InfSec2013

Security in Information Systems

  • This is a regular course at Cinvestav

Description

  • This course is organized in four fundamental parts. The first part is the introduction to the information security topics. The second part will cover the basic aspects in the construction of a firewall. The third part will review the basic cryptography aspects to provide security services and some applications. The last part will review some of the tools available for the security expert.

Objective

  • Review the general topics on the information security that affects the information systems.

Organization

  • This course is offered both at Cinvestav Zacatenco (main campus), and at Cinvestav Tamaulipas (this campus)
  • The lectures will be offered by 3 professors: Luis Gerardo de la Fraga, Arturo Díaz, and Luis Domínguez.
  • There will be a practice test, and a written exam on each section (excluding the introduction)
  • The final mark will be according to the number of weeks taken by each section

Topics

  1. Introduction, by Luis Dominguez (1 week)
    • Introduction to information security, and to the course
    • General concepts on information security
    • Network diagram for the laboratory
  2. Firewall section, by Luis Gerardo de la Fraga (4 weeks)
  3. Cryptography (4 weeks)
    • Introduction to cryptography
      • Introduction to cryptography
      • Symmetric cryptography
      • Asymmetric cryptography
      • Public Key Infrastructure (PKI)
    • Cryptography in the information security
      • Digital signature
      • SSL
      • Modern viruses
      • e-Voting, e-Cash
      • Privacy and Security
  4. Tools for information security (5 weeks)
    • See professor's website at Cinvestav Tamaulipas (link not available yet)

Grades (For part 2)

No. Concepto Porcentaje
1 Examen 30
2 Proyecto 1 10
3 Proyecto 2 15
4 Monografía/Exposisión 15
5 Proyecto 3 30
# Total 100

Projects (For part 2)

# Concept Delivery
1 SHA-3 en Magma 2013-06-24
2 PKI: web server and email 2013-07-01
M Essay/presentation 2013-07-98
3 Final project 2013-07-14

Essay options (For part 2)

  • RC4
  • Biometric authentications
  • WEP and WAP
  • Cloud security
  • PGP

Project 3 options (For part 2)

  • Mi Solcedi
  • Security analysis of electronic invoice from SAT Mexico
  • Time-stamps protocol implementation
  • Long-Term Archive and Notary Services implementation
  • BitCoin analysis, software implementation, mining
  • Denuncia Anómina system
  • Electronic Money proposal
  • Simple electronic voting system
  • Brute force attack
  • Document signing system
  • Anonymous feedback to lecturer performance
  • Smartphone authentication
  • Security and Privacy in social networks
  • Secure log
  • Security policies
  • Any Security Software Proposal.

Rules part2

  • Email delivery only to ldominguez
  • Pack your homework and name the file appropriately: t1_lastname.zip
  • Use PGP to encrypt your file. Public Key
  • Time delivery is at mid-night of the day, 10\% penalty per delayed day
  • No plagiarism
  • Include bibliography on risk to the expelled
  • Add documentation in LNCS format to your homework:
    • For programs, 2-4 pages
    • Papers, 5-7 pages

Slides (For part2)

Extras