Nazionale per l’Informatica. A cura di: Roberto Baldoni, Rocco De Nicola, Paolo Prinetto.
Methods of Provision
Teaching Methods Oral lessons and seminars.Case studies. Practical sessions in the computer laboratory.
Evaluation methods Verification of learning:
Knowledge and ability to understand.The learning outcomes can be assessed using two alternative methods.The first method consists in delivering one or more written assignments containing answers to both theoretical and empirical questions.Next, there will be an optional oral interview for assessing the basic and theoretical knowledge (on student and teacher request).The marks are out of 30 and will be based on the evaluation of writings and, possibly, on the oral interview. The second method consists in replacing one or more written assignments with a (group or individual) project work with written (and possibly software) deliverables.Next, there will be an oral interview for assessing the student contribution to the project work as well as basic and theoretical knowledge.The marks are out of 30 and will be based on the evaluation of writings and, possibly, on the project work and the oral interview.Ability to apply knowledge and comprehension.During the exam, it will be possible to assess the ability of the student to applying his/her knowledge of security threats and countermeasures for facing practical situations.