Schedule
IERG 5310 · First Term 2026–27
All meetings are Thursday, 12:30–3:15 PM, in Ho Sin-Hang Engineering Building 801. Topics and readings are subject to revision.
Introduction, the Security Mindset & Research Ethics
- Course overview and administrivia; how the seminar works
- The security mindset: thinking like an attacker
- Research ethics: the Menlo Report, human subjects, measurement ethics
- How to read, review, and present a research paper
Required
- The Menlo Report: Ethical Principles Guiding Information and Communication Technology Research. D. Dittrich, E. Kenneally, et al. U.S. Department of Homeland Security, Science and Technology Directorate (report), 2012.
- The Moral Character of Cryptographic Work. Phillip Rogaway. IACR Distinguished Lecture, Asiacrypt 2015.
- The Security Mindset. Bruce Schneier. Schneier on Security (blog), 2008.
Optional
- No Encore for Encore? Ethical questions for web-based censorship measurement. Arvind Narayanan, Bendert Zevenbergen. Technology Science, 2015.
- Reflections on Trusting Trust. Ken Thompson. Communications of the ACM, 1984.
- Timeline of the xz open source attack. Russ Cox. research.swtch.com (blog), 2024.
TCP/IP & DNS Security
- Internet design philosophy
- Classic TCP/IP attacks
- Off-path attacks and network side channels
- DNS and cache poisoning
- DNSSEC: the design, and the deployment reality
Required
- Augur: Internet-Wide Detection of Connectivity Disruptions. P. Pearce, R. Ensafi, F. Li, N. Feamster, V. Paxson. IEEE Symposium on Security and Privacy, 2017.
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side Channels. K. Man, Z. Qian, Z. Wang, X. Zheng, Y. Huang, H. Duan. ACM CCS, 2020.
- Off-Path TCP Exploits: Global Rate Limit Considered Dangerous. Y. Cao, Z. Qian, Z. Wang, T. Dao, S. V. Krishnamurthy, L. M. Marvel. USENIX Security, 2016.
Optional
- The Design Philosophy of the DARPA Internet Protocols. David D. Clark. ACM SIGCOMM, 1988.
- SnailLoad: Exploiting Remote Network Latency Measurements without JavaScript. S. Gast, R. Czerny, J. Juffinger, F. Rauscher, S. Franza, D. Gruss. USENIX Security, 2024.
- The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSEC. E. Heftrig, H. Schulmann, N. Vogel, M. Waidner. ACM CCS, 2024.
Routing Security
- BGP basics: how Internet routing actually works
- Prefix hijacking and route leaks
- IP spoofing and source address validation
- RPKI and Route Origin Validation
- SCION: a clean-slate secure Internet
Required
- Nation-State Hegemony in Internet Routing. A. Edmundson, R. Ensafi, N. Feamster, J. Rexford. ACM COMPASS, 2018.
- RPKI is Coming of Age: A Longitudinal Study of RPKI Deployment and Invalid Route Origins. T. Chung, E. Aben, T. Bruijnzeels, et al. ACM Internet Measurement Conference, 2019.
- SoK: An Introspective Analysis of RPKI Security. D. Mirdita, H. Schulmann, M. Waidner. USENIX Security, 2025.
Optional
- SCION: Scalability, Control, and Isolation On Next-Generation Networks. X. Zhang, H.-C. Hsiao, G. Hasker, H. Chan, A. Perrig, D. G. Andersen. IEEE Symposium on Security and Privacy, 2011.
- The CURE to Vulnerabilities in RPKI Validation. D. Mirdita, H. Schulmann, N. Vogel, M. Waidner. NDSS, 2024.
- Why Is It Taking So Long to Secure Internet Routing?. Sharon Goldberg. ACM Queue, 2014.
Give me a break!
TLS, HTTPS & the Web PKI
- TLS evolution and attacks on TLS
- The Web PKI: certificate authorities and their failures
- Scanning the entire Internet: ZMap and Censys
Required
- Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice. D. Adrian, K. Bhargavan, Z. Durumeric, et al. ACM CCS, 2015.
- Tracking Certificate Misissuance in the Wild. D. Kumar, Z. Wang, M. Hyder, et al. IEEE Symposium on Security and Privacy, 2018.
- Opossum Attack: Application Layer Desynchronization using Opportunistic TLS. R. Merget, N. Erinola, M. Maehren, et al. USENIX Security, 2026.
Optional
- Analysis of the HTTPS Certificate Ecosystem. Z. Durumeric, J. Kasten, M. Bailey, J. A. Halderman. ACM Internet Measurement Conference, 2013.
- Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire Web. J. Aas, R. Barnes, B. Case, et al. ACM CCS, 2019.
- The Security Impact of HTTPS Interception. Z. Durumeric, Z. Ma, D. Springall, et al. NDSS, 2017.
Web, Email & Tracking
- The web security model: origins, cookies, sessions
- Classic web attacks and modern defenses
- Email security mechanisms and how they fail in practice
- The tracking and fingerprinting arms-race
Required
- Composition Kills: A Case Study of Email Sender Authentication. J. Chen, V. Paxson, J. Jiang. USENIX Security, 2020.
- Leaky Forms: A Study of Email and Password Exfiltration Before Form Submission. A. Senol, G. Acar, M. Humbert, F. Zuiderveen Borgesius. USENIX Security, 2022.
- Same-Origin Policy for Agentic Browsers. X. Wang, X. Chen, P. Li, D. Song, N. Gong. arXiv preprint (not peer reviewed), 2026.
Optional
- Robust Defenses for Cross-Site Request Forgery. A. Barth, C. Jackson, J. C. Mitchell. ACM CCS, 2008.
- Online Tracking: A 1-million-site Measurement and Analysis. S. Englehardt, A. Narayanan. ACM CCS, 2016.
- BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet. C. Wang, Y. Kuranaga, Y. Wang, et al. NDSS, 2024.
Authentication, Identity, and Usable Security
- The authentication problem and the Quest to Replace Passwords
- Breaches, credential stuffing, and password guessing
- Two-factor authentication
- Federated identity: OAuth, OIDC, and single sign-on
- Usable security: humans are not the enemy
Required
- The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes. J. Bonneau, C. Herley, P. C. van Oorschot, F. Stajano. IEEE Symposium on Security and Privacy, 2012.
- Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms. K. Luo, X. Wang, P. H. A. Fung, W. C. Lau, J. Lecomte. USENIX Security, 2025.
- The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web. L. Jannett, A. Mayer, M. Westers, V. Mladenov, C. Mainka, J. Schwenk. USENIX Security, 2026.
Optional
- Why Johnny Can't Encrypt: A Usability Evaluation of PGP 5.0. A. Whitten, J. D. Tygar. USENIX Security, 1999.
- The Tangled Web of Password Reuse. A. Das, J. Bonneau, M. Caesar, N. Borisov, X. Wang. NDSS, 2014.
DDoS, Botnets & Security Measurement
- DoS fundamentals
- Botnets: from the worm era to Mirai
- Defenses in practice
- Measuring attacks at Internet scale: backscatter, telescopes, scanning
Required
- ZMap: Fast Internet-wide Scanning and Its Security Applications. Z. Durumeric, E. Wustrow, J. A. Halderman. USENIX Security, 2013.
- Understanding the Mirai Botnet. M. Antonakakis, T. April, M. Bailey, et al. USENIX Security, 2017.
- Weaponizing Middleboxes for TCP Reflected Amplification. K. Bock, A. Alaraj, Y. Fax, K. Hurley, E. Wustrow, D. Levin. USENIX Security, 2021.
Optional
- Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope. R. Hiesgen, M. Nawrocki, A. King, A. Dainotti, T. C. Schmidt, M. Wählisch. USENIX Security, 2022.
- How to Operate a Meta-Telescope in your Spare Time. D. Wagner, S. A. Ranadive, H. Griffioen, et al. ACM Internet Measurement Conference, 2023.
- Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services. A. V. Vu, B. Collier, D. R. Thomas, J. Kristoff, R. Clayton, A. Hutchings. USENIX Security, 2025.
Firewalls, NIDS, Tunnels & Censorship
- Firewalls and middleboxes
- Intrusion detection: signatures, anomalies, and the base-rate fallacy
- NIDS evasion and normalization
- Tunnels: IPsec, VPNs, WireGuard
- Censorship as a nation-scale firewall: mechanics and measurement
- The circumvention arms race
Required
- Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection. T. H. Ptacek, T. N. Newsham. Secure Networks, Inc. (technical report), 1998.
- SoK: Towards Grounding Censorship Circumvention in Empiricism. M. C. Tschantz, S. Afroz, Anonymous, V. Paxson. IEEE Symposium on Security and Privacy, 2016.
- Blind In/On-Path Attacks and Applications to VPNs. W. J. Tolley, B. Kujath, M. T. Khan, N. Vallina-Rodriguez, J. R. Crandall. USENIX Security, 2021.
Optional
- Decoy Routing: Toward Unblockable Internet Communication. J. Karlin, D. Ellard, A. W. Jackson, et al. USENIX FOCI, 2011.
- The Parrot is Dead: Observing Unobservable Network Communications. A. Houmansadr, C. Brubaker, V. Shmatikov. IEEE Symposium on Security and Privacy, 2013.
- An Analysis of China's “Great Cannon”. B. Marczak, N. Weaver, J. Dalek, et al. USENIX FOCI, 2015.
- How the Great Firewall of China Detects and Blocks Fully Encrypted Traffic. M. Wu, J. Sippe, D. Sivakumar, et al. USENIX Security, 2023.
Privacy, Anonymity & Tor
- What anonymity means
- Traffic analysis and how metadata kills
- Mixnets
- Tor: onion routing
- Attacking Tor
Required
- Tor: The Second-Generation Onion Router. R. Dingledine, N. Mathewson, P. Syverson. USENIX Security, 2004.
- Online Website Fingerprinting: Evaluating Website Fingerprinting Attacks on Tor in the Real World. G. Cherubin, R. Jansen, C. Troncoso. USENIX Security, 2022.
- LPG: Raise Your Location Privacy Game in Direct-to-Cell LEO Satellite Networks. Q. Shi, L. Wang, P. Gope, et al. USENIX Security, 2026.
Optional
- The Loopix Anonymity System. A. M. Piotrowska, J. Hayes, T. Elahi, S. Meiser, G. Danezis. USENIX Security, 2017.
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions System. J. Reardon, Á. Feal, P. Wijesekera, et al. USENIX Security, 2019.
- On the Anonymity of Peer-To-Peer Network Anonymity Schemes Used by Cryptocurrencies. P. K. Sharma, D. Gosain, C. Diaz. NDSS, 2023.
Secure Messaging & Crypto War
- From PGP to E2EE: goals and security properties
- The Signal protocol: OTR → X3DH → Double Ratchet
- Group messaging, MLS, key transparency
- Client-side scanning and today's encryption-policy fight
Required
- SoK: Secure Messaging. N. Unger, S. Dechand, J. Bonneau, et al. IEEE Symposium on Security and Privacy, 2015.
- CONIKS: Bringing Key Transparency to End Users. M. S. Melara, A. Blankstein, J. Bonneau, E. W. Felten, M. J. Freedman. USENIX Security, 2015.
- Practically-exploitable Cryptographic Vulnerabilities in Matrix. M. R. Albrecht, S. Celi, B. Dowling, D. Jones. IEEE Symposium on Security and Privacy, 2023.
Optional
- Off-the-Record Communication, or, Why Not To Use PGP. N. Borisov, I. Goldberg, E. Brewer. ACM WPES, 2004.
- A Formal Security Analysis of the Signal Messaging Protocol. K. Cohn-Gordon, C. Cremers, B. Dowling, L. Garratt, D. Stebila. IEEE EuroS&P, 2017.
- Three Lessons From Threema: Analysis of a Secure Messenger. K. G. Paterson, M. Scarlata, K. T. Truong. USENIX Security, 2023.
Blockchain
- Bitcoin mechanics: transactions, mining, consensus
- Attacking the network
- Attacking consensus and incentives
- Tracing and mixers
- Smart-contract and DeFi security
Required
- Bitcoin: A Peer-to-Peer Electronic Cash System. Satoshi Nakamoto. Self-published whitepaper, 2008.
- A Fistful of Bitcoins: Characterizing Payments Among Men with No Names. S. Meiklejohn, M. Pomarole, G. Jordan, et al. ACM Internet Measurement Conference, 2013.
- Majority Is Not Enough: Bitcoin Mining Is Vulnerable. I. Eyal, E. G. Sirer. Financial Cryptography and Data Security, 2014.
Optional
- Uncle Maker: (Time)Stamping Out The Competition in Ethereum. A. Yaish, G. Stern, A. Zohar. ACM CCS, 2023.