Lecturer:
Antonio Barili
Course name: Information security
Course code: 504718
Degree course: Bioingegneria, Computer Engeneering
Disciplinary field of science: ING-INF/05
L'insegnamento è caratterizzante per: Computer Engeneering
University credits: ECTS 6
Course website: http://lotarionline.unipv.it/
Specific course objectives
Knowledge of information and communication security techniques and applicable laws. Ability to assess the security level of some common software systems and to design improvement actions.
Course programme
Introduction
"Security" vs. "Safety". Physical security of computer systems and communication networks. People security and safety. Information security: privacy, avaliability, integrity and authenticity. Information security threats and countermeasures.
Basic Cryptography
Introduction to information theory, cryptography and steganography. Symmetric and asymmetric cryptography. Cryptographic algorithms. Hashing functions. Keys and certificates protection and distribution. Attacks and threats to cryptographic systems.
Digital Signature
Digital documents and digital signatures. Creation, preservation and validation of digital documents. Digital documents as trial court evidence. Public key infrastructures. Italian and EU laws.
Copyright Protection
Introduction to copyright law. Software and database protection. Audio, video and picture protection. Digital rights management (DRM). Applicable laws.
Communication Protection
Information communication and diffusion. Synchronous and asynchronous communication. E-mail. The Web as an information diffusion media. Communication privacy protection. Threats to the freedom and privacy of communications and countermeasures. Phishing.
Systems and Networks Protection
Access control: authentication, authorization and accounting. Phisical and logical information protection. Networks protection. Firewalls. Threats to systems and communication networks. Malware.
Incident Response e Digital Forensics
Detection and processing of information incidents. Log analysis. Intrusion Detection Systems. Introduction to Digital Forensics.
Course entry requirements
Good knowledge of operating systems, networking and data base technologies.
Course structure and teaching
Lectures (hours/year in lecture theatre): 45
Practical class (hours/year in lecture theatre): 0
Practicals / Workshops (hours/year in lecture theatre): 0
Suggested reading materials
Jason Andress. The Basics of Information Security - Understanding the Fundamentals of InfoSec in Theory and Practice. Elsevier Ltd, Oxford, 2011.
Adam J. Elbirt. Understanding and Applying Cryptography and Data Security. Auerbach, 2009.
Testing and exams
Written test.
|