Lecturer:
Antonio Barili
Course name: Digital Systems and Services Security
Course code: 064167
Degree course: Ingegneria Biomedica, Ingegneria Informatica, Ingegneria dei Servizi
Disciplinary field of science: ING-INF/05
L'insegnamento è caratterizzante per: Ingegneria Informatica, Ingegneria dei Servizi The course relates to: Ingegneria Informatica, Ingegneria dei Servizi
University credits: CFU 5
Course website: http://www.unipv.it/abarili
Specific course objectives
Knowledge of information and communication security techniques and applicable laws. Ability to assess the information protection level of some common software systems and to design improvement actions.
Course programme
Introduction
"Security" vs. "Safety". Physical security of computer systems and communication networks. People security and safety. Information security: privacy, avaliability, integrity and authenticity. Information security threats and countermeasures.
Basic Cryptography
Introduction to information theory, cryptography and steganography. Symmetric and asymmetric cryptography. Cryptographic algorithms. Hashing functions. Keys and certificates protection and distribution. Attacks and threats to cryptographic systems.
Digital Signature
Digital documents and digital signatures. Creation, conservation and validation of digital documents. Digital documents as trial court evidence. Public key infrastructures. Italian and EU laws.
Copyright Protection
Introduction to copyright law. Software and database protection. Audio, video and picture protection. Digital rights management (DRM). Applicable laws.
Communication Protection
Information communication and diffusion. Synchronous and asynchronous communication. E-mail. The Web as an information diffusion media. Communication privacy protection. Threats to the freedom and privacy of communications and countermeasures. Phishing.
Systems and Networks Protection
Access control: authentication, authorization and accounting. Phisical and logical information protection. Networks protection. Firewalls. Threats to systems and communication networks. Malware.
Incident Response e Digital Forensics
Detection and processing of information incidents. Log analysis. Intrusion Detection Systems. Introduction to Digital Forensics.
Course entry requirements
Good knowledge of operating systems, database and computer networks technologies.
Course structure and teaching
Lectures (hours/year in lecture theatre): 32
Practical class (hours/year in lecture theatre): 10
Practicals / Workshops (hours/year in lecture theatre): 0
Suggested reading materials
Lecture Notes.
Testing and exams
Written test (open questions on all the program topics)
|