{"id":75,"date":"2019-03-28T11:32:36","date_gmt":"2019-03-28T15:32:36","guid":{"rendered":"https:\/\/sites.bu.edu\/braude\/?page_id=75"},"modified":"2019-03-28T11:40:41","modified_gmt":"2019-03-28T15:40:41","slug":"met-cs-895-developing-secure-systems","status":"publish","type":"page","link":"https:\/\/sites.bu.edu\/braude\/courses\/met-cs-895-developing-secure-systems\/","title":{"rendered":"MET CS 895 Developing Secure Systems"},"content":{"rendered":"<p>Last updated: <em>Monday, <\/em><em>May 5, 2006<\/em><em>.\u00a0 The most recent updates are usually in red type<\/em><\/p>\n<p><strong>Description:<\/strong> This course is designed for Information professionals who intend to be experts in security policies, procedures, and techniques.\u00a0 It provides the basis for specialization in areas of security.<\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td width=\"235\" valign=\"top\">Background   of Instructors red if changed<\/td>\n<td width=\"228\" valign=\"top\">Learning   Objectives red if changed<\/td>\n<\/tr>\n<tr>\n<td width=\"235\" valign=\"top\">Evaluation of Students red   if changed<\/td>\n<td width=\"228\" valign=\"top\">Plagiarism red if changed<\/td>\n<\/tr>\n<tr>\n<td width=\"235\" valign=\"top\">Forum red   if changed<\/td>\n<td width=\"228\" valign=\"top\">Policies   for class <em>red if <\/em>changed<\/td>\n<\/tr>\n<tr>\n<td width=\"235\" valign=\"top\">Home page   for Eric Braude<\/td>\n<td width=\"228\" valign=\"top\">Textbooks   and Materials red if changed<\/td>\n<\/tr>\n<tr>\n<td width=\"235\" valign=\"top\">Homework   and due dates red if changed<\/td>\n<td width=\"228\" valign=\"top\">Topics,   Class Dates, and Readings red if   changed<\/td>\n<\/tr>\n<tr>\n<td width=\"235\" valign=\"top\">How to Contact Eric Braude red if changed<\/td>\n<td width=\"228\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>Meeting Time: Wednesdays Noon\u00a0 through 3:00 pm EST<\/li>\n<li>Meeting Place: Andover<\/li>\n<li>Prerequisites: The prerequisites are as follows, but      can be superseded with the consent of the instructor.<\/li>\n<\/ul>\n<ul>\n<li>\n<ul>\n<li>A course in or experience with       programming, preferably in Java, C++ or C#<\/li>\n<li>Knowledge of data communication       fundamentals<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<hr size=\"2\" \/><strong>Learning Objectives<\/strong>: Students will \u2026<\/p>\n<ul>\n<li>Understand the principles of security<\/li>\n<li>Recognize and evaluate security threats<\/li>\n<li>Understand the source of security threats<\/li>\n<li>Understand the basics of security-aware design and development<\/li>\n<li>Plan for security threat mitigation<\/li>\n<\/ul>\n<hr size=\"2\" \/>\n<h3>Textbook and Materials<\/h3>\n<p>\u201cSecurity in Computing,\u201d Third Edition (Hardcover) by Charles P. Pfleeger, Shari Lawrence Pfleeger; Prentice Hall PTR (December 2, 2002); ISBN: 0130355488<\/p>\n<p>Reference Material<\/p>\n<p>An Alternative to the Textbook:<\/p>\n<p>Computer Security (Paperback) by Dieter Gollmann; John Wiley &amp; Sons; 2 edition (January 18, 2006); ISBN: 0470862939<\/p>\n<p>Security in Networks:<\/p>\n<p>Network Security Essentials (2nd Edition); by William Stallings; Prentice Hall; 2 edition (November 20, 2002); ISBN: 0130351288<\/p>\n<p>Policy (Not technical)<\/p>\n<p>Information Security Policies and Procedures: A Practitioner&#8217;s Reference, Second Edition; by Thomas R. Peltier; AUERBACH; 2 edition (May 20, 2004); ISBN: 0849319587<\/p>\n<p>Design (Very technical)<\/p>\n<p>Secure Systems Development with UML; by Jan J\u00fcrjens; Springer; 1 edition (November 23, 2004)<\/p>\n<p>ISBN: 3540007016<\/p>\n<hr size=\"2\" \/>\n<h3>Background of Instructors<\/h3>\n<p>Please see the links as shown.<\/p>\n<p><span style=\"text-decoration: underline;\">Background of Eric Braude<\/span><\/p>\n<p>Background of Lou Chitkushev<\/p>\n<p>Background of Suresh Kalathur<\/p>\n<p>Background of Anatoly Temkin<\/p>\n<hr size=\"2\" \/>\n<h3>Evaluation of Students<\/h3>\n<p>There will be a midterm, a final, and homework assignments.\u00a0 The exact weights will be determined during the first third of the course, and will be in the following range.<\/p>\n<table border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"173\">\n<tbody>\n<tr>\n<td width=\"56%\"><\/td>\n<td width=\"43%\"><strong>weight<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"56%\"><strong><em>Midterm <\/em><\/strong><\/td>\n<td width=\"43%\">35-50%<\/td>\n<\/tr>\n<tr>\n<td width=\"56%\"><strong><em>Final <\/em><\/strong><\/td>\n<td width=\"43%\">35-50%<\/td>\n<\/tr>\n<tr>\n<td width=\"56%\"><strong><em>Homework\u2019s <\/em><\/strong><\/td>\n<td width=\"43%\">10-30%<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Parts of assignments are evaluated equally unless otherwise stated.<\/p>\n<p>Late homework is not accepted unless there is a reason why it was impossible to perform the work. In that case, the written reason should be attached to the homework, which will be graded on a pass\/fail basis.<\/p>\n<p>Please also read <strong>detailed information about grade averaging method.<\/strong><\/p>\n<hr size=\"2\" \/><strong>Plagiarism<\/strong><\/p>\n<p>Please cite all references and uses of the work of other.\u00a0 All instances of plagiarism must be reported to the College for action.\u00a0 See plagiarism policy and reference.<\/p>\n<hr size=\"2\" \/><strong>Topics, Class Dates,<\/strong><strong> and Readings<\/strong><\/p>\n<table border=\"1\" cellspacing=\"1\" cellpadding=\"0\" width=\"548\">\n<tbody>\n<tr>\n<td width=\"7%\"><strong><span style=\"text-decoration: underline;\">Class<\/span><\/strong><\/p>\n<p><strong><span style=\"text-decoration: underline;\">#<\/span><\/strong><\/td>\n<td width=\"7%\"><strong><span style=\"text-decoration: underline;\">Date<\/span><\/strong><\/td>\n<td width=\"12%\" valign=\"top\"><strong><span style=\"text-decoration: underline;\">Instructor<\/span><\/strong><\/td>\n<td width=\"27%\" valign=\"top\"><strong><span style=\"text-decoration: underline;\">Textbook Readings<\/span><\/strong><\/td>\n<td width=\"43%\"><strong><span style=\"text-decoration: underline;\">Topic<\/span><\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">1<\/td>\n<td width=\"7%\">May 3<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Chapter 1<\/strong><\/p>\n<p>Chapters   3 and 9 are additional background<\/td>\n<td width=\"43%\"><strong>The Context of Security<\/strong><\/p>\n<p>A review   of the threat environment<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">2<\/td>\n<td width=\"7%\">May 10<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Chapter 8<\/strong><\/p>\n<p>Except 8.2<\/p>\n<p><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Policies and Procedures<\/strong><\/p>\n<p>We will review the kinds of   overall policies and specific procedures that organizations devise in order   to counter security threats.<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">3<\/td>\n<td width=\"7%\">May 17<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\">Chapter   9 is general background<\/td>\n<td width=\"43%\"><strong>Security Among Web Services<\/strong><\/p>\n<p>This class reviews various   methods for designing securely on the Internet, from HTTPS to the WS-Security   specifications.<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">4<\/td>\n<td width=\"7%\">May 24<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Pages <\/strong>160-162,<\/td>\n<td width=\"43%\"><strong>Specifying Secure Requirements   Designs<\/strong><\/p>\n<p>How design notations,   including the Unified Modeling Language, can specify security.<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">5<\/td>\n<td width=\"7%\">May 31<\/td>\n<td width=\"12%\" valign=\"top\">Lou Chitkushev<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Chapter 8<\/strong><\/td>\n<td width=\"43%\"><strong>Developing   Security in Distributed Systems<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">6<\/td>\n<td width=\"7%\">June 7<\/td>\n<td width=\"12%\" valign=\"top\">Anatoly Temkin<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Chapters 2 and   10<\/strong><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Applying Cryptographic Elements <\/strong><\/p>\n<p>Encryption, conventional and   public key; message digest and digital signature; key management<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">7<\/td>\n<td width=\"7%\">June   14<\/td>\n<td width=\"12%\" valign=\"top\">Lou Chitkushev<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Chapter 8<\/strong><\/p>\n<p><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Developing Network Security<\/strong><\/p>\n<p>Authentication systems, security standards,   Kerberos, public key infrastructure; IPsec,   SSL\/TLS; PEM, S\/MIME; PGP; Firewalls<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">8<\/td>\n<td width=\"7%\">June   21<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Midterm<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">9<\/td>\n<td width=\"7%\">June   28<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Applying Language Level Security; <\/strong><\/p>\n<p><strong>Testing for Security<\/strong><\/p>\n<p>Security policies and permissions,   access control, secure class loading, security management<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">10<\/td>\n<td width=\"7%\">July 5<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Section 8.2<\/strong><\/p>\n<p><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Developing Security Risk Analyses<\/strong><\/p>\n<p>Definitions,   factors, risk types<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">11<\/td>\n<td width=\"7%\">July   12<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Section 8.2<\/strong><\/p>\n<p><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Applying Security Risk Analysis<\/strong><\/p>\n<p>Risk   calculations; trade-offs<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">12<\/td>\n<td width=\"7%\">July   19<\/td>\n<td width=\"12%\" valign=\"top\">Suresh Kalathur<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Chapter 4<\/strong><\/p>\n<p><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Developing Protection in General Purpose   Operating Systems<\/strong><\/p>\n<p>Access control   lists; file protection; authentication<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">13<\/td>\n<td width=\"7%\">July   26<\/td>\n<td width=\"12%\" valign=\"top\">Suresh Kalathur<\/td>\n<td width=\"27%\" valign=\"top\"><strong>Chapter 5<\/strong><\/p>\n<p><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Designing Trusted Operating Systems <\/strong><\/p>\n<p>Security   policies; security models; assurance; examples<\/td>\n<\/tr>\n<tr>\n<td width=\"7%\">14<\/td>\n<td width=\"7%\">August   2<\/td>\n<td width=\"12%\" valign=\"top\">Eric Braude<\/td>\n<td width=\"27%\" valign=\"top\"><strong> <\/strong><\/td>\n<td width=\"43%\"><strong>Final<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr size=\"2\" \/><strong>Forum<\/strong><\/p>\n<p>Web Site: http:\/\/groups.yahoo.com\/group\/895Su06\/<\/p>\n<table border=\"0\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"top\">Post message:<\/td>\n<td valign=\"top\">895Su06@yahoogroups.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\">Subscribe:<\/td>\n<td valign=\"top\">895Su06-subscribe@yahoogroups.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\">Unsubscribe:<\/td>\n<td valign=\"top\">895Su06-unsubscribe@yahoogroups.com<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\">List owner:<\/td>\n<td valign=\"top\">895Su06-owner@yahoogroups.com<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong> <\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last updated: Monday, May 5, 2006.\u00a0 The most recent updates are usually in red type Description: This course is designed for Information professionals who intend to be experts in security policies, procedures, and techniques.\u00a0 It provides the basis for specialization in areas of security. Background of Instructors red if changed Learning Objectives red if changed [&hellip;]<\/p>\n","protected":false},"author":2828,"featured_media":0,"parent":22,"menu_order":12,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/75"}],"collection":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/users\/2828"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/comments?post=75"}],"version-history":[{"count":1,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/75\/revisions"}],"predecessor-version":[{"id":76,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/75\/revisions\/76"}],"up":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/22"}],"wp:attachment":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/media?parent=75"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}