Course Details

CYBERSECURITY

MF0737

Course
CYBERSECURITY
Code
MF0737
Academic Year
2026/2027
Curriculum Year
2024/2025
Degree Programme
CHEMISTRY
Curriculum
000 - CORSO GENERICO
Course coordinator
Lecturers
Credits
6
Lecture Hours
48
Scientific Disciplinary Sector (SSD)
INF/01 - Computer Science
Course Type
Single-subject learning activity
Course Delivery
OBB - Obbligatoria
Year
3
Teaching period
Primo Semestre
Campus
ALESSANDRIA
Teaching language
Italian
Course Contents
Introduction to the basic principles of network security and cryptography, description of the fundamental techniques, applications and protocols.
Reference Texts
William Stallings, Cryptography and Network Security, fifth edition or any later one, Pearson
or
Maurizio Cinotti, Internet Security, third edition, Hoepli Informatica, ISBN 978-88-203-3895-4 (this book is no longer printed but still valid under many respects, and can be found in DiSIT's library)
Additional material is provided on the course's online site.
Learning Outcomes
The course's objective is to have students
-develop a feeling on security risks, based on the knowledge of vulnerabilities and attack types;
-learn the principles of information security;
-acquire the fundamental tools for implementing security requirements.
Prerequisites
Knowledge of the principles of operation of computer networks, Java programming, basic notions of Unix usage
Teaching Methods
The course is entirely taught in lab. Each lesson begins with a presentation of the subject, during which technical aspects are enriched with references to recent security incidents. Hands on activity follows: students are guided in the realization of proof-of-concept security exploits, so that they acquire a feeling for vulnerabilities and understand the features and limits of security technologies and mechanisms; they are also guided in the implementation of cryptographic software, and in the configuration of security systems so that they acquire familiarity with software instruments and their use.
Students can find on the DIR platform the subjects treated in each lesson, along with appropriate bibliographic references, and indications on the hands-on activity. This way students that attend the course can review or complete proposed activities and keep abreast of the course when they miss a class. This also enables non attending students to experiment on their own with the hands-on activity and to follow autonomously the class.
Moreover on DIR students can find additional material such as (pointers to) documents about protocols, links to security news, and links to sites of organizations that work on security etc, in order to stimulate the curiosity of the students and to keep them up-to-date in a field that changes quickly. Since most of such material is written in English, preparing for the exam will give the students the possibility to practice the technical language of computer science.
Finally on DIR, students have access to a self-evaluation quiz that aims at encouraging the students to reason about the subjects taught in class.
During classes, questions are posed to students using the tool wooclap in anonymous mode, to verify comprehension and to stimulate active participation.
Additional Information
Hands-on activity requires active participation of the students, and leads the latter to ask themselves questions (and, as a consequence, often to ask questions to the instructor); this way it allows a regular monitoring of the way the subject is being understood.
The activity in lab is thought as a way to ease comprehension and to develop the necessary sensitivity, and not as a means to teach usage of security tools. Yet, the motivated students gains from such activity also useful practical skills.
During classes, questions are posed to students using the tool wooclap in anonymous mode, for a constant monitoring of the students' difficulties

Students with physical disabilities, Learning Disabilities or Special Education Needs can request
specific services and tools via the Staff Sviluppo e Coordinamento Carriere e Servizi alle Studentesse
e agli Studenti, consulting the University webpage: https://www.uniupo.it/en/services/services-
students-physical-or-learning-disabilities
Students with disabilities, learning disabilities or special education needs, once they have contacted
the University Staff, can refer to the tutor in charge of the course to define the examination
modalities, concerning academic aspects.
Assessment Methods
The grades are assigned according to the following evaluation grid:less than 18: Significant gaps in content, missing answers, or inadequate responses.18–22: Acceptable preparation, but with significant gaps or topics not adequately studied. Sufficient application skills. Basic use of technical vocabulary.23-25: Appropriate knowledge with some gaps, fair application skills; articulated presentation and appropriate use of technical language.26–28: Good knowledge of the content and ability to establish connections between different parts of the syllabus. Solid use of technical language.29–30 with honors: Complete and thorough preparation, with a clear and coherent view of the topics covered. Precise use of technical language.
The exam is oral, but an alternative way to pass the exam is offered (see below).In the interview, students must in general answer questions on three topics (the number of questions can vary depending on the quality of the answers, since the goal is to ascertain that the student has attained the formative objectives). The interview uses basically two tools: it is verified that the student has learned the basic principles, mechanisms and technology taught in class and has acquired the appropriate technical language, through a request to describe some of the subjects; in order to verify that the student has acquired a feeling for security risks along with autonomy and critical skills in the use of security tools, the student is submitted simple security problems or minimal variations of known protocols and is asked to discuss them. The passing score is obtained showing comprehension of the fundamental principles and a basic mastering of the technical language. Excellency is achieved showing skills in identifying security risks in simple problems, capability of judging the adequacy of solutions and being able to discuss the topics using with precision the technical language.As an alternative, students can choose to take the exam as a 20 question quiz, that must be taken in lab. The quiz is automatically corrected. A passing score is obtained by correctly answering to 70% of the questions. The maximum score that one can obtain with the quiz is 22/30 which is achieved with at least 90% correct answers to the quiz.
Detailed Syllabus
- Introduction to network and computer security. Vulnerabilities and security requirements. - Security policy - Symmetric key cryptography. Block and stream ciphers. Confusion and diffusion principles. DES and 3DES, AES, RC4. Modes of operation of block ciphers. - Public key cryptography. RSA, Diffie-Hellman and DSA: usage, attacks, protocols and standards. Introduction to Elliptic Curve Cryptography: ECDH and ECDSA. - Symmetric key ciphers vs. public key ciphers. Hybrid scheme. Exchange of a secret and symmetric key derivation. IES and ECIES. - Cryptographic hash functions. Properties and structure. Collisions. Examples. - Message Authentication Codes. Comparison with hash functions. - Public key message authentication. Non repudiability - Time: nonces and timestamps. Synchronization. - Public key certificates. Certification and Registration authorities. Certificate revocation lists. OCSP protocol. - Authentication Authorization and Accounting scheme (AAA). Authentication paradigms: login/password, challenge/response and timestamp - VPNs. Hints on IPsec. As an application of the principles introduced in the course: SSL/TLS and SSH. - Firewalls. Firewall architectures. Fundamental principles. Bastion Hosts. DMZ. - Static and dynamic packet filtering. Access lists. Proxies.
Expected Learning Outcomes
Knowledge and understanding: knowledge of the basic principles of security, the fundamental cryptographic techniques and the essential devices to protect a computer network.
Applying knowledge and understanding: students must be able, to a minimal extent, to recognize vulnerabilities and to propose protection tools. As an additional benefit, the motivated students will learn to implement security protocols in Java, to use some security tools and to configure some simple security systems.
Making judgements: They must also acquire a correct perception of security risks and of the way security issues intertwine with the organization of a computer network.
Communication skills: students must have acquired the specific technical terminology and must be able to discuss security aspects and protection mechanisms. Moreover the students will increase their proficiency in the technical English of computer science.
Learning skills: having acquired the fundamental principles the student will later be able to appreciate and evaluate new technologies and protocols based on the same principles.
Last update:09-09-2026 00:14:31