Contact: andrew@cs.unc.edu
Class Meetings: Mon/Wed 1:25-2:40PM, SN011
Office Hours By Appointment, in FB340
Syllabus
The goal of this course is to give students a broad overview of research topics in the field of computer security. This involves reading and discussing both foundational and recent papers, and conducting a course research project.
Course Structure
Grades will be based upon the following:Class Participation (20%)
Students are expected to contribute to class discussions following paper presentations. Students should be able to ask insightful questions and demonstrate that they have read and understand the assigned readings.
Paper Presentations (20%)
Students will give conference style talks on assigned papers. They will prepare slides and a 15 minute presentation on the papers.
Paper Reviews (20%)
Students will submit mini-reviews on assigned papers to Canvas.
Course Project (40%)
Students will conduct original research on a topic related to computer security over the course of the semester. Students will propose a project part-way through the class, and will submit a final report (6-12 pages) by the end of the course. Students will also give a conference style talk on their results during the final week of class. Working in groups is allowed, but a more substantial product is expected when working as a group.
Reading List
Welcome
Monday, August 17 — Welcome/Course Overview
SlidesWednesday, August 19 — Instructor Presents
Binary Exploitation
Monday, August 24 — Stack Smashing
- Smashing The Stack For Fun And Profit. Aleph One. Phrack 49(14), Nov. 1996.
- StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks. USENIX Security 1998.
Wednesday, August 26 — Advanced Pwning
Side-Channels
Monday, August 31
- FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. USENIX Security 2014.
- KeyTAR: Practical Keystroke Timing Attacks and Input Reconstruction. Oakland 2026.
Wednesday, September 2
- Hey, You, Get Off of My Cloud: Exploring Information Leakage in Third-Party Compute Clouds. Ristenpart Tromer, Shacham, and Savage. CCS 2009.
- Spectre attacks: Exploiting Speculative Execution. Oakland 2019.
Nation State Attacks
Monday, September 7
No Class-Labor DayWednesday, September 9
Cyber-Physical Systems
Monday, September 14
- Experimental Security Analysis of a Modern Automobile. Oakland 2010.
- Comprehensive Experimental Analyses of Automotive Attack Surfaces. USENIX Security 2011.
Wednesday, September 16
- Security Analysis of a Full-Body Scanner . USENIX Security 2014.
- Pacemakers and Implantable Cardiac Defibrillators: Software Radio Attacks and Zero-Power Defenses. Oakland 2008.
Proposals
Monday, September 21
No Class-Well-Being DayWednesday, September 23 — Proposal Presentations
Course Project Proposal Presentations
Monday, September 28 — Proposal Presentations
Wednesday, September 30 — Proposal Presentations Continued
Browser Security
Monday, October 5
- Native Client: A Sandbox for Portable, Untrusted x86 Native Code. Oakland 2009.
- Retrofitting Fine Grain Isolation in the Firefox Renderer. USENIX Security 2020.
Wednesday, October 7
- Exploiting the DRAM rowhammer bug to gain kernel privileges. Google blog post, 2015.
- SMASH: Synchronized Many-sided Rowhammer Attacks from JavaScript. Usenix Security 2021.
Botnets/Spam
Monday, October 12
- Your Botnet is My Botnet: Analysis of a Botnet Takeover. CCS 2009.
- Understanding the Mirai Botnet. USENIX Security 2017.
Wednesday, October 14
- Detecting and Characterizing Lateral Phishing at Scale. USENIX Security 2019.
- A Large-Scale Study of Personalized Phishing using Large Language Models. USENIX Security 2026.
AI Security
Monday, October 19
Wednesday, October 21
- Extracting Training Data from Large Language Models. USENIX Security 2021.
- Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models. USENIX Security 2024.
Crypto Fails/Privacy
Monday, October 26 — Real World Cryptography
Wednesday, October 28 — Privacy
- BlindBox: Deep Packet Inspection over Encrypted Traffic. SIGCOMM 2015.
- Zerocash: Decentralized Anonymous Payments from Bitcoin. Oakland 2014.
Human Factors
Monday, November 2 — Usability
- Why Johnny Can't Encrypt: A Usability Evaluation of PGP 5.0.. USENIX Security 1999
- Alice in Warningland: A Large-Scale Field Study of Browser Security Warning Effectiveness. USENIX Security 2013.
Wednesday, November 4 — Passwords
Tracking
Monday, November 9
— Anonymous Browsing
-
Tor: The Second-Generation Onion Router.
USENIX Security 2004.
-
How Unique Is Your Web Browser?.
PETS 2010
Wednesday, November 11 — Web/Device Tracking
Memory/Election Security
Monday, November 16 — Disturbance Effects/Forensics
- BadRAM: Practical Memory Aliasing Attacks on Trusted Execution Environments. Oakland 2025
- Lest We Remember: Cold Boot Attacks on Encryption Keys. USENIX Security 2008.