15/02/2016 | Intro to course | netsec_intro.pdf01-netsec_sec_foundations.pdf | Reflections on Trusting Trust |
17/02/2016 | Security of Network protocols - IP | 02-netsec_network_aspects-ip.pdf | Added traceroute as explained in class (slide 46). Specified L2 address in slide 21. |
22/02/2016 | Security of Network protocols - TCP | 02-netsec_network_aspects-tcp.pdf | Added info on [.] notation in tcpdump. |
24/02/2016 | Security of Net. protocols - Application Layer | 02-netsec_network_aspects-applayer.pdf | demo_scripts.tar.gz |
29/02/2016 | Crypto | 03-netsec_crypto.pdf | http://www.acm.org/media-center/2016/march/turing-award-2015 |
02/03/2016 | Vulnerabilities & attack surfaces | 04-netsec_vulnerabilities.pdf | Arora-Impact of vulnerability disclosure and patch availability, Miller-The legitimate vulnerability market, http://phrack.org/issues/49/14.html |
07/03/2016 | Vulnerabilities (b) | 04-netsec_vulnerabilities-b.pdf | http://onlinelibrary.wiley.com/doi/10.1002/asi.20779/full; Moore-Current state of phishing attack and defence; Acquisti-Infosec attitudes and behavior; Lab activities and topics (subject to change until wednesday the 9th) |
09/03/2016 | Vulnerability scoring | 05-netsec_cvss_intro.pdf | CVSS v3 Metric Definitions; Final Lab Topics |
14/03/2016 | Vuln Scoring class exercise | 06-netsec_cvss_exercise.pdf | |
16/03/2016 | Attacks - malware | 07-netsec_malware.pdf | http://www.sciencedirect.com/science/article/pii/S1389128612003568; Stone-Gross - Analysis of a botnet takeover |
21/03/2016 | Attacks - web attacks | 08-netsec_webattacks.pdf | kanich_-_spamalytics.pdf; kotov_-_exploit_kits.pdf; provos-_iframes_point_to_us.pdf; studer-_coremelt.pdf; argyraki_-_network_capabilities.pdf |
23/03/2016 | Attacks - economy and infrastructure | 09-netsec_cybercrime_economy.pdf | gier-manufacturing_compromise.pdf; thomas-framing_dependencies_underground_commoditization.pdf; allodi-then_and_now.pdf (16Mb PDF) |
28/03/2016 | Easter (suspended) | | |
30/03/2016 | Defensive tech - Network defense Sys hardening - Auth+Static FW | 10-netsec_syshardening-fw.pdf | |
04/03/2016 | Defensive tech - Network defense Sys hardening - Stateful/App FWs | 11-netsec_syshardening-appfw.pdf | firewall_configuration_errors.pdf |
06/04/2016 | Classes suspended | | |
11/04/2016 | IDSs + Vuln Mngmt + Lab notes | 12-netsec_syshardening_vuln_mngmt.pdf Lab: 12b-netsec_lab_notes.pdf | allodi-comparing_vulnerability_exploits.pdf; axelsson-base_rate_fallacy.pdf; nayak-some_vulnerabilities_are_different_than_others.pdf; Sections 1-3 only: allodi-heavy_tails_of_vuln_exploitation.pdf |
13/04/2016 | Malware Lab: exploit kits | 13_-_netsec_ekits_lab.pdf [53MB] | |
18/04/2016 | Privacy in networks | 14-netsec_privacy.pdf | arnbak-httpsmarketcollapse.pdf |
20/04/2016 | Student Labs - T2: DoS attacks | MORNING session - AFTERNOON session | Morning report: G5 - Afternoon report: G6 |
25/04/2016 | Liberazione (suspended) | | |
27/04/2016 | Student Labs - T3: MitM | MORNING session - AFTERNOON session | Morning report: G4 - Afternoon report: G1+Afternoon attachments: G1 |
02/05/2016 | Student Labs - T4 DNS cache poisoning | MORNING session - AFTERNOON session | click to get proper image orientation Morning report. - Afternoon report |
04/05/2016 | Student Labs - T5 Kaminsky Attack | MORNING session - AFTERNOON session | Morning report - Afternoon report |
09/05/2016 | Student Labs - T6 XSS + phishing +CSRF | MORNING: session moved to 12/05/2016 - AFTERNOON session | Afternoon report |
11/05/2016 | Student Labs - T7 BoF | MORNING session - AFTERNOON session | Morning report -Afternoon report |
12/05/2016 | Student Labs - EXTRA T6 XSS + phishing +CSRF | Extra session (substitues 09/05/16 morning session) | Extra Session report |
16/05/2016 | Student Labs - T8 SQLi + defenses | MORNING session - AFTERNOON session: 1, 2, 3 | Morning report -Afternoon report |
18/05/2016 | Student Labs - T9 FW Stateless | MORNING Session - AFTERNOON Session | Morning report - Afternoon report |
23/05/2016 | Student Labs - T10 FW Stateful | MORNING Session - AFTERNOON Session +cheatsheet | Morning report Afternoon report |
25/05/2016 | Student Labs - T11 NIDS - Snort | MORNING Session - AFTERNOON Session | Morning report - Afternoon report |
30/05/2016 | Student Labs -T12 NIDS - Bro | MORNIG Session - AFTERNOON Session | Afternoon report |