Computer and Network Security
by
Avinash Kak


Think of these lecture notes as a living textbook that strives to strike a balance between the systems-oriented issues and the cryptographic issues. Without the latter, many aspects of the former cannot be fully comprehended, and, without the former, the latter are too dry to appreciate.

Note for instructors using these slides/notes:

It is not uncommon for the instructors who use these notes/slides to want to know how exactly I use them in class since there is much more information on a typical slide than you will usually find in a powerpoint presentation.

Here is the answer:    When I teach the theoretical portions of this course, I actually work out the formulas on the chalkboard and, when I do so, I follow the derivations presented in these lecture notes.   On the other hand, when I teach the systems portion of the course, I spend quite a bit of time demonstrating the issues on my Linux laptop, again in the manner described in these lecture notes.   These lecture notes are intended as much for showing in class in the form of slides as they are for focused reading by the students on their own. When used as slides, these serve as backdrop to the explanations provided on the chalkboard or through demonstrations on a computer.


Regarding homework assignments:

Homework assignments typically involve writing Perl or Python scripts in order to gain a deeper understanding of the ideas through actual implementation. (From a pedagogical standpoint, scripting is much more efficient for this than writing code in raw C.)   In the part of the course that deals with encryption and hashing, students write scripts for implementing DES, AES, RC4, SHA1, SHA512, etc.   In the part of the course that deals with more system related issues, the students are asked to write scripts that carry out DoS attacks, buffer overflow attacks, etc., against servers (for buffer overflow attacks, that would be a socket program in C with intentionally embedded buffer-overflow vulnerability).

If you are an instructor and you'd like to see these homework assignments (along with the two best solutions submitted by the students at Purdue), send me a note at kak@purdue.edu. If you do so, please place the string "requesting security homework" in your subject line to get past my merciless spam filter. VERY IMPORTANT: Your email request for this material must establish two things: that you are an instructor and that you are using these lecture notes to teach your class. An anonymous email request (using, say, a gmail or a yahoomail address) that does not indicate your institutional affiliation will be ignored.


Useful resources for homework assignments:
  1. If you are writing Perl and/or Python scripts for solving homework problems or for course projects, you will find the book "Scripting with Objects" a useful resource for this course. Chapters 2 and 3 of the book provide quick and easy-to-follow introductions to Perl and Python, respectively.

  2. The BitVector class in Python is useful for creating compact implementations for hash functions (see Lecture 15 for an example) and for writing scripts for block and stream ciphers.

  3. If you'd rather do your homework in C++ or Java, you will find the book "Programming With Objects" a useful resource. This book is now being used at a number of universities for teaching object-oriented programming in both C++ and Java simultaneously.
When will this material be updated next?:

The 2013 update of the lecture notes has been completed. The next serious update of this material is scheduled for the January – April 2014 time frame.


Lecture Notes
1.   Introductory material, course administration handout, etc.
2.   Classical Encryption Techniques Updated March 13, 2014 download code
3.   Block Ciphers and the Data Encryption Standard Updated March 13, 2014 download code
4.   Finite Fields (PART 1): Groups, Rings, and Fields Updated April 10, 2014
5.   Finite Fields (PART 2): Modular Arithmetic Updated February 4, 2014 download code
6.   Finite Fields (PART 3): Polynomial Arithmetic Updated January 31, 2014
7.   Finite Fields (PART 4): Finite Fields of the Form GF(2n)   Updated February 5, 2014 download code
8.   AES: The Advanced Encryption Standard Updated March 6, 2014
9.   Using Block and Stream Ciphers for Secure Wired and WiFi
  Communications
Updated March 12, 2014 download code
10.   Key Distribution for Symmetric Key Cryptography and
  Generating Random Numbers
Updated March 1, 2014 download code
11.   Prime Numbers and Discrete Logarithms Updated March 4, 2014 download code
12.   Public-Key Cryptography and the RSA Algorithm Updated March 1, 2014 download code
13.   Certificates, Certificate Authorities, and Digital Signatures Updated March 6, 2014
14.   Elliptic Curve Cryptography and Digital Rights Management Updated March 21, 2014 download code
15.   Hashing for Message Authentication Updated March 11, 2014 download code
16.   TCP/IP Vulnerabilities: IP Spoofing and Denial-of-Service Attacks Updated March 12, 2014 download code
17.   DNS and the DNS Cache Poisoning Attack Updated March 27, 2014 download code
18.   Packet Filtering Firewalls (Linux) Updated April 1, 2014 download code
19.   Proxy-Server Based Firewalls Updated April 1, 2014 download code
20.   PGP, IPSec, SSL/TLS, and Tor Protocols Updated April 14, 2014
21.   The Buffer Overflow Attack Updated April 8, 2014 download code
22.   Malware: Viruses and Worms Updated April 15, 2014 download code
23.   Port and Vulnerability Scanning, Packet Sniffing, Intrusion
  Detection, and Penetration Testing
Updated April 15, 2014
24.   Dictionary Attacks and Rainbow-Table Attacks on Password
  Protected Systems
Updated April 16, 2014
25.   Security Issues in Structured Peer-to-Peer Networks Updated April 16, 2014
26.   Small-World Peer-to-Peer Networks and Their Security Issues Updated April 17, 2014 download code
27.   Web Security: PHP Exploits and the SQL Injection Attack Updated April 17, 2014 download code
28.   Web Security: Cross-Site Scripting and Other Browser-Side
  Exploits
Updated April 17, 2014 download code
29.   Bots and Botnets Updated April 20, 2014 download code
30.   Mounting Targeted Attacks with Trojans and Social Engineering
  --- Cyber Espionage
Updated April 15, 2014
31.   Filtering Out Spam Updated April 17, 2014 download code
32.   Index   (HTML) Updated April 28, 2013



Follow me on Twitter if you want to be automatically informed of when the updates to these lectures are completed each year.

A BRIEF HISTORY: These lecture notes, at least several of them, made their first appearance on the web in 2006. They have so far gone through six major revisions. With each revision I have attempted to improve the explanations on the basis of the feedback I receive from the students at Purdue and from other users of these notes. Regarding the notes that deal with the systems side of security, I have tried to seek out the best ways to combine the explanation of the concepts and their demonstration on a laptop keeping in the mind the time constraints of a typical lecture period.

HOW CAN YOU BE SURE YOU HAVE THE LATEST UPDATED VERSION OF A LECTURE: As I am thinking about the material and teaching it in class, a lecture may go through as many as a dozen updates. If you are tracking my updates, the only way you can be certain you have the final version of an updated lecture is to check on the last day of the month shown in the update column. The actual posting date for each lecture as it is being revised is shown on the first page of the lecture.

EXPERIENCING PROBLEMS? If you experience any problems with downloading or using any of these PDF files, please send an email to kak@purdue.edu  with the string "Problem with computer security notes"   in the subject line to get past my spam filter.

FEEDBACK WELCOME! If you have any comments or any suggestions for improving these notes, please send an email to kak@purdue.edu  with the string  "Comments on computer security notes"   in the subject line to get past my spam filter. Any suggestions that I incorporate would be duly acknowledged.

WOULD YOU LIKE TO CONTRIBUTE A HOMEWORK PROBLEM OR A PROJECT? My goal is for these notes to become self-contained as a medium of instruction in computer and network security. Toward that end, I'd like to end the notes for each lecture on a set of homework problems and/or projects. If you send me a problem or a project, your name will be mentioned as the author of that problem or project. If you submit a project, please make sure that it can be done in one or two weeks' time in some high-level language. I'll certainly include the problems and projects I currently give out when teaching this material, but any contributions made by others using these lecture notes would add to the variety. If you choose to send me a problem or a project, email it to  kak@purdue.edu  with the string "homework for computer security notes" in the subject line.

SAVE THIS INFORMATION IN A SAFE PLACE: If you are a frequent user of this material, please note that every once in a long while you may find the web server hosting this material to be down for one reason or another. Usually these outages do not last more than a few minutes, but on occasion they have been known to last a few hours (although that is extremely rare). If you cannot access this material but you have an urgent need to do so, send an email immediately to kak@purdue.edu  with the string  "Unable to access computer security notes"   in the subject line to get past my spam filter. I should be able to provide you with a URL to another web server hosting this material.


Valid HTML 4.01 Transitional Valid CSS!