CS3IS16-Information Security

Module Provider: Computer Science
Number of credits: 10 [5 ECTS credits]
Terms in which taught: Spring term module
Module version for: 2017/8

Module Convenor: Dr Frederic Stahl

Email: f.t.stahl@reading.ac.uk

This module includes topics in network security and data security.

The module covers the major threats and risks that affect the security of a network and the systems that rely on it (network security), and the major threats to data in both structured and unstructured form (data security). It aims to counter these threats and to minimise risks with technical mechanisms.

Assessable learning outcomes:

On completion of this module, the student should be able to:

1. Identify ways of countering different types of threat;

2. Produce strategies to minimise risks of security breaches in a range of network environments and data storage systems;

3. Critically analyse the shortcomings of a range of security strategies;

4. Describe and apply the techniques used to penetrate a Web application;

5. Develop appropriate security policies and network architectures to minimise the threats from network intrusion;

6. Understand the different types of threat posed by different classes of hacker and by different categories of malware;

7. Describe and apply the principles of key cryptography and message digests;

8. Understand the role cryptography plays in security protocols such as SSL;

9. Apply appropriate access controls and authentication techniques at different levels;

10. Critically analyse the security and privacy issues surrounding unstructured data in a variety of different scenarios, with an in-depth focus on securing such data in Web applications;

11. Critically analyse the security and privacy issues surrounding structured data, including the techniques used to secure file storage and databases.

1. Recognise the role of privacy in computer security
2. Recognise the role of ethics in computing

Outline content:
The module comprises three parts:

Overview of information security

This part of the module provides an overview of the issues involved in information security in general, focusing on cryptography, the theories underlying computer security, authentication and access control.

Network Security

This part of the module focuses on the role the network plays in computer security, including its vulnerabilities, and the techniques that can be used to make the network secure. The part covers security issues related to general networks (e.g. port scanning, Denial of Service, etc.), the Web (e.g. SQL injection, XSS, CSRF, directory traversal attacks, etc.), and system threats in general, such as viruses, worms and Trojan horses. It also covers security controls such as firewalls, secure network protocols such as SSL and IPSec, and Intrusion Detection Systems.

Data Security

This part of the module focuses on the security of structured data (i.e. data stored in file storage systems or in databases) and unstructured data (i.e. data outside of a storage system that is manually used and transformed, and which is frequently in various states of rest, transit and use). The part covers the techniques that should be used to secure access to structured data, to prevent its accidental loss and to prevent it from being read by intruders; it also covers the techniques used to secure unstructured data, with particular emphasis made on Web applications, one of the most commonly used sources of unstructured data, yet one of the most notoriously difficult systems to secure. This part brings together the previous two parts, and shows how the theories and techniques used in Computer and Network Security can be applied to ensure the security of structured and unstructured data.

Brief description of teaching and learning methods:

There will be two, one hour lectures each week.

Contact hours:
  Autumn Spring Summer
Lectures 20
Guided independent study 80
Total hours by term 100.00
Total hours for module 100.00

Summative Assessment Methods:
Method Percentage
Written exam 70
Set exercise 30

Penalties for late submission:
The Module Convenor will apply the following penalties for work submitted late, in accordance with the University policy.

  • where the piece of work is submitted up to one calendar week after the original deadline (or any formally agreed extension to the deadline): 10% of the total marks available for the piece of work will be deducted from the mark for each working day (or part thereof) following the deadline up to a total of five working days;
  • where the piece of work is submitted more than five working days after the original deadline (or any formally agreed extension to the deadline): a mark of zero will be recorded.

  • The University policy statement on penalties for late submission can be found at: http://www.reading.ac.uk/web/FILES/qualitysupport/penaltiesforlatesubmission.pdf
    You are strongly advised to ensure that coursework is submitted by the relevant deadline. You should note that it is advisable to submit work in an unfinished state rather than to fail to submit any work.

    Length of examination:
    One 2-hour examination paper in May/June.

    Requirements for a pass:

    A mark of 40% overall.

    Reassessment arrangements:

    One examination paper of 2 hours duration in August/September - the resit module mark will be the higher of the exam mark (100% exam) and the exam mark plus previous coursework marks (70% exam, 30% coursework).

    Last updated: 31 March 2017

