CS 4803E, 8803E, Spring Semester 2000
Survey of Information Security
Instructors: Dr. Philip
Enslow , (404) 894-3187
Teaching Assistant: Rod
Peters , (404) 894-1155
Time: Tuesdays, Thursdays 9:30-11:00am
Place: CCB Room 101
Text::
Security in
Computing by Charles P. Pfleeger,
Prentice Hall, 1997.
Description: Complete examination of the issues and problems in
providing security for information processing
systems - secure
operating systems and applications, network security, cryptography,
security protocols, etc.
MISSING HOMEWORK ASSIGNMENTS LINK
Team Assignments:
Team #1 
Buyer, Julie, Jensen, Peter and Lunz, Jason.
Team #2  Farahmand, Fariborz, Khalaf, Hani and Preble, Adam.
Team #3 
EL Sallah, Mohd Wajih Abdul-Jalil, Hsieh, Hung-Yun and Shillingburg,
Rebecca.
Team #4  Molavi, Darius, Nettles, Ladonna and Razzaque, Aqib.
Team #5  Lemons, Desiree, Liu, Jian and Mitchell, Brian.
Team #6  Dixon, Robert, Grandhige, Hemanth and Wright, Gregory.
Team #7  Griffin, Shanna, Hicks, Jeffrey and Nowatkowski,
Michael.
Reading Assignments:   (subject to change)
- For 01/13/00: Chap. 1 pgs. 1 - 20.
- For 01/18/00: Chap. 2 pgs. 21 - 46.
- For 01/20/00: Chap. 2 continued.
- For 01/25/00: Chaps. 2 & 3 pgs. 47 - 82.
- For 01/27/00: Chap. 3 pgs. 82 - 125.
- For 02/01/00: Chap. 4 pgs. 126 - 159.
- For 02/03/00: Chap. 4 pgs. 159 - 175.
- For 02/08/00: Chap. 5 pgs. 176 - 207.
- For 02/10/00: Chap. 5 pgs. 207 - 227.
- For 02/15/00: Chap. 5 pgs. 207 - 227.
- For 02/17/00: Chap. 6 pgs. 228 - 268.
- For 02/22/00: Chap. 6 pgs. 228 - 268.
- For 02/24/00: Chap. 6 pgs. 269 - 306.
- For 02/29/00: Chap. 7 pgs. 306 - 335.
- For 03/02/00: Guest Speaker: Peter Wan
- For 03/14/00: Chap. 8 pgs. 336 - 376.
- For 03/16/00: Chap. 9 pgs. 377 - 422.
- For 03/21/00: Guest Speaker: Jim Butler
- For 03/23/00: Chap. 9 pgs. 377 - 422.
- For 03/28/00: Network Security cont.
- For 03/30/00:Chap. 9 pgs. 422 - 446.
- For 04/04/00: Network Security cont.
- For 04/06/00: Network Security cont.
- For 04/11/00: Chap. 10 pgs. 447 - 491.   
HW DUE: Identifying Paths of System Penetration
- For 04/13/00: Chap. 11 pgs 492 - .
- For 04/18/00: Chap. 11 cont.
- For 04/20/00: Chap. 11
cont.             HW
DUE: Acceptable Use Practices
- For 04/25/00: TBD
- For 04/27/00: Final
Project Due
Links to Security Information on the Web: (student
submissions)
Week of 1/23/00:
- Cyphers by Ritter (M.
Nowatkowski)
- RSA
Panelist Debate on Cryptography (R. Shillingburg)
- Cyber
Law Journal (B. Dixon)
- DES
is Not Secure (H. Hsieh)
- Chaffing and
Winnowing: Confidentiality without Encryption (A. Preble)
- GSM Cell
Phone Authentication Protocol (P.Jensen)
- "Tales of
the Encrypted" (D. Molavi)
- Advanced
Encryption Standard Development Effort (G. Wright)
- Beginner's
Guide to Crypto (S. Griffin)
- Digital
Signatures and and Public Key Cryptosystems (D. Lemons)
- Java
Security (H. Grandhige)
- Cryptography is
Harder
than it Looks (J. Buyer)
- Full Disclosure -
PacketStorm Security (J. Lunz)
Week of 1/30/00:
- AspEncrypt's
Crypto 101 (R. Shillingburg)
- Forum on Risks - Risk
Digest (B.
Dixon)
- Hackers
Attack AOL IM Accounts (F. Farahmand)
- The Hacker Quarterly (J. Buyer)
- SecurityFocus (M.
Nowatkowski)
- Internet
Explorer Security Area IE 4.0 (J. Liu)
- Windows
NT Info Security (G. Wright)
- Cryptanalysis
of SkipJack (A. Razzaque)
- Information
warfare: A two-edged Sword (J. Buyer)
- LAN to
DSL Uplink Security Risks (J. Lunz)
- The Risks of Key
Recovery, Key escrow, and Trusted Third-Party Encryption (H. Hsieh)
- IPSEC.com - an
inforsecurity site (D. Molavi)
Week of 2/6/00:
- Nist Pubs - A
Guide to
Selecting Anti-virus Tools and Techniques (R. Shillingburg)
- What
is a virus and how does work (R. Shillingburg)
- The Terrorism
research Center, Inc. (A. Preble)
- CNN -
Hackers (H. Khalaf)
- A Security Glossary
of Terms (S. Griffin)
- InfoSec and InfoWar Portal (G.
Wright)
- Navigator's
Encryption Scheme Gets Broken (D. Lemons)
- IEEE
Electronic
Newsletter on Security and Privacy (B. Mitchell)
- George Washington Univ.
Class Page on InfoSec (H. Grandhige)
- Micorsoft
Windows 2000 security Issues (F. Farahmand)
- The Virus
Wars (real audio file) (M. Nowatkowski)
- Attack
Trees (A. Razzaque)
- A Computer Security Index on the Web
(P. Jensen)
- The Cryptography
FAQ (P. Jensen)
- Cyber-attacks batter
Web Heavyweights (J. Buyer)
- Center for
Information Technology - NIH (J. Lunz)
- Lucent
Personalized Web Assistant (B. Dixon)
- Intruder
Detection List (S. Griffin)
Week of 2/13/00:
- Computer Virus Myths
and Hoaxes (A. Hsieh)
- Sun Microsystems'
Internet Security Tutorial (R. Shillingburg)
- Random
Number Generators (M. Nowatkowski)
- Network Security Buyer's
Guide (B. Mitchell)
- Computer
Viruses and Data Protection (D. Lemons)
- Linux
Privacurity (J. Liu)
- Phil Zimmerman - The
Creator of PGP (D. Molavi)
- Mixed
Signals Over Encryption Technology (H. Khalaf)
- Gelb Organization - Papers on
Firewalls (G. Wright)
- Three New
Attack Strategies Disclosed (F. Farahmand)
- Article
on Virus W32.FunLove.4099 (J. Buyer)
- Hiding Crimes in
Cyberspace (A. Razzaque)
- Cryptographic
Software Solutions and How to Use Them (J. Lunz)
- Virus Database (H. Grandhige)
- Covert
Channels (P. Jensen)
- Phrack.com (B. Dixon)
- Steganography
(with related links) (A. Preble)
- Choosing
Passwords (S. Griffin)
- Open
Source Security (A. Hsieh)
Week of 2/20/00:
- The
Resurrecting Duckling: Security Issues for Ad-hoc Wireless
Networks (B. Dixon)
- Opinion:
Is Free Software Communist? (H. Khalaf)
- Practical UNIX &
Internet Security (J. Liu)
- Symantec
Antivirus Center (D. Molavi)
- Distributed Denial of
Service - Dave Dittrich (M. Nowatkowski)
- Computer
Security Awareness - A course (R. Shillingburg)
- Basic
Information on Computer Viruses (B. Mitchell)
- Wipe Out
Viruses (D. Lemons)
- Trojan Horses,
Worms, and Viruses (J. Buyer)
- Java
and ActiveX Security Issues (A. Razzaque)
- An
Essay on Trust (P. Jensen)
- Network
Vulnerabilities - Cisco Secure Consulting Report (P. Jensen)
- Open
SSH (J. Lunz)
- WWW Security Issues (G.
Wright)
- Center for Education
and Research in Information Assurance and Security (S. Griffin)
- NTP
Security Model (H. Grandhige)
- Research
Challenges in Operating System Security (H. Hsieh)
Week of 2/27/00:
- Paul Judge's
efforts on Security related topics (R. Shillingburg)
- Security
Architecture for the Internet Protocol (D. Molavi)
- Computer
and Network Security Reference Index (D. Lemons)
- Unix and Internet Security Info
Page (B. Mitchell)
- Secure
Linux Project at Univ. of Utah (L. Liu)
- Network World Fusion (M.
Nowatkowski)
- Peter
Galvin's Unix OS Security Tutorial (G. Wright)
- Freshmeat.com - Linux
Information (A. Preble)
- Redhat's
Linux Security Site (A. Razzaque)
- NSI - Virus
Information (J. Buyer)
- Insecure.org
- Murphy's Law for Computer Security (H. Hsieh)
- Cellular Message
Encryption Algorithm (J. Lunz)
- Computer
Viruses: Background, Safe Computing Practices, and Recommended Antiviral
Software (S. Griffin)
Week of 3/12/00:
- Defending
Against Sequence Number Attacks (D. Molavi)
- Security
Issues Related to Database Access from the Web (R. Shillingburg)
- Security Enabled E-business (J. Liu)
- NSI Threat Listing
(F. Farahmand)
- ADSL Security Issues
(F. Farahmand)
- Nortel
Networks ADSL Security Page (F. Farahmand)
- Open
Systems Security Issues (F. Farahmand)
- Securing a UNIX
System (A. Razzaque)
- Network Security Information
(D. Lemons)
- The Information Security News
Daily (B. Mitchell)
- International Federation for
Information Processing - Database Security (M. Nowatkowski)
- X Windows
Security (S. Griffin)
- Kevin Mitnick and Tsutomu
Shimora - A description of a cyberattack (H. Grandhige)
- ACLU.org -
Echelon Watch (H. Hsieh)
- COMMSEC.com - PGP
Information Site (J. Buyer)
Week of 3/19/00:
- A
Network Security Tutorial (R. Shillingburg)
- P3P Implementations
and Privacy Negotiation Services (J. Liu)
- Privacy Act of
1974 (D. Lemons)
- The Unofficial
Tempest Homepage (D. Molavi)
- Cryptographic
Service Providers (A. Preble)
- Innovative Security
Products Newsletter (B. Mitchell)
- Differential
Power Analysis (F. Farahmand)
- Center for Information
Technology Standards - Public Key Infrastructure Standardization Home
Page (M. Nowatkowski)
- Network Security
Planning (G. Wright)
- Java
Security - MSIE (S. Griffin)
- A Secure Linux Distribution
Project (B. Dixon)
- Cybercops
(H. Khalaf)
- Free
ISP and why it will cost you dearly (H. Khalaf)
- IEEE 1363
Standard for PK Cryptography (H. Grandhige)
- Hacking
Tools and Solutions to Avoid being Hacked (A. Razzaque)
- Anticode.com (J. Buyer)
- Northern
Light Technology - Computer Privacy (H. Hsieh)
Week of 03/26/00:
- Intrusion
Detection Pages (R. Shillingburg)
- Risks of the Passport
Single Signon Protocol (B. Dixon)
- Stealth Programs - Iopus.com (D.
Molavi)
- Information and Privacy -
Commisioner/Ontario (D. Lemons)
- Apache Cross
Site Scripting Problem (J. Liu)
- AntiOnline.com (B. Mitchell)
- Federal Computer
Week (M. Nowatkowski)
- Looksmart.com
- security, terrorism, cybercrimes, etc. (F. Farahmand)
- Customer-Data
Software That We Could Do Without (H. Khalaf)
- Secure Internet Programming
Laboratory (A. Preble)
- Red
Hat Linux Security Advisories (G. Wright)
- Securing NIS
Networks (S. Griffin)
- Webroot.com - Internet
Privacy Software (J. Buyer)
- Biometrics
(H. Hsieh)
- Security Networking
Tools for the Unix Environment (A. Razzaque)
Week of 4/02/00:
- Human
Identification in Information Systems (J. Buyer)
- Intruder
Detection (H. Khalaf)
- The EPIC
Cookies Page (R. Shillingburg)
- ACM
Crossroads - Security Techniques (J. Liu)
- Electronic Privacy Information Center
(D. Lemons)
- U.S. Navy - Information
Security (D. Molavi)
- Zeuros
Network Solutions - Firewalls (B. Mitchell)
-
The Unix Secure Programming FAQ (A. Preble)
- TSSI - Custom Security Solutions
(G. Wright)
- Viruses
(F. Farahmand)
- Model
Security Policies (S. Griffin)
- Fishnet Security
(M. Nowatkowski)
- PKI Links
Page (H. Hsieh)
- NT Security
Advisories (A. Razzaque)
Week of 4/09/00:
- IT Security Cookbook (R.
Shillingburg)
- CCIPS - Computer Crime and
Intellectual Property Section of the Dept. of Justice (M. Nowatkowski)
- Denial
of Service Attack Tools (D. Molavi)
- Net
Privacy Violators (H. Khalaf)
- Famous
Hackers and Crackers (F. Farahmand)
- SecureLab.com (J. Liu)
- Public Key
Infrastructures and Standards (B. Mitchell)
- Software Patents Tangle
the Web (D. Lemons)
- Computer Crime Laws and Penalties (A. Razzaque)
- TripWireSecurity.com
(G. Wright)
- Theory of Cryptography
Library (S. Griffin)
- IETF
IPSec Page (B. Dixon)
- Director of
Computer Security FAQs (B. Dixon)
- Internet
Taxes (D. Lemons)
- The (EBX) Electronic Book
Exchange Specification (H. Hsieh)
- 3-Part
Password (J. Buyer)
Week of 4/16/00:
- Secure
Sockets Layer (R. Shillingburg)
- Zonelab's Firewall
Software Site (J. Liu)
- NSA - Information Systems
Security Organization (D. Molavi)
- Beyond
Concern: Understanding Net Users' Attitudes About Online Privacy (D.
Lemons)
- Picking
Up the Digital Check (H. Khalaf)
- Encryption
Methods (F. Farahmand)
- Java Security
Hotlist (B. Mitchell)
- Bruce
Schneier - Cryptorhythms (P. Jensen)
- Crypto-Gram
Archive (P. Jensen)
- Identity
Theft and Fraud (A. Razzaque)
- Credit
Fraud (G. Wright)
- CERT Coordination
Center FAQs (S. Griffin)
- The
Children's Online Privacy Protection Rule (B. Dixon)
- Declassified
NSA Documents (H. Grandhige)
- Clipper
Chip and the Clinton ADministration (H. Grandhige)
- FAS.org - useful
security links (J. Buyer)
Week of 4/23/00:
- Electronic
Voting (H. Hsieh)
- Survivability
Blends Computer Security with Business Risk Management (R.
Shillingburg)
- The
Cookie Debate D. Lemons)
- A
Secure Client-Server Application? (M. Nowatkowski)
- Naval
Postgraduate School - CS4601 Computer Security (M. Nowatkowski)
- The Computer Security Insitute (D.
Molavi)
- Designing
Secure Software (L. Jian)
- Center For Education and
Research in Information Assurance and Security (B. Mitchell)
- Once
Again, technology Is Outrunning Privacy (H. Khalaf)
- Peter G.
Neumann's Web page (P. Jensen)
- RSA FAQs (A.
Preble)
- NIST AES
Homepage (A. Preble)
- Vulnerable
Library Calls (A. Preble)
- FreeVSD.org (A. Preble)
Course Bibliography:
- Radcliff, Deborah. "Diary of a Hack Attack". In Network World, January
10, 2000, pgs. 42 and 43.
- Simons, John. "How an FBI Cybersleuth Busted a Hacker
Ring". In
Telecom Digest, October, 1999.
- Dunn, Ashley. "Self-Spreading Viruses Represent Growing Threat to Home
PCs". In the Atlanta Journal-Constitution, October 10, 1999.
- Lawton, George. "Explorer Worm Targets Networks, Deletes Data". In
Computer, August, 1999, pgs. 15 - 17.
- Anderson, Ross. "How to Cheat at the Lottery (or Massively Parallel
Requirements Engineering)", University of Cambridge Computer Laboratory,
pgs. 1 - 13.
- Thompson, Ken. "Reflections on Trusting Trust", Communications of the
ACM, Vol. 27, No. 8, August 1984, pgs. 761 - 763.
- Harris, B. and Hunt, R. "TCP/IP Security Threats and Attack Methods",
Computer Communications, Vol. 22, 1999, pgs. 885 - 897.
Contact Information:
Prof. Philip
Enslow , (404) 894-3187
Office hours: Tues, Thurs 11am-12pm CCB 269 (thru Room
264)
enslow@cc.gatech.edu
TA: Rod Peters
, (404) 894-1155
Office hours: MWF 10:00am-11:00am CCB 153
repeters@cc.gatech.edu
Last Modified: Jan. 11, 2000