Introduction to cybersecurity for Generalists
James Davenport
University of Bath
16 May 2019
James Davenport Introduction to cybersecurity for Generalists 1 / 16
Introduction to cybersecurity for Generalists James Davenport - - PowerPoint PPT Presentation
Introduction to cybersecurity for Generalists James Davenport University of Bath 16 May 2019 James Davenport Introduction to cybersecurity for Generalists 1 / 16 CM50209: Security and Integrity Course is 6 ECTS (12 CATS) credits, in Semester
James Davenport Introduction to cybersecurity for Generalists 1 / 16
James Davenport Introduction to cybersecurity for Generalists 2 / 16
1 To develop an understanding of the difficulties of security -
2 To develop the ability to analyse the security threats to a
3 To develop the ability to propose realistic counter-measures,
1 describe common security models; 2 discuss what it means for a given system to be ’secure’; 3 identify security weaknesses in proposed systems. James Davenport Introduction to cybersecurity for Generalists 3 / 16
James Davenport Introduction to cybersecurity for Generalists 4 / 16
1 Introduction, resources [And08], CIA triangle. But “In
James Davenport Introduction to cybersecurity for Generalists 5 / 16
James Davenport Introduction to cybersecurity for Generalists 6 / 16
2 Cryptography for Security Engineers. Kerckhoffs’ Principle
3 PCI DSS [Pay18b, Pay18a]. Hosted compliance [UK 19b]. 4 SQL Injection (example of OWASP for CW2). Lack of
5 Passwords: attacks, salt [MT79], policies, secure storage.
6 Access controls (Unix permissions, ACL, setuid, etc.).
7 Vulnerability Scans versus Penetration Testing. PenTest tools
8 “Consolidation week”: no new material. James Davenport Introduction to cybersecurity for Generalists 7 / 16
9 Forensics Principles, ACPO “guidelines” [Ass12]. Importance
10 Guest Lecture (a CISO). Also two group presentations. 11 CSRF (prevented by Token-Based Mitigation, implemented by
12 Revision and Class Test. James Davenport Introduction to cybersecurity for Generalists 8 / 16
James Davenport Introduction to cybersecurity for Generalists 9 / 16
James Davenport Introduction to cybersecurity for Generalists 10 / 16
James Davenport Introduction to cybersecurity for Generalists 11 / 16
James Davenport Introduction to cybersecurity for Generalists 12 / 16
James Davenport Introduction to cybersecurity for Generalists 13 / 16
James Davenport Introduction to cybersecurity for Generalists 14 / 16
James Davenport Introduction to cybersecurity for Generalists 15 / 16
James Davenport Introduction to cybersecurity for Generalists 16 / 16