2 項進行中

115-1 選課時程

進行中

  • 初選第一階段 6/15 – 6/18
  • 初選第二階段 6/22 – 6/25
  • 校際選修 進行中 8/24 – 9/18
  • 初選第三階段 8/31 – 9/3
  • 開學後加退選 進行中 9/7 – 9/21
  • 逾期加退選 9/21 – 9/24
選課資源

加入行事曆

選擇訂閱 Google Calendar,或下載通用的 ICS 檔案。

使用 Google Calendar 時,Google 會收到這份課表的公開連結。

程式安全

Secure Programming

學期
107-1
學分
0 學分
當期課號
5212
永久課號
IOC5087
開課單位
資訊科學與工程研究所
授課教師
黃俊穎、黃世昆
校區
光復
類別
選修
上課時間表
週五
2
09:00–09:50
程式安全
EC324(光復)
3 節連堂
3
10:10–11:00
4
11:10–12:00

* 根據陽明交大上課時間表所列

概述

We will introduce how software quality and programming practices related issues will influence the overall system security. The students can learn the principles of writing secure code, practice several analysis techniques and writing exploit for assuring software security. 我們將介紹軟體品質與程式寫作議題,探討與整體系統安全的相關性。學生將以練習程式安全相關攻擊技術為主,撰寫與開發軟體安全脅迫程式。

先修科目

Programming Languages, Assembly, C and C++ programming languages are required. Unix System and Scripting (python, ruby...) experiences are recommended. 程式語言與組合語言為必備能力。最好有Unix 系統與 Script 語言經驗。

備註

無備註

教學方式

課堂教學將與台大、台科大課程網路同步教學,並輔以課堂實際操作、進行資安攻防演練。開學前將有修課資格測驗,原則上必須通過此測驗,我們才建議修此課程。

評分方式

? Final exam: 25% On-site bug analysis and exploit development. ? We will have the joint final exam with NTU/NTUST related courses lasting two days in CTF style of challenges. ? Online CTF of Secure Coding: 65% ? Misc. 10% Attending CTF competitions is encouraged

課程大綱
  • Static Analysis and Binary Exploits

    1. Data Flow Analysis 2. Control Flow Analysis 3. Reverse Engineering of Binary Executable files

    講授:
    4
    示範:
    1
    實作:
    1
  • Symbolic Execution and Fuzz Testing

    1. Software Testing 2. Fuzz Testing 3. Symbolic and Concolic Testing 4. Debugging Techniques

    講授:
    4
    示範:
    2
    實作:
    2
  • Exploits

    1. Command injection 2. Smashing the stack 3. Heap Feng Shui 4. Format String 5. Writing shellcode 6. Automatic Exploit Generation

    講授:
    10
    示範:
    2
    實作:
    2
  • Crypto

    1. Crypto Analysis 2. Crypto Implementation flaws

    講授:
    10
    示範:
    1
    實作:
    1
  • Web Applications

    1. Input Validation 2. Cross-site scripting 3. SQL injection

    講授:
    6
    示範:
    2
    實作:
    2
  • Overview

    1. Introduction to Software Security 2. Software Quality Problems 3. Bugs, Vulnerabilities, Exploits

    講授:
    2
    示範:
    1
    實作:
    1
週次計畫
週次主題
第 1 週

Outline and overview

第 2 週

Introduction

第 3 週

Basic Tools & Concept

第 4 週

Web+Reverse I

第 5 週

Web+Reverse II

第 6 週

Web+Reverse III

第 7 週

Crypto + MISC

第 8 週

Crypto + MISC

第 9 週

Crypto + MISC

第 10 週

Mid-term Exam

第 11 週

Symbolic Execution + Fuzz Testing

第 12 週

Symbolic Execution + Fuzz Testing

第 13 週

Symbolic Execution + Fuzz Testing

第 14 週

Symbolic Execution + Fuzz Testing

第 15 週

Binary Exploits

第 16 週

Binary Exploits

第 17 週

Binary Exploits

第 18 週

final exam (joint exam with NTU/NTUST related courses in CTF style)

教科書

參考書目: 1. Brian Chess and Jacob West, “Secure Programming with Static Analysis”, Addison Wesley Professional , 2007, ISBN-10: 0-321-42477-8. 2. Robert C. Seacord, “Secure Coding in C and C++”, 2006 Pearson Education, Inc. 3. Michael Howard and Davide LeBlanc, “Writing Secure Code”, 2006 Microsoft Press. 4. Mark G. Graff and Kenneth R. van Wyk, “Secure Coding Principles and Practices”, 2003 O’Reilly and Associates, Inc

Office Hours
地點
教師未提供此項資料
時間
教師未提供此項資料
聯絡方式
chuang@cs.nctu.edu.tw skhuang@cs.nctu.edu.tw