Empirical Security & Privacy, for Humans

Home Syllabus Schedule Resources Canvas

SCHEDULE

Jump to next class.

Date Topic / Speaker
Readings & handouts
Aug 26 Introduction and syllabus
Aug 28
Economic view of cybersecurity -
Alex Gantman, VP Security Engineering, Qualcomm
Sep 2 End users and cybersecurity
Sep 4
Cybersecurity as a scientific pursuit -
Cormac Herley, Principal Researcher, Microsoft
Sep 9 Cybersecurity and risk assessment
Sep 11
Passwords
Sep 16
The business of attacks, and paying attackers for defense
Sep 18
LLMs and their impact on cyberattacks
Sep 23
Measuring secure software development practices
Sep 25
Project pitches
Individual students, or groups who wish to work together, should prepare project pitches. See the syllabus for details.
Sep 30
Empirical evaluations: Fuzz testing
Oct 2
Statistical tests: Pitfalls
Oct 7
Threat modeling - Adam Shostack, Shostack Associates
Oct 9
Fall break, no class
Project proposals due. See the syllabus for details.
Oct 14
Password managers, ethics of human studies
Oct 16
What's Still Missing in Static Analysis?
A Decade-Long Journey - Mayur Naik, Prof of CIS @ UPenn
Guest lecture about static analysis technology (including for finding security bugs), the influence of LLMs on it, and how we measure progress.
Oct 21
Student presentations begin

Oct 23
Student: Arya Sanjary

Oct 28
Student: Sydnie-Shea Cohen

Oct 30
Student: Noopur Bhatt

Nov 4
Student: Jiayi Xin

Nov 6
Student: Bharath Namboothiry

Nov 11
Student: Davis Brown

Nov 13
Student: Lucia Kulzer

Nov 18
Student: Ali Shirzad

Nov 20
Student: Zhiyao Tang