Skip to main content
TR

OPERATING SYSTEMS SECURITY

Course
ITSE472 - OPERATING SYSTEMS SECURITY
Department
Information Technology Security - English - Undergraduate
Course Type
Course
Status
Required
Language
English
Credit
3
ECTS
0
T+P+L
3 + 0 + 0
Course Coordinator(s)
-
Prerequisite
-
Keywords

Course Description

This course covers both the fundamentals and advanced topics in operating system (OS) security. Access control mechanisms (e.g., SACL/DACL), memory protections, and interprocess communications mechanisms will be studied. Students will learn the current state-of-the-art OS-level mechanisms and policies designed to help protect systems against sophisticated attacks. In addition, advanced persistent threats, including rootkits and malware, as well as various protection mechanisms designed to thwart these types of malicious activities, will be studied. Advanced kernel debugging techniques will be applied to understand the underlying protection mechanisms and analyze the malicious software. Students will learn both hardware and software mechanisms designed to protect the OS (e.g., NX/ASLR/SMEP/SMAP).

OPERATING SYSTEMS SECURITY

Evaluation Tools (Active Term)

No evaluation items have been defined.

Course outcomes

No course outcomes have been defined yet.

Course Syllabus

Week Topic
Week 1 Introduction to OS Security
Week 2 Unix/Linux Security Fundamentals
Week 3 User Authentication and Access Control
Week 4 File systems Security
Week 5 Common OS Vulnerabilities
Week 6 Firewalls
Week 7 Homework Presentation
Week 8 Secure shell
Week 9 Operating Systems Scripting
Week 10 Midterm Exams
Week 11 Midterm Exams
Week 12 Project Presentation
Week 13 Project Presentation
Week 14 Project Presentation
Week 15 Revision

Reference Books & Course Materials

  1. 01 Operating System Security by Trent Jaeger, 3rd edition , 2022

Learning Outcomes

  1. L01 Describe the fundamental principles and components of operating system security, including the role of the kernel, user accounts, and privilege levels. SOLO 3
  2. L02 Configure and evaluate Unix/Linux security features such as file permissions, user management, access controls, and SELinux/AppArmor frameworks. SOLO 5
  3. L03 Apply authentication and access control mechanisms, including password policies, Role-Based Access Control (RBAC), and Pluggable Authentication Modules (PAM). SOLO 4
  4. L04 Assess the security implications of file systems and implement methods for securing data, including encryption, permissions, and file integrity monitoring. SOLO 4.5
  5. L05 Identify and analyze common operating system threats and vulnerabilities, including privilege escalation, buffer overflows, and race conditions SOLO 3
  6. L06 Demonstrate the use of host-based firewalls, such as iptables on Linux and Windows Firewall, to control and monitor network traffic. SOLO 4
  7. L07 Design and evaluate homework-based security solutions with technical justification and peer collaboration. SOLO 5
  8. L08 Implement secure shell (SSH) practices for remote access, key-based authentication, and tunneling to protect system communications. SOLO 4
  9. L09 Create and develop operating system-level scripts that automate security tasks, audit logs, or user controls using Bash or PowerShell. SOLO 5
  10. L10 Demonstrate applied knowledge of OS security through exam-based assessments and a final project presentation with documentation and practical demonstration SOLO 4

Program Outcomes

  1. P01 Be able to understand and apply security protocol and tools to security challenges faced in organizations
  2. P02 Be able to design security software to combat security issues
  3. P03 Be able to identify, categorize, and develop security solutions for computer orientated challenges.
  4. P04 Be able to demonstrate autonomy and responsibility in managing computer security projects
  5. P05 Be able to follow the state of the arts concepts in computer technology security
  6. P06 Be able to design, implement, and evaluate a computational system to meet desired security needs within realistic constraints
  7. P07 Be able to use appropriate security techniques, protocols, skills, and tools necessary for securing computer systems
  8. P08 Be able to apply effective communication skills consistent with the professional environment
  9. P09 Be able to apply effective collaboration skills in teamwork consistent with the professional environment
  10. P10 Be able to apply appropriate security technology and techniques to facilitate a safe operation in an organization

Po-Lo Matrix

LO P01 P02 P03 P04 P05 P06 P07 P08 P09 P10 Average
L01 5 0 3 0 4 2 3 0 0 2 1.9
L02 2 4 2 0 2 4 5 0 0 3 2.2
L03 3 2 4 0 2 3 5 0 0 5 2.4
L04 3 2 4 0 2 3 5 0 0 5 2.4
L05 2 0 5 0 4 2 3 0 0 2 1.8
L06 2 2 3 0 2 4 5 0 0 5 2.3
L07 0 0 2 4 0 2 2 5 5 2 2.2
L08 2 2 3 0 2 3 5 0 0 5 2.2
L09 2 5 3 0 2 4 5 0 0 3 2.4
L10 2 2 3 5 2 5 4 4 5 3 3.5