Security and Privacy in Cyber Systems
IERG 5310 · First Term 2026–27
This course examines the security and privacy of large-scale networked systems, from the core Internet protocols up to the applications built on them. Topics include the security of TCP/IP, DNS, and interdomain routing; TLS and the Web public-key infrastructure; web and email security; authentication and identity; denial-of-service attacks and botnets; firewalls, intrusion detection, and network censorship; anonymity systems and Tor; end-to-end encrypted messaging; and blockchain security.
Each week, we start with the basic principles and classic results behind the week's topic, then read and discuss the latest advances in that direction. No prior background in security is assumed.
Security and privacy are multi-disciplinary by nature. Students from various backgrounds are equally welcome. If you are unsure whether the course is a fit, please get in touch.
Course Information
- Instructor
-
Office hours: Thursday 3:30–4:30 PM, or by appointment
- Teaching Assistant
TBA
- Lectures
-
Thursday 12:30–3:15 PM
Ho Sin-Hang Engineering Building 801
- Communication
We use Piazza for announcements, readings, and discussion.
- Schedule
-
Weekly topics and readings are listed on the schedule page.
- Grading
-
50% Final project
30% Reading presentation
20% Class participation
Resources
No textbook is required. If you would like additional references, these are good ones:
- Computer Security and the Internet: Tools and Jewels by Paul C. van Oorschot — freely available from the author
- Security Engineering by Ross Anderson — third edition freely available from the author
- Computer Networking: A Top-Down Approach by Jim Kurose and Keith Ross — for networking background; the authors' video lectures are free
- Cryptography Engineering by Niels Ferguson, Bruce Schneier and Tadayoshi Kohno
For reading papers, presenting them, and writing up your project:
- How to Read a Paper. S. Keshav.
- How to Give a Great Research Talk. Simon Peyton Jones. Microsoft Research, 2016.
- How to Write a Great Research Paper. Simon Peyton Jones. Microsoft Research, 2016.
Academic Honesty and Plagiarism
Attention is drawn to University policy and regulations on honesty in academic work, and to the disciplinary guidelines and procedures applicable to breaches of such policy and regulations. Details may be found at www.cuhk.edu.hk/policy/academichonesty (CUHK) and www.erg.cuhk.edu.hk/erg/AcademicHonesty (Engineering Faculty).
Use of Generative AI Tools in Learning and Assessment
Use of AI tools is allowed with no acknowledgement. Students are reminded to learn and use AI tools responsibly and ethically, and to be aware of their limitations.
Feedback for Evaluation
Students are encouraged to give comments and make suggestions using the following channels:
- There are two course evaluations — one before the mid-term, and one at the end of the course. This is a formal channel for students to rate the teacher, the course, and the course tutors. Students can give specific comments or suggestions in addition to the numeric ratings.
- Students can provide feedback using informal channels, such as email, or simply by discussing with the tutors or the instructor directly.