Schedule
IERG 5310 · First Term 2026–27
All meetings are Thursday, 12:30–3:15 PM, in Ho Sin-Hang Engineering Building 801. Topics and readings are subject to revision.
Introduction, the Security Mindset & Research Ethics
- Course overview and administrivia; how the seminar works
- The security mindset: thinking like an attacker
- Research ethics: the Menlo Report, human subjects, measurement ethics
- Trust and its transitivity: the software supply chain
- How to read, review, and present a research paper
Readings: TBA
TCP/IP and DNS Security
- The IP/TCP threat model: spoofing, sequence prediction, RST injection
- Off-path attacks and network side channels
- DNS resolution and cache poisoning; the Kaminsky attack
- DNSSEC: design, deployment, and its discontents
- Encrypted DNS (DoH/DoT) and the centralization debate
Readings: TBA
Routing Security
- Interdomain routing and BGP: why routing runs on trust
- Prefix hijacks, route leaks, and interception: a tour of incidents
- RPKI and Route Origin Validation: design, deployment, and attacks on RPKI itself
- Source address validation and the spoofing problem
- Coda: clean-slate architectures
Readings: TBA
Give me a break!
TLS, HTTPS and the Web PKI
- SSL/TLS evolution and the attack era: BEAST, Heartbleed, FREAK/Logjam, DROWN
- TLS 1.3 and formal analysis
- The certificate ecosystem: certificate authorities, misissuance, DigiNotar
- Certificate Transparency; Let's Encrypt and ACME
- Measuring the HTTPS ecosystem; QUIC, Encrypted Client Hello, post-quantum migration
Readings: TBA
Web, Email and Tracking
- The browser security model and the same-origin policy
- Cross-site scripting, request forgery, and injection; modern defenses
- Online tracking: cookies, fingerprinting, and the advertising ecosystem
- Email's missing trust model: spoofing, SPF, DKIM, DMARC
- Phishing ecosystems and countermeasures
Readings: TBA
Authentication and Identity
- Passwords: hashing, cracking, breach ecology, and guessing models
- Credential reuse and stuffing
- Two-factor authentication and its bypasses
- FIDO2, WebAuthn, and passkeys
- Federated identity: SAML, OAuth 2.0, OpenID Connect
- Human factors in authentication
Readings: TBA
DDoS, Botnets and Security Measurement
- Denial of service: volumetric attacks, reflection, and amplification
- Measuring attacks: network telescopes and backscatter
- Botnets: from worms to Mirai; command-and-control architectures
- Internet-wide scanning as a measurement instrument
- The underground economy: booter services and the efficacy of takedowns
Readings: TBA
Firewalls, Intrusion Detection, Tunnels and Censorship
- Firewalls and network intrusion detection: the Bro/Zeek and Snort lineage
- Insertion, evasion, and traffic normalization
- Tunnels: IPsec, OpenVPN, and WireGuard
- Network censorship as a nation-scale middlebox: blocking mechanisms
- Censorship measurement platforms and the circumvention arms race
Readings: TBA
Privacy, Anonymity and Tor
- Privacy threat models and privacy-enhancing technologies
- Mixnets and Chaum's foundations
- Onion routing and the design of Tor
- Attacks: traffic correlation and website fingerprinting
- Modern anonymity systems and the anonymity trilemma
Readings: TBA
Secure Messaging and the Crypto Wars
- From PGP's usability failure to off-the-record messaging
- Signal: X3DH, the Double Ratchet, and post-compromise security
- Group messaging and MLS
- Key transparency
- The Crypto Wars: key escrow, exceptional access, and client-side scanning
Readings: TBA
Blockchain and Cryptocurrency Security
- Bitcoin mechanics: transactions, peer-to-peer gossip, and mining
- Attacking the network layer: eclipse attacks and routing-based heists
- Consensus and incentive attacks; maximal extractable value
- Deanonymization and transaction tracing
- Decentralized finance incidents; mixers and the policy debate
Readings: TBA
Project Presentations
- Final project presentations
- Course wrap-up