CSE 4482

Computer Security Management:
Assessment and Forensics

Fall, 2013


  Lecture Schedule:      Tuesday  19:00 - 22:00,  ACW 002

  Instructor:                 Natalija Vlajic (vlajic @ cs.yorku.ca)

  Office Hours:              Tue and Thu  11:00 - 12:00 (CSEB 2047)
                                     and by appointment
  TA:                             Dusan Stevanovic (dusan @ cse.yorku.ca)

Required Reading
Important Dates
T, Sep. 10
Introduction: Information Security, Threats, Attacks

T, Sep. 17
Management of Information Security,
Security Organization,
Security Policy

Assignment 1
Due Date:  Oct 1, 2013 (in class)
T, Sep. 24
Risk Assessment and Risk Management (part 1)

T, Oct. 1
Risk Assessment and Risk Management (part 2)
Protection Mechanisms: Access Control (part 1)

Opnet IT Guru Lab 1
Due date:  Oct 22 (in class)
T, Oct. 8
Protection Mechanisms: Access Control (part 2)
Protection Mechanisms: Firewalls (part 1)

T, Oct. 15
Midterm - location: Lassonde (LAS) 3033 !
Protection Mechanisms: Firewalls (part 2)

T, Oct. 22
Guest Lecture
    M. Lungu - Project Manager Cryptographic Services, RBC
    P. Ndebele - Senior IT Auditor, TD Bank
    W. Rajibi - Chief Security Architect for Info. Management, IBM
location: Lassonde (LAS) 3033 !

T, Oct. 29

Opnet IT Guru Lab 2
Due date:  Nov 12 (in class)
T, Nov. 5
Protection Mechanisms: IDPS

T, Nov. 12
Protection Mechanisms: Scanning and Analysis Tools

Assignment 2
Due date:  Nov 26 (in class)
T, Nov. 19
Law and Ethics
Introduction to Computer Forensics

T, Nov. 26
Forensics in Windows

Assignment 3
Due date:  TBD

T, Dec 3
Student Presentations

Final Examination:  Sunday, Dec 15 - 7pm, VH 3006

   Software Tools:

Basic Tools:
Ping, Traceroute, Whois, Netstat, Nmap
Packet Sniffers:
Vulnerability Scanners:
Intrusion Detection Tools:
Password Cracker:
Cain and Abel, LCP
Forensic Tools:
Wireless Sniffers:

     Term Project:

As a part of this course, students will be required do a term project, and thus execute some limited independent research in the area of computer security. Term projects will complement and extend the lecture material. The list of possible project topics, together with up 2-3 starting references, can be accessed from: List of project topics, F 2013.

Each project team will consist of 2 students. Students themselves are responsible for finding their project partner, selecting a project topic, and then registering both (group and topic) with the course instructor before September 24 (through e-mail). The final allocation of project topics will be done on the 'first-come-first-served' basis.

The project work will be assessed through
1)  10-page long written report submitted no later than November 19 (single spacing, 11 point font size),
2)  15-min oral presentation on November 26.

The project assessment will be based on the following criteria:
- written report (content, structure, syntax, proper citations, reference section, etc.)  - 50%
- oral presentation (clarity and general understanding) - 50%

   Course Description:
This course introduces the student to the fundamental concepts of information security: confidentiality, integrity, availability, authentication, auditing, information privacy, legal aspects. Other more advanced topics covered in the course include: development of security policies, access control, risk management, incident response, inappropriate insider activity, ethics.


Any 12 credits at the 3000-level.

