OPERATING SYSTEMS SECURITY
- Course
- ITSE472 - OPERATING SYSTEMS SECURITY
- Department
- Information Technology Security - English - Undergraduate
- Course Type
- Course
- Status
- Required
- Language
- English
- Credit
- 3
- ECTS
- 0
- T+P+L
- 3 + 0 + 0
- Course Coordinator(s)
- -
- Prerequisite
- -
Course Description
This course covers both the fundamentals and advanced topics in operating system (OS) security. Access control mechanisms (e.g., SACL/DACL), memory protections, and interprocess communications mechanisms will be studied. Students will learn the current state-of-the-art OS-level mechanisms and policies designed to help protect systems against sophisticated attacks. In addition, advanced persistent threats, including rootkits and malware, as well as various protection mechanisms designed to thwart these types of malicious activities, will be studied. Advanced kernel debugging techniques will be applied to understand the underlying protection mechanisms and analyze the malicious software. Students will learn both hardware and software mechanisms designed to protect the OS (e.g., NX/ASLR/SMEP/SMAP).
OPERATING SYSTEMS SECURITY
Evaluation Tools (Active Term)
No evaluation items have been defined.
Course outcomes
No course outcomes have been defined yet.
Course Syllabus
| Week | Topic |
|---|---|
| Week 1 | Introduction to OS Security |
| Week 2 | Unix/Linux Security Fundamentals |
| Week 3 | User Authentication and Access Control |
| Week 4 | File systems Security |
| Week 5 | Common OS Vulnerabilities |
| Week 6 | Firewalls |
| Week 7 | Homework Presentation |
| Week 8 | Secure shell |
| Week 9 | Operating Systems Scripting |
| Week 10 | Midterm Exams |
| Week 11 | Midterm Exams |
| Week 12 | Project Presentation |
| Week 13 | Project Presentation |
| Week 14 | Project Presentation |
| Week 15 | Revision |
Reference Books & Course Materials
- 01 Operating System Security by Trent Jaeger, 3rd edition , 2022
Learning Outcomes
- L01 Describe the fundamental principles and components of operating system security, including the role of the kernel, user accounts, and privilege levels. SOLO 3
- L02 Configure and evaluate Unix/Linux security features such as file permissions, user management, access controls, and SELinux/AppArmor frameworks. SOLO 5
- L03 Apply authentication and access control mechanisms, including password policies, Role-Based Access Control (RBAC), and Pluggable Authentication Modules (PAM). SOLO 4
- L04 Assess the security implications of file systems and implement methods for securing data, including encryption, permissions, and file integrity monitoring. SOLO 4.5
- L05 Identify and analyze common operating system threats and vulnerabilities, including privilege escalation, buffer overflows, and race conditions SOLO 3
- L06 Demonstrate the use of host-based firewalls, such as iptables on Linux and Windows Firewall, to control and monitor network traffic. SOLO 4
- L07 Design and evaluate homework-based security solutions with technical justification and peer collaboration. SOLO 5
- L08 Implement secure shell (SSH) practices for remote access, key-based authentication, and tunneling to protect system communications. SOLO 4
- L09 Create and develop operating system-level scripts that automate security tasks, audit logs, or user controls using Bash or PowerShell. SOLO 5
- L10 Demonstrate applied knowledge of OS security through exam-based assessments and a final project presentation with documentation and practical demonstration SOLO 4
Program Outcomes
- P01 Demonstrate comprehensive knowledge of key concepts across the breadth of effective application and use of MIS and innovative information technologies in organizations.
- P02 Demonstrate autonomy and responsibility in managing MIS projects and improving organizational processes
- P03 Demonstrate comprehensive understanding of appropriate enterprise frameworks, theories from the MIS to research and assess contemporary issues in the field and related allied fields and disciplines
- P04 Apply MIS knowledge to facilitate the acquisition, development, deployment, and management of information systems
- P05 Apply MIS knowledge to the exploitation of opportunities created by information technology innovations ensuring the alignment between MIS strategy and organizational strategy
- P06 Demonstrate ethical reasoning in relation to crucial MIS issues such as privacy, information security, and ethical use of information
- P07 Apply appropriate technologies and techniques to the collection and analysis of organizational and environmental data to facilitate evidence-based decision-making
- P08 Analyse organizational data to accurately identify organizational problems and propose solutions using MIS
- P09 Apply effective communication skills consistent with the professional environment
- P10 Apply effective collaboration skills consistent with the professional environment
Po-Lo Matrix
| LO | P01 | P02 | P03 | P04 | P05 | P06 | P07 | P08 | P09 | P10 | Average |
|---|---|---|---|---|---|---|---|---|---|---|---|
| L01 | - | - | - | - | - | - | - | - | - | - | - |
| L02 | - | - | - | - | - | - | - | - | - | - | - |
| L03 | - | - | - | - | - | - | - | - | - | - | - |
| L04 | - | - | - | - | - | - | - | - | - | - | - |
| L05 | - | - | - | - | - | - | - | - | - | - | - |
| L06 | - | - | - | - | - | - | - | - | - | - | - |
| L07 | - | - | - | - | - | - | - | - | - | - | - |
| L08 | - | - | - | - | - | - | - | - | - | - | - |
| L09 | - | - | - | - | - | - | - | - | - | - | - |
| L10 | - | - | - | - | - | - | - | - | - | - | - |