TTM4185

Security and robustness in ICT systems

Autumn

Trondheim

Norwegian and English

Overview

79 candidates

Average grade

C

3.16

0.21

Pass rate

95%

same

Grade distribution
Average over time
Pass rate over time

About this course

Content

The course will focus on information and communication networks as critical infrastructure, where the central functions (basics, operations, maintenance of quality of service), and the properties of autonomy and heterogeneity are described. The course demonstrates how communication networks are integrated with other systems, such as Content Delivery Networks, P2P, Virtual Networks, Clouds, Emergency (wireless) networks, sensor networks, business critical systems, Smart Grids, and discusses what can happen when attacked or prone to outages. A descriptive taxonomy is introduced, which includes information security, privacy, safety, dependability, survivability, performances portability, and a classification of threats. Threats include both human-made (both intentional, incompetence, ignorance, accident) and random failure (environments / nature, weather, wear-out). Several countermeasures exist, and this course covers technological (security mechanisms, fault avoidance and fault tolerant design, measurement / monitoring, standards), organizational (contingency, preparedness, importance of role specification, communication between operational units), and political, including laws and regulations (e-Governance). The course focuses on the qualitative aspects, and will provide brief introduction to methods such as risk management and the application of graph theory.

Learning outcomes

A. Knowledge: To gain basic understanding of: 1) How information and communication networks support and interact with others socially critical system 2) the criticality, complexity and diversity (technological, organizational, interacting actors) of information systems and communications networks 3) approaches to represent information and communication networks for the evaluation of the best possible design 4) Different taxonomy for describing security and robustness properties, threats, and countermeasures 5) The broad set of threat through presentations of various risks (ranging from human to random, malicious people unfortunate combination of random events) 6) Various countermeasures for securing information systems and communication networks against such threats (including technological, organizational, regulations and laws, economic, political) 7) That it is a compromise between the demands for quality and safety (security, reliability, performance), cost (OPEX / CAPEX), environment (energy efficiency), 8) The use of contracts and agreements (e.g., Terms of Service, Service Level Agreements, privacy policies, etc.) to describe this B. Skills: 1) To learn methodical approach to analysis of risks / threats 2) To be able to carry out basic risk assessments 3) To be able to use graphs to represent the complexity and qualitative analysis of the impact of threats 4) To be able to identify and prioritize appropriate countermeasures to mitigate threats.

The learning outcomes of TTM4185 are directly related to UN Sustainable Development Goal (SDG) 9 (9.1: Develop sustainable, resilient and inclusive infrastructures).

Teaching methods

Lectures and practical exercises. Most lectures are conducted in Norwegian, while the majority of the lecture materials are provided in English (though some materials are available only in Norwegian). In exceptional cases, certain lectures may also be delivered in English.