IDATT2503
Security in programming and cryptography
Autumn
Trondheim
English
About this course
Content
- Relevant legislation, threat picture and actors. Introduction to system programming.
- Common software vulnerabilities, and protection against these, for example, the use of sanitisers and fuzzy testing.
- Ethical hacking and penetration testing, security capture the flag (CTF), reverse engineering, online privacy and anonymity.
- Cryptography: Relevant number theory, principles of cryptography, some crypto systems (classic and modern public key systems, cryptographic hash functions), attack methods.
Learning outcomes
Knowledge:
The candidate can explain:
- common system programming vulnerabilities
- aids to find vulnerabilities in system programming
- how vulnerabilities can be exploited
- online privacy and anonymity
- basic principles of cryptography, as well as some crypto systems and ways to attack them
Skills:
The candidate can:
- find vulnerabilities in system programming
- exploit vulnerabilities in system programming
- conduct penetration testing and reverse engineering
General competence:
- The candidate can examine the security of program systems and choose appropriate measures.
Teaching methods
Mandatory exercises. Mandatory attendance in the lab to get approved exercises.