192.044 Foundations of System and Application Security
This course is in all assigned curricula part of the STEOP.
This course is in at least 1 assigned curriculum part of the STEOP.

2024W, VU, 4.0h, 6.0EC
  • TUWEL course available from: 01.10.2024 00:00.

Properties

  • Semester hours: 4.0
  • Credits: 6.0
  • Type: VU Lecture and Exercise
  • Format: Hybrid

Learning outcomes

After successful completion of the course, students are able to understand common errors and security vulnerabilities as well as to deploy ways to detect and avoid them. Students are further able to conduct planning, testing and development of secure software applications. They gain a deeper understanding about the root causes of those errors and vulnerabilities by exploiting them themselves in a controlled environment, as well as apply principles of secure programming in practical examples. As a result, students are able to actively avoid these vulnerabilities and implement appropriate security measures in security relevant projects.

Subject of course

The lecture deals with common errors and vulnerabilities across OS and application layers as well as ways to detect and avoid them. Examples are used to highlight the general error classes and how they can be abused. Furthermore, software security testing techniques and binary analysis techniques are presented to detect vulnerabilities in applications and protocols and secure the development process.

In order to teach the subject in the most authentic way, the lecture uses a mostly "offensive approach": Security-related topics are viewed from an attacker's perspective and possible attack scenarios are shown. In practical challenges the students need to exploit previously discussed security vulnerabilities inside a controlled challenge-environment. This improves the students' understanding of the handled topics and helps them to prevent similar mistakes in own projects and allows them to actively take security measures when handling security relevant projects. 

Teaching methods

  • Lectures with slides and live demonstrations
  • Live online discussions of course topics
  • Accompanying challenges as homework assignments

Mode of examination

Immanent

Additional information

ECTS Breakdown (6 ECTS = 150 hours)

Lectures (20h)
Online Discussions, Self-studies (38h)
Challenges (90h)
Exam (2h)

Lecturers

Institute

Course dates

DayTimeDateLocationDescription
Thu14:00 - 16:0010.10.2024 - 30.01.2025FAV Hörsaal 1 Helmut Veith - INF Lecture
Foundations of System and Application Security - Single appointments
DayDateTimeLocationDescription
Thu10.10.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu24.10.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu31.10.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu07.11.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu14.11.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu21.11.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu28.11.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu05.12.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu12.12.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu19.12.202414:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu09.01.202514:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu16.01.202514:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu23.01.202514:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture
Thu30.01.202514:00 - 16:00FAV Hörsaal 1 Helmut Veith - INF Lecture

Examination modalities

Written exam and practical exercises (challenges).

 The partial achievments are:

  • 4 Challenges (each 15% of the total points)
  • 2 Exams (each 20% of the total points)

Course registration

Begin End Deregistration end
01.09.2024 00:00 31.10.2024 23:59 31.10.2024 23:59

Curricula

Study CodeObligationSemesterPrecon.Info
033 521 Informatics Mandatory electiveSTEOP
Course requires the completion of the introductory and orientation phase
033 526 Business Informatics Mandatory electiveSTEOP
Course requires the completion of the introductory and orientation phase

Literature

No lecture notes are available.

Previous knowledge

Programming experience in C/C++ and/or Python would be helpful. 

 

Preceding courses

Continuative courses

Language

English