Official Syllabus & Policies

CS 436 / CS 636 / CS 736

Computer Security • Fall 2026

Download Official PDF
InstructorDr. Ragib Hasan
Department & LabSECRETLab (Secure and Trustworthy Computing Lab)
UniversityUniversity of Alabama at Birmingham (UAB)

Course Description & Learning Outcomes

Computer security is the systematic study and practice of protecting software, hardware, networks, digital identities, and society against unauthorized access, modification, disruption, and destruction.

By completing this course, students will be able to:

Evaluate systems against the CIA Triad (Confidentiality, Integrity, Availability) and human psychological vulnerabilities.
Construct rigorous Threat Models using Microsoft STRIDE and calculate mitigation priorities using DREAD risk scoring.
Analyze symmetric block ciphers (AES), block cipher modes (CBC, CTR vs insecure ECB), and public key infrastructure (Diffie-Hellman, RSA, X.509).
Apply cryptographic hash functions (SHA-2, SHA-3), verify the Strict Avalanche Criterion (SAC), and construct HMAC message authentication codes.
Mitigate high-volume Denial of Service attacks (SYN floods via SYN cookies, UDP amplification via BCP 38, Slowloris).
Architect multi-factor authentication systems balancing False Acceptance Rate (FAR), False Rejection Rate (FRR), TOTP tokens, and secure salted hashing (Argon2, bcrypt).

Security Ethics & Responsible Disclosure Code

The security tools, attack methodologies, and vulnerabilities discussed in CS 636/736/436 are taught strictly for educational and defensive engineering purposes. Using these techniques against production networks or systems without explicit prior written authorization is illegal under federal and state law (e.g., Computer Fraud and Abuse Act - CFAA). Always practice responsible disclosure.

Module Roadmap Breakdown

MODULE 1•9 Lectures

Module 1: Introduction to Computer Security

Foundational cybersecurity paradigms, the critical role of human factors, real-world cyber incidents (Colonial Pipeline, SolarWinds), and the core building blocks: CIA Triad, Authentication, and Access Control.

9 Slides & Transcripts
MODULE 2•5 Lectures

Module 2: Threat Modeling

Systematic identification of security objectives, assets, adversaries, attack surfaces, and threat categories using STRIDE, DREAD, and Attack Trees.

5 Slides & Transcripts
MODULE 3•6 Lectures

Module 3: Encryption & Symmetric Cryptography

The mathematical and historical evolution of cryptography: classical substitution ciphers, frequency analysis, One-Time Pad perfect secrecy, modern symmetric block ciphers (AES), and cipher modes.

6 Slides & Transcripts
MODULE 4•9 Lectures

Module 4: Integrity & Hash Functions

Ensuring authenticity and tamper-resistance: cryptographic hash functions (MD5, SHA-2, SHA-3), the Avalanche Effect, HMAC, Digital Signatures, PKI, and X.509 Certificates.

9 Slides & Transcripts
MODULE 5•7 Lectures

Module 5: Availability & Denial of Service

The mechanics of cyber denial-of-service: volumetric floods, botnet orchestration, TCP handshake exploitation (SYN flood), UDP amplification, Slowloris, and defensive mitigations like SYN cookies and Anycast.

7 Slides & Transcripts
MODULE 6•7 Lectures

Module 6: Authentication & Access Control

The science of proving identity: claim/evidence verification, authentication factors (know, have, are), secure password hashing (salts, peppers, bcrypt, Argon2), entropy calculations, tokens (TOTP/HOTP), biometrics (FAR/FRR), and multi-factor defense.

7 Slides & Transcripts