printlogo
http://www.ethz.ch/index_EN
Welcome
 
print
  

System Security SS12

News / Recent Events

- 4.5.2012 Joel Reardon presents the paper "User-level Secure Deletion on Log-structured File Systems" at ASIACCS in Seoul, Korea.
- 16.4.2012 Aanjhan Ranganathan presents the paper "Physical-Layer Attacks on Chirp-based Ranging Systems" at WiSec in Tucson, Arizona.
- 2.4.2012 Nils Ole Tippenhauer is interviewed for students.ch regarding the risk of cyber attacks.
- 23.12.2011 Christina Pöpper is interviewed for WRS regarding the recent U.S. drone captured in Iran and the GPS spoofing claims.
- 8.12.2011 Boris Danev presents the paper "Enabling Secure VM-vTPM Migration in Private Clouds" at ACSAC in Orlando, Florida.
- 21.10.2011 Ghassan Karame presents the paper "Privacy-Preserving Outsourcing of Brute-Force Key Searches" at CCSW in Chicago, IL.
- 18.10.2011 Nils Ole Tippenhauer presents the paper "On the Requirements for Successful GPS Spoofing Attacks" at CCS in Chicago, IL.

All News / Events

All Media Coverage

Lecture: Thu, 13:15-15:00, CAB  G 11
Exercises: Fri, 10:15-12:00, CAB G 11 (must be handed in on the following Thursday, no later than 13:30)

Course responsible: Prof. Srdjan Capkun, ETHZ, (capkuns@inf.ethz.ch)

Teaching Assistants: Dr. Elli Androulaki Ramya Jayaram Masti, Nils Ole Tippenhauer (SysSec-Exercise@lists.inf.ethz.ch)

Lecture start: Thursday, 23.2.12
Lecture end: Thursday, 31.5.12
No lectures on: 12.4. (Easter),17.5 (Ascension)
Duration: 13 weeks

Exercises start: Friday, 24.2.12
Exercises end: Friday, 25.5.12
No exercises on: 6./13.4. (Easter)
12 Exercise sessions in total.

Testat: 80% of exercises. If an examination is taken, all 11 exercises will count towards 20% of the exam grade.
Exam: oral, 20 minutes
Literature recommendations: Security in Computing, Pfleeger; Security Engineering, Anderson; plus special on literature list

Oral exam schedule

The oral exams are going to take 20 minutes each. The oral exam is not necessary if you don't need a grade ("Schein").
In the case that you cannot make it to the exam for any reason, please contact the Pruefungsplanstelle (+41 44 632 20 68).

Exercise schedule and material

The solutions must be handed in on Thursdays, no later than 13:30. Exceptions to this rule are explicitely stated below. After the lecture on Thursdays the solutions to that weeks exercises will be online (below) and so we can't accept any more solutions from you.

Please be aware that these are just the preliminary contents, they might still changes!

Date Exercises and slides Note Solution
24.02.2012 Exercise1 | Slides
Due on 8th March, 2012 Solutions 1
02.03.2012   No exercise session on 2nd March, 2012.  
09.03.2012 Slides Lab report guide  
16.03.2012 Exercise 2 | Slides vulnapp_ex2.tar Solutions 2
23.03.2012 Exercise 3 | Slides   Solutions 3
30.03.2012 Exercise 4 | Slides biometrics_matchers.tar Solutions 4
20.04.2012 Exercise 5 | Slides   Solutions 5
27.04.2012 Exercise 6 | Slides ex6.tar Solutions 6
04.05.2012 Exercise 7 | Slides ex7.tar.gz Solutions 7
11.05.2012 Exercise 8 ex8.tar.gz  
18.05.2012      
25.05.2012      

Learning objectives

After this course you will be able to (1) classify and describe vulnerabilities and protection mechanisms of secure hardware (smartcards, crypto-coprocessors), operating systems and software systems (2) analyze / reason about basic protection mechanisms for modern OSs, software and hardware systems.

Content Description

The lecture covers the security of individual computer systems, including personal computers, smart cards and dedicated platforms. The course starts with considerations of cryptosystem implementations and side channel attacks, security of widely used computer platforms and tamper resistant hardware. The course continues with the examination of operating system and application related security mechanisms, from their security architectures to malware; this part also cover virtualization and sandboxing mechanism, and modern virtualization platforms. Finally, the course ends with a set of selected security topics like biometrics and computer forensics.

Lecture schedule and material

Lectures are accessible with your ETH id and password. Please use Mozilla/Firefox to download them!

Please be aware that these are just the preliminary contents, they might still changes!

Date W Who Lecture
23.02.12 1 Srdjan Capkun Background, Introduction to Side Channel Attacks pdf
01.03.12 2 Srdjan Capkun Side Channel Attacks pdf
8.03.12 3 Srdjan Capkun Physical Attacks pdf
15.03.12 4 Srdjan Capkun Physical Layer attacks continued pdf
22.03.12 5 Ghassan Karame Trusted Computing pdf
29.03.12 6 Srdjan Capkun User Authentication pdf
05.04.12 7 Srdjan Capkun OS Security pdf
19.04.12 8 Srdjan Capkun OS Security pdf
26.04.12 9 Srdjan Capkun OS Security pdf
03.05.12 10 Claudio Marforio File Systems and Secure Deletion pdf
10.05.12 11 Srdjan Capkun OS Security (see slides of 26.04)
24.05.12 12 Nathalie Weiler (Credit Suisse) Developing Large Secure Systems in Practice
31.05.12 13 Srdjan Capkun Malware
 

Wichtiger Hinweis:
Diese Website wird in älteren Versionen von Netscape ohne graphische Elemente dargestellt. Die Funktionalität der Website ist aber trotzdem gewährleistet. Wenn Sie diese Website regelmässig benutzen, empfehlen wir Ihnen, auf Ihrem Computer einen aktuellen Browser zu installieren. Weitere Informationen finden Sie auf
folgender Seite.

Important Note:
The content in this site is accessible to any browser or Internet device, however, some graphics will display correctly only in the newer versions of Netscape. To get the most out of our site we suggest you upgrade to a newer browser.
More information

© 2012 ETH Zurich | Imprint | Disclaimer | 10 May 2012
top