Language-Based Security
Språkbaserad datasäkerhet
About the Syllabus
Grading scale
Course modules
Position
The course can be part of the following programmes:
- Computer Science, Master's Programme (N2COS)
- Software Engineering Master's Programme (N2SOF)
- Applied Data Science Master's Programme (N2ADS)
The course is a also a single-subject course at Gothenburg University.
Main field of study with advanced study
Entry requirements
- Bachelor´s degree in Computer Science or equivalent.
- Completed 15 hec in programming.
- Completed 7.5 hec in computer security.
Applicants must prove knowledge of English: English 6/English level 2 or the equivalent level of an internationally recognized test, for example TOEFL, IELTS.
Content
This course combines practical and cutting-edge research material. The course consists of lectures, labs, exercises and project presentations. The theme of attack-vulnerability-defense is threaded through all parts of the course.
More datails on the course conent:
Foundations of Language-based Security
- Introduction to language-based security
- Principles of information flow security
- Saltzer & Schroeder’s design principles for protection of information
Program Analysis and Security Mechanisms
- Static analysis and program transformation
- Reference monitoring and enforcement mechanisms
- Noninterference and secure multi-execution
Concurrency and Low-level Attacks
- Data races, randomness, and determinism
- Time-of-check to time-of-use (TOCTOU) vulnerabilities
- Buffer overruns and memory safety
Application and Platform Security
- Database security
- Android app security
- Copyright protection and code obfuscation
- JavaScript sandboxing
Web and Software Security
- Web application security (OWASP Top 10)
- Browser extension security
- Regular expression security (input validation, ReDoS)
- Security tooling and practical web security
Objectives
After completion of the course the student should be able to:
Knowledge and Understanding
- apply practical knowledge of security for modern programming languages
- demonstrate critical knowledge of principles behind application-level attacks (such as data races, buffer overrun attacks, web application attacks, covert channels, and malicious code)
- define language-based protection mechanisms (such as static and dynamic code analysis, program monitoring, and sandboxing)
Skills and Abilities
- identify application- and language-level security threats,
- specify and argue for application- and language-level security policies,
- design and claim the security, clarity, usability, and efficiency of solutions
- implement such solutions in expressive programming languages
Judgement Ability and Approach
- demonstrate the ability to judge which security mechanisms are appropriate for a given scenario
Sustainability labelling
Form of teaching
The course consists of lectures, labs, exercises and project presentations.
Language of instruction: English
Examination formats
The laboratory part is graded pass/fail and is worth of 3 hec. The project part is graded U/3/4/5, worth 4.5 hec. based on the project report and presentation.
If a student who has been failed twice for the same examination element wishes to change examiner before the next examination session, such a request is to be granted unless there are specific reasons to the contrary (Chapter 6 Section 22 HF).
If a student has received a certificate of disability study support from the University of Gothenburg with a recommendation of adapted examination and/or adapted forms of assessment, an examiner may decide, if this is consistent with the course’s intended learning outcomes and provided that no unreasonable resources would be needed, to grant the student adapted examination and/or adapted forms of assessment.
If a course has been discontinued or undergone major changes, the student must be offered at least two examination sessions in addition to ordinary examination sessions. These sessions are to be spread over a period of at least one year but no more than two years after the course has been discontinued/changed. The same applies to placement and internship (VFU) except that this is restricted to only one further examination session.
If a student has been notified that they fulfil the requirements for being a student at Riksidrottsuniversitetet (RIU student), to combine elite sports activities with studies, the examiner is entitled to decide on adaptation of examinations if this is done in accordance with the Local rules regarding RIU students at the University of Gothenburg.
Grades
Sub-courses
- Project, 4,5 credits
Grading scale: Pass with distinction (5), Pass with credit (4), Pass (3) and Fail (U) - Laboratory work, 3 credits
Grading scale: Pass (G) and Fail (U)
The grading scale comprises: Pass with distinction (5), Pass with credit (4), Pass (3) and Fail (U).
To pass the course, both of the laboratory and project parts need to be passed. The final grade on the course is determined by the grade on the project.
Course evaluation
The course is evaluated through meetings both during and after the course between teachers and student representatives. Further, an anonymous questionnaire is used to ensure written information. The outcome of the evaluations serves to improve the course by indication which parts could be added, improved, changed or removed.
Other regulations
The course is a joint course together with Chalmers.
The course replaces the course DIT101, 7.5 credits. The course cannot be included in a degree which contains DIT101. Neither can the course be included in a degree which is based on another degree in which the course DIT101 is included.