CS 436 / CS 636 / CS 736
Computer Security • Fall 2026
Course Description & Learning Outcomes
Computer security is the systematic study and practice of protecting software, hardware, networks, digital identities, and society against unauthorized access, modification, disruption, and destruction.
By completing this course, students will be able to:
Security Ethics & Responsible Disclosure Code
The security tools, attack methodologies, and vulnerabilities discussed in CS 636/736/436 are taught strictly for educational and defensive engineering purposes. Using these techniques against production networks or systems without explicit prior written authorization is illegal under federal and state law (e.g., Computer Fraud and Abuse Act - CFAA). Always practice responsible disclosure.
Module Roadmap Breakdown
Module 1: Introduction to Computer Security
Foundational cybersecurity paradigms, the critical role of human factors, real-world cyber incidents (Colonial Pipeline, SolarWinds), and the core building blocks: CIA Triad, Authentication, and Access Control.
Module 2: Threat Modeling
Systematic identification of security objectives, assets, adversaries, attack surfaces, and threat categories using STRIDE, DREAD, and Attack Trees.
Module 3: Encryption & Symmetric Cryptography
The mathematical and historical evolution of cryptography: classical substitution ciphers, frequency analysis, One-Time Pad perfect secrecy, modern symmetric block ciphers (AES), and cipher modes.
Module 4: Integrity & Hash Functions
Ensuring authenticity and tamper-resistance: cryptographic hash functions (MD5, SHA-2, SHA-3), the Avalanche Effect, HMAC, Digital Signatures, PKI, and X.509 Certificates.
Module 5: Availability & Denial of Service
The mechanics of cyber denial-of-service: volumetric floods, botnet orchestration, TCP handshake exploitation (SYN flood), UDP amplification, Slowloris, and defensive mitigations like SYN cookies and Anycast.
Module 6: Authentication & Access Control
The science of proving identity: claim/evidence verification, authentication factors (know, have, are), secure password hashing (salts, peppers, bcrypt, Argon2), entropy calculations, tokens (TOTP/HOTP), biometrics (FAR/FRR), and multi-factor defense.