Educational objectives Educational goals:
To be able to design and evaluate a biometric or multibiometric system.
To know the features and basic techniques related to physical biometric identifiers, such as face, fingerprint, iris, etc., and behavioral, such as gait, signature (dynamic), voice, typing mode, etc. Architecture of a biometric system: unimodal systems and multibiometric architectures. To be able to evaluate the performance of a biometric system according to the adopted modality: verification and identification. To be able to evaluate/assure the robustness of a biometric system against spoofing attacks (identity theft).
Knowledge and understanding:
Fundamentals of design of a biometric system and of the techniques to extract/match the specific characteristics for the main biometric traits.
Applying knowledge and understanding:
To be able to design and implement an application for biometric recognition for at least one biometric trait.
Making judgments:
To be able to assess the performance and robustness of a biometric system to presentation attacks. To be able to transfer techniques and protocols in different contexts.
Communication skills:
To be able to communicate/share the requirements of a biometric system, the most suited modalities for a certain application, and the performance measures of a system.
Learning skills:
To be able to autonomously get a deeper insight on the course topics, in relation to either specific/complex techniques and methods, or to biometric traits not covered in the course.
|
Educational objectives General Objectives
The main objective of the course is to provide the fundamentals of system programming.
Specific Objectives
Students will be able to independently develop programs that interact with the operating system and exploit its services.
Knowledge and Understanding
Knowledge of the C programming language and of the tools normally available in the development environment (compiler, preprocessor, debugger, make, etc.).
Knowledge of the main functions of an operating system and its fundamental components (scheduler, virtual memory manager, filesystem, etc.).
Knowledge of the most important primitives and interfaces for creating and synchronizing processes and threads, and for exchanging messages and signals.
Knowledge of the socket framework and its API.
Applying Knowledge and Understanding
Ability to invoke system primitives and correctly integrate system calls into applications.
Ability to select the most appropriate frameworks and paradigms according to application requirements and runtime characteristics.
Autonomy of Judgement
Students will be able to assess the complexity and the implementation criteria of specific applications.
Communication Skills
Students will be able to describe how their applications use the system call API and explain the reasons behind their choices.
Learning Skills
Students will be able to further develop their skills by examining advanced topics in system programming.
|
Educational objectives Educational goals
The Data and Network Security course is designed to provide students with a comprehensive understanding of a broad spectrum of cybersecurity concepts, paradigms, and real-world applications. It provides a solid foundation in the fundamental principles of cybersecurity while exposing students to current trends and cutting-edge developments in the field. Moreover, the course promotes active participation through class discussions on cybersecurity topics.
The course emphasizes a critical perspective on the evolving threat landscape, encouraging students not only to learn the foundations of cybersecurity but also to explore emerging challenges and current research trends. Each lecture is structured with a dual purpose: first, to introduce a specific cybersecurity topic, such as authentication mechanisms, malware, covert communication channels, cyber deception, remote attestation in IoT, digital forensics, data privacy, software-defined networking, and advanced persistent threats; second, to highlight key research questions, emerging threats, and novel techniques related to each topic. This approach ensures that students acquire both a solid theoretical background and an awareness of practical challenges and research-driven issues.
A central aim of the course is to cultivate critical thinking and research-oriented curiosity. Students are encouraged to move beyond a superficial understanding of the topics by engaging with research papers that have advanced the state of the art or uncovered new vulnerabilities and system abuses. To foster this mindset, students will conduct independent research on a cybersecurity topic of their choice, analyze current approaches, present their findings to their peers, and participate in discussions on future directions in cybersecurity. This active engagement with contemporary research equips students with the skills needed to critically evaluate, question, and contribute to the evolution of the field.
Knowledge and understanding
By the end of the course, students will have acquired knowledge of the fundamental principles of data and network security, with particular reference to core security concepts, such as confidentiality, integrity, and availability; common cyber threats, vulnerabilities, and attack vectors, with a focus on emerging trends and practices; network security architectures, protocols, and defense mechanisms; security standards, policies, and risk management methodologies; and current research trends and emerging technologies in cybersecurity.
Applying knowledge and understanding
By the end of the course, students will be able to analyze the security requirements of computer networks and information systems, analyze and critically evaluate current solutions in the field of data and network security, evaluate security mechanisms such as malware detection systems and emerging network technologies, identify vulnerabilities, and propose appropriate mitigation strategies.
Making judgements
By the end of the course, students will have developed the ability to critically assess the security posture of systems and networks; critically evaluate emerging trends and proposed attack and defense solutions presented in the scientific literature; compare alternative security solutions while considering technical, organizational, and economic constraints; analyze security incidents and identify appropriate response strategies; make informed decisions regarding risk management and security policies; and evaluate the ethical, legal, and privacy implications associated with cybersecurity solutions.
Communication skills
By the end of the course, students will be able to communicate security concepts clearly to both technical and non-technical audiences, with particular attention to technical audiences having limited knowledge of specific cybersecurity domains; produce technical documentation, security reports, and risk assessments, including SWOT analyses; prepare technical presentations suitable for both academic and industrial contexts to communicate the outcomes of their research activities and emerging research directions; and effectively present security analyses and research proposals.
Learning skills
By the end of the course, students will have developed the ability to independently acquire and evaluate new knowledge in the rapidly evolving field of cybersecurity through an in-depth analysis of the scientific literature on state-of-the-art security solutions; analyze scientific literature, technical standards, and industry best practices to address emerging security challenges and propose innovative solutions or new research directions; and adapt to evolving technologies, emerging threat scenarios, and changing regulatory requirements, such as the GDPR.
|
Educational objectives Educational goals
Know how to apply management accounting tools to support and improve corporate decision-making processes.
Use planning methodologies to manage complex technology projects.
Knowledge and understanding
Gain a solid understanding of the fundamental concepts of economics and management, with a particular focus on technological aspects.
Develop a thorough understanding of the key aspects, concepts, and tools of management accounting and project management.
Applying knowledge and understanding
The ability to effectively implement time and cost planning tools in business or technology case studies.
The ability to translate IT security and infrastructure requirements into budget plans that are sustainable for the organization.
Making judgements
Develop the critical thinking skills needed to analyze, evaluate, and understand complex management issues.
Recognize the economic and technological impact of business decisions.
Communication skills
Be able to communicate and defend one’s strategic decisions.
Correctly use technical and economic terminology related to project and cost management.
Learning skills
Develop the flexibility to independently adopt new business models and management tools that will emerge in the cybersecurity and technological innovation sectors.
|
Educational objectives General objectives:
The course will provide students with both theoretical and practical background on wireless and Internet of Things systems. The course includes an hands on lab.
Specific objectives:
The course will provide students with both theoretical and practical background on wireless and Internet of Things systems. The unique challenges of such systems will be introduced, explaining why they requires special design choices with respect to wired networks. The student will be able to reason on what are the right design choices to increase efficiency, reliability, energy efficiency,..., creating the background for being able to design future generation sensing and IoT systems. He/she will also have the possibility to have hands on experience on programming IoT devices in a lab.
Course summary
-Introduction to Wireless Systems (design challenges of a wireless system; things to know on how the signal propagate, on how to design a low power system and on how to cope with limited resources available)
-From 2G to 5G: Cellular systems evolution towards an integrated system including also Internet of Things (Architecture, Protocols, Procedures, detailed presentation of how cellular systems work)
-Sensing systems basics: MAC protocols, routing protocols, localization and synchronization
-Towards the Internet of Things: features, standards, open challenges, low power IoT radio technologies -SigFox, LoRa
-Trends in Internet of Things research. This part will cover on going research issues related to future generation IoT systems. It will be based on research papers and maybe subject of revision during the class based on students interests and emerging topics. The following topics are expected to be addressed:
*Towards zero energy consuming IoT systems: how energy harvesting and wake up radios, as well as passive backscattering technologies are changing what and for how long we can do in IoT systems.
* IoT security issues and how blockchain technologies is being exploited in large scale IoT deployments to enable IoT vertical applications.
* When IoT meets machine learning: system level optimization at scale through machine learning techniques.
* IoUT (Internet of Underwater Things): how IoT, robotic technologies and machine learning are changing the Blue Economy sector.
- Lab: IoT systems programming
Knowledge and understanding:
At the end of the course students will have acquired knowledge about the performance trade offs associated to different system design choices and will be able to read and understand technical documents on wireless and IoT systems (papers, standards,---). At the end of the course students will be able to analyze standards and technical documents, understanding and implementing them. He/she will have done practical hands on experience on the programming and performance evaluation of such systems.
Application of knowledge and understanding:
The students will be able to provide solutions for new generations of wireless and IoT systems.
Judgment skills:
Students will develop the analytical skills necessary to evaluate various alternatives for the design of wireless and IoT systems selecting the best alternative for a
specific application scenario.
Communication skills:
Students will learn to present, in a synthetic and accurate way, using an adequate technical language, ideas, solutions and research results on wireless and IoT systems.
Learning ability:
The course will provide students with both theoretical and practical background on wireless and Internet of Things systems.
|
Educational objectives Educational goals
The "Practical Network Defense" course aims to provide students with the theoretical and, above all, practical skills necessary to design, implement, and monitor effective defense strategies within modern network infrastructures. Through a hands-on approach heavily focused on cloud-based virtual laboratory environments, students will learn how to analyze network vulnerabilities, mitigate the attack surface, and respond promptly to threats by simulating real-world attack and defense scenarios.
Knowledge and understanding
Upon successful completion of this course, students will have acquired knowledge regarding:
The fundamental principles of network security, with a particular focus on the Defense in Depth paradigm, and minimizing the attack surface.
The operation, architecture, and configuration of perimeter and internal security tools, such as Firewalls, VPNs, IDS/IPS, Proxies, and Demilitarized Zones (DMZs).
Network monitoring and traffic analysis methodologies through log study and packet capturing.
Cyber deception concepts using Honeypots and Honeynets.
The main network attack techniques (e.g., session hijacking, man-in-the-middle) used to test the robustness of defenses.
The role of security policies in network service governance and compliance.
Applying knowledge and understanding
Upon successful completion of this course, students will be able to:
Configure and deploy security appliances (Firewalls, IDS/IPS, Proxies) within a cloud-based virtual infrastructure.
Apply network hardening and network access control to restrict packet flow using granular rules.
Isolate critical network components by designing DMZs and segmenting traffic securely.
Utilize analysis and monitoring tools to detect anomalies, analyze network packets, and interpret system logs.
Deploy and monitor Honeypots/Honeynets in isolated environments to analyze attacker behavior.
Conduct controlled security tests (simulating attacks such as MitM or hijacking) to verify the effectiveness of the applied countermeasures.
Translate high-level requirements into enforceable and measurable network security policies.
Making judgements
Upon successful completion of this course, students will be able to:
Critically evaluate the security posture of an existing network infrastructure, identifying attack vectors and potential weaknesses.
Select the most appropriate countermeasures and defense tools based on the balance between cost, complexity, performance, and risk level.
Analyze network traffic and logs to independently distinguish between legitimate activities, false positives, and actual intrusion attempts.
Formulate independent judgments on the effectiveness of security policies adopted within an organization.
Communication skills
Upon successful completion of this course, students will be able to:
Draft technical reports and project documentation clearly describing the implemented defense architecture and configurations deployed in the cloud laboratory.
Effectively communicate discovered network vulnerabilities and mitigation strategies to both technical specialists and non-technical/managerial stakeholders.
Clearly explain and justify the rationale behind choosing a specific security policy or countermeasure.
Learning skills
Upon successful completion of this course, students will have developed:
The ability to independently keep up to date with new cyber threats, emerging vulnerabilities (Zero-Days), and evolutions in network defense tools.
The autonomy to navigate cloud and virtualization environments to test and implement new security solutions.
The capability to learn how to use new monitoring, attack simulation, or encryption software by directly consulting official technical documentation.
|
Educational objectives Educational goals
The objectives of this course consist of presenting the concept of secure computation with the purpose of designing systems for data protection according to the data in use paradigm, therefore avoiding data leakage towards servers, satisfying the principle of data minimization. This course includes both theoretical and practical contents.
The course will introduce the concepts of security through simulation, the use of garbled circuits, the computations through encrypted data via homomorphic encryption, secret sharing and fairness in distributed computations, including both theoretical and practical aspects, presenting concrete use cases and devoting part of the allocated time to the use of libraries allowing to concretely implement software including the above functionalities.
Knowledge and understanding
Knowledge of the concept of secure, fair and private computation.
Knowledge of the cryptographic tools useful for secure computation.
Understanding the practical limits when achieving practical secure computation.
Applying knowledge and understanding
Use of libraries to realize applications of secure computation.
Measure the performance and the obtained security levels with existing libraries.
Making judgements
The students will be able to judge the actual (in)security of a design and its performance.
Communication skills
The students will learn how to illustrate the various options to securely realize systems through techniques of secure computation.
Learning skills
The students will obtain the necessary background for a deeper study of the subjects.
|
Educational objectives General Objectives
The basics of security in software programs
Specific Objectives
Methodologies and tools to find and remove the most common software vulnerabilities, and to develop software free of security flaws
Knowledge and Comprehension
Learning the most effective techniques to remove vulnerabilities from code and to develop software satisfying specific security policies
Ability to Apply Knowledge and Comprehension
The student is able to transfer knowledge of methodologies to the selection of appropriate techniques and tools to remedy the presence of vulnerabilities.
Autonomy of Judgement
The student learns to analyze problems and identify the proper methodologies and tools to solve software security problems.
Ability to Communicate
The student is able to communicate successfully and defend the choices made in the selection of appropriate methodologies and tools.
Ability to Learn
The student is able to continue the learning process autonomously to u
|
Educational objectives General objectives
The course aims at providing basic concepts and methodologies of control theory, operations research and game theory, which constitute an analytical framework for the modeling of cyber-physical systems and of the main types of attacks on cyber-physical systems (for example: "denial of service", " replay attack "," covert attack "," false data injection ") and for the solution of security games and decision problems. The course will summarize a number of such methodologies and show how their application is able to deal with cyber-physical security problems in numerous example use cases.
Specific objectives
Knowledge and understanding:
The students will learn methodologies for to model and solve security problems in cyber-physical systems by unsing control theory, game theory and operations research methodologies.
Apply knowledge and understanding:
At the end of the course, the student will be able to derive abstract mathematical models for a wide class of cyber-physical systems, to analyze, starting from these models, some important properties concerning their security.
Critical and judgment skills:
The student will be able to to face cybersecurity problems through control theory, game theory and operations research methodologies.
Communication skills:
The course activities allow the student to be able to communicate / share the main problems concerning cybersecurity problems in cyber-physical systems and the possible design choices for their soultions.
Learning ability:
The aim of the course is to make students aware on how to deal with control and decision-making problems in the context of cybersecurity problems in cyber-physical systems.
|
Educational objectives General Objectives
Traditional cryptographic tools are insufficient for data protection in emerging scenarios. The objectives of this course consist in presenting several modern cryptographic tools and techniques along with their applications to realize the principle of "security and privacy by design" in cyberspace. This course provides both theoretical and practical expertise.
Specific Objectives
The course will illustrate the power of advanced signature schemes, advanced encryption schemes, verifiable random functions, privacy-preserving proof systems, and cryptographic puzzles. A particular focus will be given to concrete applications such as e-voting, e-auctions, privacy-preserving contact tracing, digital cash, anonymous cryptocurrencies, identity wallets, secure messaging, fighting misinformation, GDPR compliance (right to be forgotten and data minimization principles), and practical libraries and tools for advanced cryptography.
Knowledge and Understanding
Knowledge of the security properties of advanced cryptographic tools.
Knowledge of the main hardness assumptions on which the security of advanced cryptographic tools is based.
Knowledge of cryptographic schemes currently used in practice.
Understanding of their practical and theoretical properties.
Applying Knowledge and Understanding
How to select and combine the appropriate advanced cryptographic tools for a given application.
How to analyze the security and efficiency of a system based on advanced cryptographic tools.
Autonomy of Judgment
Students will be able to assess whether a system is secure according to a realistic threat model.
Communication Skills
Students will learn how to illustrate the resilience of a digital system against concrete attacks.
Learning Skills
Students will acquire the necessary background for deeper study of the subject.
|