Seguridad de Sistemas Informáticos (Inglés)
Perfilado de sección
-
-
** by @creative_vanesa (https://instagram.com/creative_vanesa?igshid=YmMyMTA2M2Y=)
DISCLAIMER: A lot of care have been put into referencing all the images in this course, both decorative and informative, especially in those cases in which the image itself has no embedded authorship or source information (if this is the case, the source or authorship part have been left clearly visible). If some images have not been attributed it is by mistake, and I sincerely apologize for it. If you find that any image have not been properly referenced, please let me know to correct the mistake. The images labeled as "Stable Diffusion AI" have been generated using this text-to-image AI system (https://huggingface.co/stabilityai), and hence have no defined author.



Welcome to the "Computer Security" course, an introduction to the main computer security paths so you can get started studying them. This course tries to cover a broad number of topics, enabling you to decide if you like some of them and want to study them deeper in the future.A possible continuation of this course is also planned in the University of Oviedo. This course is part of the "Cobra Kali" initiative. This means that this is the first introductory course of a series of 6 courses, most of them taught on the Master Degree and Phd in Web Engineering (https://miw.uniovi.es/). This diagram shows the structure of those courses:
* * Course logos by @creative_vanesa (https://instagram.com/creative_vanesa?igshid=YmMyMTA2M2Y=)
1. Course information
- Lecturer: José Manuel Redondo López
- Course: Computer Security (GIISOF01-3-010)
- Study Plan: Bachelor´s Degree in Computer Science - Software Engineering - 2011
- Center: Computer Science School (https://ingenieriainformatica.uniovi.es/)
- Type: Mandatory
- Total ECTS Credits: 6.0
- Level: Undergraduate
- Period: 3rd Year, Second Semester
- Department: Computer Science (https://www.di.uniovi.es/)
- Language: English 🇬🇧
2. Context
The Computer Security course belongs to the Computer Systems topic. This topic also contains Operating Systems course (fourth semester of the degree) and the Distributed Systems and Internet and Systems and Networks Administration courses, which are studied at the same time as this one in the sixth semester of the degree.
The course will study the factors that can influence the security of computer systems at all levels, from physical security to security in application usage and configuration, paying attention to the possible threats that may exist in each case, as well as the measures to be taken to avoid them.
3. Requirements
In order to properly understand the topics, and to be able to take the course with the adequate conditions, it is necessary that the student has previously completed the following courses:
- Computer Science Fundamentals.
- Computer architecture.
- Operating systems.
- Systems and Networks Administration (can be taken in parallel with this one).
In terms of competences, the student must have acquired the following before completing the course:- Basic knowledge about computer programming and usage, operating systems, databases and software with application in engineering fields.
- Knowledge of the characteristics, functionalities and structure of the operating systems, and design and implement applications based on their services.
- Ability to know, understand and evaluate the structure and architecture of computers, as well as the basic components that form them.
- Knowledge and application of the features, functionalities and structure of distributed systems, Internet and computer networks, and design and implement applications based on them.
- Knowledge of the structure, organization, operation and interconnection of computer systems, the fundamentals of their programming, and their application to solve engineering problems.
4. Competencies and learning results
The Computer Security course belongs to the topic "Computer systems". This topic is described in the verification report of the Bachelor of Software Engineering (https://calidad.uniovi.es/c/document_library/get_file?p_l_id=2535677&folderId=4419021&name=DLFE-56004.pdf). The course competencies assigned in this module are:
- CG-1: Competence to design solutions to complex human problems
- CG-2: Capacity to adapt to the standards.
- CG-4: Analysis and synthesis
- CG-6: Search, analysis and information management to transform it into knowledge
- CG-7: Ability in written expression
- CG-12: Leadership
- CG-13: Negotiation
- CG-15: Capacity for human, technical, functional and economic management of complex systems
- CG-18: Sense of responsibility
- CG-21: Professional ethics
- CG-26: Ability to learn and work autonomously
- Com-1: Capacity to design, develop, select and evaluate computer applications and computer systems, ensuring their reliability, safety and quality according to the ethical principles and the legislation and norms in force.
- Com-4: Capacity to elaborate the technical specifications of a computer system that complies with current standards and regulations.
- Com-5: Knowledge, administration and maintenance of computer systems, services and applications.
- Com-8: Ability to analyze, design, build and maintain applications in a robust, secure, safe and efficient way, choosing the most appropriate paradigm and programming language.
- ISW-1: Capacity to develop, maintain and evaluate software services and systems that satisfy quality standards, applying software engineering theories, principles, methods and practices.
- ISW-3: Ability to provide solutions to integration problems based on the strategies, standards and technologies available.
- ISW-5: Ability to identify, evaluate and manage potential associated risks that may arise.
The learning outcomes of the course are:
- RA.SI-7. Identify the risks that can compromise the security of a computer system, posing the appropriate security policies and managing the corresponding mechanisms
- RA.SI-8. Designing secure computer systems and the applications they may include.
- RA.SI-9. Work in teams for developing group assignments where it is necessary to develop technical documentation and display the results through an oral presentation.
- RA.SI-11. Be able to autonomously adapt to new threats and technologies.
- RA.SI-12. Be able to sensitize system users to follow the established protocols of utilization.
- RA.SI-13. To acquire an ethical code of behavior of all aspects related to the management of a computer system and the information it supports
With this course the student will acquire knowledge about the factors that intervene in the security of a computer system, how to plan the appropriate measures to protect the system and all its components, and how to deploy them into systems with usual configurations in the real world
4. Contents
The course is composed by three different lines of activities, all of them coordinated together to reinforce student learning. The activities start with a general introduction, moving through mayor cybersecurity topics like practical applications of cryptography, OS security, security automation and security policies, network security and enumeration, application security and Red Team operations:
- Lectures: explaining the theory of the topics necessary to complete the necessary laboratories
- Seminars: complementary topics to the lectures, reinforcing some of their aspects showing the results of practical applications of the theory concepts
- Laboratories: Hands-on experience on the things explained in the corresponding theory topic.
5. Methodology
This course has been adapted to be done at the student pace, and the 14-week period indicated in the Calendar section is only a suggestion. Topics are linked together and coherent in the theory, seminar, and laboratory parts, so the course can be suspended and resumed at will. Activities in laboratories are structured so they can be precisely tracked to also improve this aspect. Laboratory materials have been designed with modern Infrastructure as Code technology to be multiplatform, easily mobile and deployable, and with low resource usage, to adapt to any possible context and student resources and possibilities.
6. Activities
Course activities are structured in two parts:
- Theory topics and concepts: That must be studied. Badges are used at the end of each topic to facilitate and self-evaluate the main concepts of each topic.
- Laboratory activities: Activities that must be completed to be sure the student have understood. Each activity includes the description of their practical application to give more value to the student work. Also, each one has an "Expected Results" box describing what the student must obtain after finishing each activity, so they immediately know if the activity has been done correctly.
7. Evaluation
As this is a non-presential open course, evaluation will rely on student self-evaluation. To implement this, theory and seminar topics have badges (classified by difficulty) that contain the main concepts that the students must understand to consider they have successfully understood each topic. Apart from that, laboratory activity reports also contain badges and are also accompanied by .csv files with each activity, to facilitate keeping track of the activities the student have done and, hence, easily control those that have been completed successfully (thanks to the "Expected Results" box of each activity) and those that are still remaining. Evaluation of the course will be exclusively practical, as laboratory topics require a correct understanding of the theory topics.
Students will elaborate a complete answer report of all the activities and questions in the laboratory report to successfully pass the course. This report will not only contain the answer to the questions, but also the detailed procedure for reaching these answers, including text explanations and screen captures when judged necessary to describe the solution procedure.
-