|
|||||||||||
News / Recent Events
- 4.5.2012 Joel Reardon presents the paper "User-level Secure Deletion on Log-structured File Systems" at ASIACCS in Seoul, Korea.
- 16.4.2012 Aanjhan Ranganathan presents the paper "Physical-Layer Attacks on Chirp-based Ranging Systems" at WiSec in Tucson, Arizona.
- 2.4.2012 Nils Ole Tippenhauer is interviewed for students.ch regarding the risk of cyber attacks.
- 23.12.2011 Christina Pöpper is interviewed for WRS regarding the recent U.S. drone captured in Iran and the GPS spoofing claims.
- 8.12.2011 Boris Danev presents the paper "Enabling Secure VM-vTPM Migration in Private Clouds" at ACSAC in Orlando, Florida.
- 21.10.2011 Ghassan Karame presents the paper "Privacy-Preserving Outsourcing of Brute-Force Key Searches" at CCSW in Chicago, IL.
- 18.10.2011 Nils Ole Tippenhauer presents the paper "On the Requirements for Successful GPS Spoofing Attacks" at CCS in Chicago, IL.
NOTE: ALL COURSE MATERIAL HAS BEEN TAKEN OFFLINE AS OF JULY 2010. Please contact the assistants if you require lecture slides or have other questions
The webpage of System Security SS09 is archived here.
Lecture: Thu, 13:15-15:00, CAB G 11
Exercises: Fri, 10:15-12:00, CAB G 11 (must be handed in on the following Thursday, no later than 13:30)
Course
responsible: Prof. Srdjan Capkun, ETHZ, (capkuns@inf.ethz.ch)
Teaching Assistants: Boris Danev, Nils Ole Tippenhauer
Lecture start: Thursday, 25.2.10
Lecture end: Thursday, 3.6.10
No lectures on: 8.4., (Easter),13.05 (Ascension)
Duration: 13 weeks
Exercises start: Friday, 5.3.10
Exercises end: Friday, 28.5.10
No exercises on: 2./9.4. (Easter)
11 Exercise sessions in total.
Testat: 80% of exercises. If an examination is taken, exercises will count towards 20% of the exam grade.
Exam: oral, 20 minutes
Literature recommendations: Security in Computing, Pfleeger; Security Engineering, Anderson; plus special on literature list
The oral exams are going to take 20 minutes each. The oral exam is not necessary if you don't need a grade ("Schein").
The exam will take place in CNB F 102.2. In the case that you cannot make it to the exam for any reason, please contact the Pruefungsplanstelle (+41 44 632 20 68).
The solutions must be handed in on Thursdays, no later than 13:30. Exceptions to this rule are explicitely stated below. After the lecture on Thursdays the solutions to that weeks exercises will be online (below) and so we can't accept any more solutions from you.
Please be aware that these are just the preliminary contents, they might still changes!
| Date | Exercises and slides | Note | Solution |
| 05.03.2010 | Exercise 1 | Slides 1 | Solutions 1 | |
| 12.03.2010 | Exercise 2 | Slides 2 | Solutions 2 | |
| 19.03.2010 | Lab Guide | Slides lab |
Solution lab |
|
| 26.03.2010 | Exercise 3 | Slides 3 |
dumped image |
Solutions 3 |
| 16.04.2010 | Exercise 4 | Slides 4 | vulnapp_ex4.tar | Solutions 4 |
| 23.04.2010 | Exercise 5 | Slides 5 | Solutions 5 | |
| 30.04.2010 | No Exercise Session | ||
| 07.05.2010 | Exercise 6 | Slides 6 | biometric_matchers.tar | Solutions 6 |
| 14.05.2010 | Exercise 7 | Slides 7 | eve.image.tar.gz | Solutions 7 |
| 21.05.2010 |
Exercise 8 | Slides 8 |
Solutions 8 | |
| 28.05.2010 | Exam Preparation |
After this course you will be able to (1) classify and describe vulnerabilities and protection mechanisms of secure hardware (smartcards, crypto-coprocessors), operating systems and software systems (2) analyze / reason about basic protection mechanisms for modern OSs, software and hardware systems.
The lecture covers the security of individual computer systems, including personal computers, smart cards and dedicated platforms. The course starts with considerations of cryptosystem implementations and side channel attacks, security of widely used computer platforms and tamper resistant hardware. The course continues with the examination of operating system and application related security mechanisms, from their security architectures to malware; this part also cover virtualization and sandboxing mechanism, and modern virtualization platforms. Finally, the course ends with a set of selected security topics like biometrics and computer forensics.
Lectures are accessible with your ETH id and password. Please use Mozilla/Firefox to download them!
Please be aware that these are just the preliminary contents, they might still changes!
| Date | W | Who | Lecture |
| 25.02.10 | 1 | Srdjan Capkun |
Background, Introduction to Side Channel Attacks (updated 03.03.2010) |
| 04.03.10 | 2 | Srdjan Capkun |
Side Channel Attacks (updated 07.03.2010) |
| 11.03.10 | 3 | Srdjan Capkun | Physical Attacks |
| 18.03.10 | 4 | Aurelien Francillon / Srdjan Capkun |
Hardware based Attestation (updated 24.03.2010) |
| 25.03.10 | 5 | Srdjan Capkun |
Software based Attestation Operating Systems I: Security Principles |
| 01.04.10 | 6 | Nathalie Weiler | Operating Systems II: Windows Vista case study |
| 15.04.10 | 7 | Srdjan Capkun | Operating Systems III: Authentication, Access Control, Linux Security (updated 28.04) |
| 22.04.10 | 8 |
Srdjan Capkun / Boris Danev / Nils Tippenhauer |
Biometrics |
| 29.04.10 | 9 | Srdjan Capkun | Continuing with Linux Security |
| 06.05.10 | 10 | Nathalie Weiler | Developing Large Secure Systems in Practice |
| 20.05.10 | 11 | Srdjan Capkun | Malware (I) |
| 27.05.10 | 12 | Srdjan Capkun | Malware (II) |
| 03.06.10 | 13 | Srdjan Capkun |
Taint Analysis, reading material |
Wichtiger Hinweis:
Diese Website wird in älteren Versionen von Netscape ohne
graphische Elemente dargestellt. Die Funktionalität der
Website ist aber trotzdem gewährleistet. Wenn Sie diese
Website regelmässig benutzen, empfehlen wir Ihnen, auf
Ihrem Computer einen aktuellen Browser zu installieren. Weitere
Informationen finden Sie auf
folgender
Seite.
Important Note:
The content in this site is accessible to any browser or
Internet device, however, some graphics will display correctly
only in the newer versions of Netscape. To get the most out of
our site we suggest you upgrade to a newer browser.
More
information