Planning
According to the UA academic schedule, classes will be lectured from September 14th, until December 19th. The subject is structured as 2 hours of theoretical lectures, 2 hours of practical laboratories, and 1 hour of tutoring hours (optional).
Theoretical classes will present key concepts related to the application of security to modern information systems, and organizations. The practical classes will be focused in the exploration of security mechanisms, and in the exploration and analysis of common security attacks.
The topics lectured in each class should be as follows. Changes may happen, so please check it frequently.
Rules
Faculty and Lectures
- The team will be composed by João Paulo Barraca, Alfredo Matos and Paulo Bartolomeu
- Teaching staff will be available especially during the allocated tutoring slots.
- Official course information will be available on this page, or through the Elearning platform.
- Classes will be lectured in Portuguese, unless a foreign student is attending. In this case English will be used.
- All Lecture Notes, Projects and Laboratory guides will be made available in English only.
Attendance
- Students can choose to attend the theoretical classes, and is highly recommended they do so every week as it correlates with a good outcome.
- Attendance to practical classes is mandatory and faults will be recorded. Students must be present at (at least) 70% of the practical classes. For this edition that results in a maximum of 4 unjustified faults.
- If student exceed the number of faults allowed, they will automatically fail the subject and won’t be allowed at any other evaluation during the current academic year.
Grading
Grading will be composed by two components (T and P), each contributing with 50% to the final grade. Both components are mandatory and have a minimum threshold.
-
Theoretical Component: Includes the contents lectured during theoretical lectures and the Mandatory reading materials.
- 1 (One) exam (E1), composed by 2 (two) parts (T1 and T2), covering all contents lectured (T or P).
- T1 will be provided in mid November.
- T2 will be provided in the Exam Season.
- Final Theoretical Grade: (T1 + T2)
- Minimum points of this component: 7 pts over 20. (i.e. $ T1 + T2 >= 7 $)
- 1 (One) exam (E1), composed by 2 (two) parts (T1 and T2), covering all contents lectured (T or P).
-
Practical Component:
-
Development of practical project by a group of students.
- Project will focus on the application of the lectured concepts in the development of a small system.
- Grading of the project will focus on the deliverables and a defense.
-
Assessment of the knowledge regarding the Practical Laboratories.
- Conducted as written tests (PT1 and PT2) at the same times as T1 and T2.
-
Minimum points of this component: 7 pts over 20 (i.e. $ project + PT1 + PT2 >= 7$ )
-
The following table summarizes the points of each component:
| Component | Item | Weight |
|---|---|---|
| P | Project | 25% |
| P | PT1 | 12.5% |
| P | PT2 | 12.5% |
| T | T1 | 25% |
| T | T2 | 25% |
Repeat Exam season
- The Repeat Exam Season takes place after the Normal Season. It is automatically available for all students that failed to obtain at least 9.50 points during the Normal Season, or 7 at one of the components.
- The remaining students may also access this season, after an administrative process is initiated by the student, and the professors are informed.
Special season
- The special season usually takes place in September and is available to students in specific cases. Accessing this season will require an additional administrative process.
Additional Content
Software
- Bettercap: The Swiss Army knife for WiFi, Bluetooth Low Energy, wireless HID hijacking and Ethernet networks reconnaissance and MITM attacks.
- Wireshark: The most popular packet sniffer application.
- WebGoat: A deliberately insecure web application maintained by OWASP designed to teach web application security lessons.
- Kali Linux: A popular Penetration Testing Distribution.
- John the Ripper: A password Cracker.
- Hashcat: Advanced Password Recovery tool, especially tailored at OpenCL.
- nmap: Probably the most famous port scanner and reconnaissance tool.
Websites
- TryHackMe: Beginner friendly website for cybersecurity training.
- GameOfHacks: Identify common programming errors that lead to security issues.
- Let’s Encrypt: A free, automated and open Certification Authority.
- Bruce Schneier Blog: A very interesting blog dedicate to security and cryptography.
- SANS Technology Institute: Best Security Books
- Reddit NetSec and NetSecStudents
- Reddit NetSec Books Galore
- Hacking Secret Ciphers With Python
- CVE Details
- PicoCTF: Beginner friendly challenges for your curiosity