| Size: 2486 Comment:  | Size: 4512 Comment:  | 
| Deletions are marked like this. | Additions are marked like this. | 
| Line 4: | Line 4: | 
| = CPTR 427 Network Security Class Wiki = | = CPTR 427 Network Security = | 
| Line 6: | Line 6: | 
| This page contains information about Network Security CPTR 427. For assignments see the [[http://eclassbeta.southern.edu/moodle|Eclass website]]. For past class check the bottom of this page for links. | || <<TableOfContents>> || {{http://imgs.xkcd.com/comics/cryptography.png||width=300}} || | 
| Line 8: | Line 8: | 
| * [[NetworkSecurity/Syllabus|Syllabus Winter 2011]] * [[NetworkSecurity/Schedule|Schedule Winter 2011]] | == Course Description == | 
| Line 11: | Line 10: | 
| This course provides an overview to key issues and solutions for network security and privacy issues. It provides an introduction to cryptography and its application to network and operating systems security; security threats; applications of cryptography; secret key and public key cryptographic algorithms; hash functions; authentication; security for electronic mail; intrusion detection; malicious software and firewalls. This course provides the necessary information to prepare for the CompTIA Security+™ exam SY0-501. | |
| Line 12: | Line 12: | 
| Before you get too involved with looking at what we plan to do this semester, you need to look at '''what you should already know'''. Take a look at [[NetworkSecurity/Prerequisites]]. | == Purpose, Goals & Objectives == | 
| Line 14: | Line 14: | 
| The purpose of this course is to introduce students to the real world of network security. Because this is an important, fast growing and changing field, the course goal covers training students to research security related information and implement the solutions found to protect vital assets. To accomplish these goals the student will research a chosen area and setup or write the necessary software on his/her own system. They will then prepare a lecture on the value, implementation and effectiveness of the chosen topic. Lecture topics may include: | |
| Line 15: | Line 17: | 
| * What is Security? * Cryptography * Symmetric and asymmetric key cryptography * Hashes & Message Digests * Public Key Algorithms & Infrastructure * Number Theory Authentication * IPSec * SSH/SSL * Mail/GNU Privacy Guard * Hardening Issues * Windows * Firewalls * Web Issues * Intrusion Detection and Prevention * Wireless * Security Tools | |
| Line 16: | Line 34: | 
| Below is a list of areas and resources we will look at in NetworkSecurity | Upon successful completion of this course, students will be able to: | 
| Line 18: | Line 36: | 
| * [[NetworkSecurity/Lab]] * [[NetworkSecurity/Tools]] * [[NetworkSecurity/Hacking]] * [[NetworkSecurity/Encryption]] * [[NetworkSecurity/FireWall]] * [[http://facultyfp.salisbury.edu/despickler/personal/CryptTools.asp|Cryptotools]] * [[http://www.backtrack-linux.org/|Backtrack Penetration Testing]] * In the past we have used [[NetworkSecurity/WebScarab|Web scarab]] * [[http://www.securitywizardry.com/radar.htm|A nice dashboard]] * [[http://osvdb.org/|Open Source Vulnerability Database]] | * Understand the basic security concepts applicable to system administration * Develop skill to be able to find useful security information * Develop skill to be able to understand the legal and ethical responsibilities as a network security administrator * Present anoral lecture and poster presentation on their own project. * Develop skill to be able to evaluate the effectiveness of security information * Develop skill to be able to understand the basics of security research | 
| Line 29: | Line 43: | 
| = Resources = | |
| Line 30: | Line 45: | 
| == Books Used in this Class == | This page contains resources for Network Security CPTR 427. For assignments etc. see the [[https://eclass.e.southern.edu|Eclass website]]. For information on '''what you should already know''', take a look at [[NetworkSecurity/Prerequisites]]. | 
| Line 32: | Line 47: | 
| '''Required Books''' | == Topics, Resources and Ideas for the future == /* * /NetworkSecurityEssentials4 notes from the book used in 2013. */ * [[/Schedule|Schedule]] * [[/Lab]] * [[/Nebula|Nebuala, a nice beginner hacking tutorial]] * [[https://www.offensive-security.com/metasploit-unleashed/|Metasploit course - free]] * [[/Tools]] * [[http://academic.comptiastore.com/|CompTIA Academic Marketplace]] * [[/Programs]] * [[/Spam]] * /FireWall * [[/Topics]] * /SageIdeas * [[http://facultyfp.salisbury.edu/despickler/personal/CryptTools.asp|Cryptotools]] from AMS/MAA conference 2011 by Dr. Don Spickler. * [[http://www.backtrack-linux.org/|Backtrack Penetration Testing]] * Two proxy tools that allow editing and observing http(s) are [[NetworkSecurity/WebScarab|Web scarab]] and [[http://www.parosproxy.org/|Paros Proxy]] - there is also some nice proxies specifically for firefox. * [[http://www.securitywizardry.com/radar.htm|A nice dashboard]] * [[http://osvdb.org/|Open Source Vulnerability Database]] * [[http://web.nvd.nist.gov/view/vuln/search?execution=e2s1|National Vulnerability Database]] * [[http://exploit-db.com/]] Once upon a time there was a site called Milw0rm.com and it was great! But the maintainer passed away and eventually it was taken over by http://exploit-db.com/. * /SocksProxy * Back in the stone age (relatively speaking of course) Dr. A took a course called [[Csce877]]. | 
| Line 34: | Line 70: | 
| * [[http://www.snort.org/assets/125/snort_manual-2_8_5_1.pdf | Snort Manual]] (Free) * Hacking Exposed 6th Ed. ISBN: 978-0-07-161374-3 * Each student will be responsible for presenting a chapter from this book. * Each student will be responsible for demonstrating an attack related to the chapter they present. * The Code Book: The Science of Secrecy from Ancient Egypt to Quantum Cryptography ISBN: 0385495323 * Each student must read this New York Times Best Seller. * Cryptography will be studied in conjunction with the assigned chapters. * Cryptography and Network Security 4th Ed. ISBN: 0-13-187316-4 * The theory of cryptography (Symmetric, Public-key, Key-management, Hash and MAC) are covered from this book * Applications of theory are partially covered from this book (Kerberos, X.509, IPSec) * Dr. A will do all the lecturing on these topics. * Labs will be given from handouts and rely on internet and suggested resources. Topics will be take from [[NetworkSecurity/Lab]] | == Materials Used in this Class == '''Recommended AdditionalReading''' | 
| Line 47: | Line 73: | 
| * [[http://www.snort.org/assets/125/snort_manual-2_8_5_1.pdf|Snort Manual]] (Free) * [[http://ofps.oreilly.com/titles/9781449320317/ch_Security.html|MVC 4 Security, Authentication and Authorization]] * [[http://www.tomsitpro.com/articles/information-security-certifications,2-205.html|Security Certifications]] | |
| Line 48: | Line 77: | 
| == DES Hints == | |
| Line 49: | Line 79: | 
| * http://www.cs.bham.ac.uk/research/projects/lemsys/DES/DESPage.jsp | |
| Line 50: | Line 81: | 
| '''Recommended Book(s)''' * Snort IDS and IPS Toolkit ISBN-10: 1-59749-099-7 Past Year Class Pages. * Cptr427Winter2010 | == Past Year Class Pages == * /Cptr427Winter2010 | 
CPTR 427 Network Security
| 
 Contents 
 |   | 
Course Description
This course provides an overview to key issues and solutions for network security and privacy issues. It provides an introduction to cryptography and its application to network and operating systems security; security threats; applications of cryptography; secret key and public key cryptographic algorithms; hash functions; authentication; security for electronic mail; intrusion detection; malicious software and firewalls. This course provides the necessary information to prepare for the CompTIA Security+™ exam SY0-501.
Purpose, Goals & Objectives
The purpose of this course is to introduce students to the real world of network security. Because this is an important, fast growing and changing field, the course goal covers training students to research security related information and implement the solutions found to protect vital assets. To accomplish these goals the student will research a chosen area and setup or write the necessary software on his/her own system. They will then prepare a lecture on the value, implementation and effectiveness of the chosen topic. Lecture topics may include:
- What is Security?
- Cryptography
- Symmetric and asymmetric key cryptography
- Hashes & Message Digests 
- Public Key Algorithms & Infrastructure 
- Number Theory Authentication
- IPSec
- SSH/SSL
- Mail/GNU Privacy Guard
- Hardening Issues
- Windows
- Firewalls
- Web Issues
- Intrusion Detection and Prevention
- Wireless
- Security Tools
Upon successful completion of this course, students will be able to:
- Understand the basic security concepts applicable to system administration
- Develop skill to be able to find useful security information
- Develop skill to be able to understand the legal and ethical responsibilities as a network security administrator
- Present anoral lecture and poster presentation on their own project.
- Develop skill to be able to evaluate the effectiveness of security information
- Develop skill to be able to understand the basics of security research
Resources
This page contains resources for Network Security CPTR 427. For assignments etc. see the Eclass website. For information on what you should already know, take a look at NetworkSecurity/Prerequisites.
Topics, Resources and Ideas for the future
- Cryptotools from AMS/MAA conference 2011 by Dr. Don Spickler. 
- Two proxy tools that allow editing and observing http(s) are Web scarab and Paros Proxy - there is also some nice proxies specifically for firefox. 
- http://exploit-db.com/ Once upon a time there was a site called Milw0rm.com and it was great! But the maintainer passed away and eventually it was taken over by http://exploit-db.com/. 
- Back in the stone age (relatively speaking of course) Dr. A took a course called Csce877. 
Materials Used in this Class
Recommended AdditionalReading
DES Hints

