1. Course Description
This course offers foundational to intermediate knowledge in network security principles, mechanisms, and protocols. Topics include cryptography, key management, secure communication, authentication systems, and real-world security applications. Students will learn the security threats faced by modern networks and how to design systems to counteract them.
2. General Objectives
The general objectives of this course are;
- Understand the goals and fundamental principles of network security.
- Learn about symmetric and asymmetric cryptography.
- Explore security protocols like SSL/TLS, IPsec, and wireless security standards.
- Understand key management, authentication, and digital signatures.
- Learn basic system security concepts including firewalls and intrusion detection.
3. Contents in Detail
| Specific objectives | Contents |
|---|---|
| Unit I: Foundations of Security (6 Hours )
|
| Unit II: Cryptography Basics (8 Hours)
|
| Unit III: Network Security Mechanisms (6 Hours)
|
| Unit IV : Authentication & Key Management (6 Hours)
|
| Unit V: Transport & Application Security (6 Hours)
|
| Unit VI: Malware & Intrusion Detection (4 Hours)
|
| Unit VII: Cyber Laws & Ethics (7 Hours)
|
| Unit VIII: Emerging Trends (5 Hours)
|
Note: The figures in the parenthesis indicate the approximate teaching hours for the respective units.
4. Methods of Instructions
Lecture, Demonstration, Practical Lab, Discussion, Assignments, and Case Studies
5. Practical Activities: Lab Work
| SN | Lab Title | Unit | Tools/Environment | Key Activities | Expected Outcomes |
|---|---|---|---|---|---|
1 | Simulating Attacks & CIA Triad Analysis |
Unit 1 |
Kali Linux, Wireshark | DoS, spoofing, replay attacks, packet capture and analysis | Identify attacks that violate Confidentiality, Integrity, Availability |
2 | Access Control Models & Security Architecture |
Unit 1 | Linux VM (SELinux), User role tools | Configure MAC, DAC, RBAC; study Bell- LaPadula and Biba models | Demonstrate and compare access control implementations |
3 | Implementing Feistel Cipher & SPN | Unit 2 |
Python or Java | Code a 4-round Feistel cipher; implement basic SPN structure | Understand block cipher construction mechanisms |
4 | DES, 3DES & AES Symmetric Encryption |
Unit 2 |
OpenSSL, Python (pycryptodome) | Encrypt/decrypt files; compare DES, 3DES, AES in execution and key strength | Evaluate performance and security of symmetric encryption algorithms |
5 | RSA & Diffie- Hellman Key Exchange |
Unit 2 |
OpenSSL, Python | Generate RSA keys, encrypt/decrypt messages, simulate Diffie-Hellman key exchange | Understand public-key encryption and secure key sharing |
6 | Hashing & Digital Signatures | Unit 2 |
OpenSSL, Python | Create MD5, SHA-2 hashes; implement digital signatures using RSA and DSA | Ensure message integrity and non-repudiation |
7 | Configuring Firewalls & VPN | Unit 3 | pfSense, GNS3/VirtualBox, OpenVPN | Packet filtering, DMZ setup, implement OpenVPN between 2 networks | Deploy firewall rules and VPN for secure network access |
8 | Wireless Security Protocol Evaluation | Unit 3 | Kali Linux, aircrack-ng, Wireshark | Capture WPA2 handshake, attempt WEP cracking with wordlists | Analyze weaknesses in wireless protocols |
9 | Authentication & PKI Demonstration |
Unit 4 | OpenSSL, Kerberos, Linux tools | Simulate Kerberos, create X.509 certs, discuss biometric and multi-factor authentication | Implement and verify strong authentication techniques |
10 | SSL/TLS, HTTPS & Application Security | Unit 5 | Apache/NGINX, OpenSSL, Browser DevTools, DVWA | SSL/TLS handshake, setup HTTPS on server, explore SQL injection with DVWA | Configure secure web and transport protocols |
11 | Malware Analysis & Intrusion Detection | Unit 6 | Snort, Suricata, Cuckoo Sandbox | Detect malware in sandbox, simulate anomaly detection with Snort | Classify malware and analyze IDS alerts |
12 | Case Study: Cyber Laws, Ethics & Emerging Trends | Units 7 & 8 |
Web, Docs, Zoom/Meet | Research and present a real-world breach (blockchain/cloud/AI), debate privacy vs. security | Relate cyber threats with legal and ethical perspectives |
6. Evaluation System and Students’ Responsibilities
Evaluation System
The internal evaluation of a student may consist of assignments, attendance, term-exams, lab reports and projects etc. The tabular presentation of the internal evaluation is as follows:
| Internal Evaluation | Weight | Marks | External Evaluation | Marks |
|---|---|---|---|---|
| Theory | 30 | Semester End | 50 | |
| Attendance & Class Participation | 10% | |||
| Assignments | 20% | |||
| Presentations/Quizzes | 10% | |||
| Internal Assessment | 60% | |||
| Practical | 20 | |||
| Attendance & Class Participation | 10% | |||
| Lab Report/Project Report | 20% | |||
| Practical Exam/Project Work | 40% | |||
| Viva | 30% | |||
| Total Internal | 50 | |||
| Full Marks: 50 + 50 = 100 | ||||
Students’ Responsibilities
Each student must secure at least 45% marks separately in internal assessment and practical evaluation with 80% attendance in the class in order to appear in the Semester End Examination. Failing to get such score will be given NOT QUALIFIED (NQ) to appear the Semester-End Examinations. Students are advised to attend all the classes, formal exam, test, etc. and complete all the assignments within the specified time period. Students are required to complete all the requirements defined for the completion of the course.
7. Prescribed Books and References
Text Books
- William Stallings, Network Security Essentials: Applications and Standards, 4th edition, Pearson
References
- Charles P. Pfleeger, Shari Lawrence Pfleeger, Jonathan Margulies, Security in Computing, Fifth Edition, Prentice Hall.
- Matt Bishop, Introduction to Computer Security, Addison-Wesley.
- Behrouz Forouzan, Cryptography and Network Security, McGraw-Hill
- Charlie Kaufman, Network Security: Private Communication in a Public World, Prentice Hall
- NIST Publications, OWASP.org Resources