Network Security · Computer Science
The group project is a big time sink, but none of the work is very hard. You will likely lose some points here and there for no reason, no matter how long you spend on it, so best not to stress.
The first couple of assignments were challenging (the hardest part was deciphering the crypto APIs and working through them, the APIs can be sometimes very obscure with poor docs until you plow through them for a little), but the first assignment was fun especially the crypto file transfer part !!! Second was more on javascript and XSS attacks, so there were some tricky situations there but super interesting. Good on the professor for setting this up. From then on the next few assignments were pretty straight forward Linux scripts were all pretty straight forward, but interesting neverthless. The grading curve seemed very fair too.
4 written assignments - straightforward 3 programming assignments - long but also straightforward, do not miss as this is a significant part of your grade 1 midterm - very comprehensive, tests your knowledge of definitions of protocols, attacks and algorithms learned in class 1 final
This is by far the worst course I have taken here. I am specializing in security so I have other security CS classes, and can compare. It's just really bad. The content overlapped with other classes too much. I have learned more from single assignments in other classes than I did from this entire class. Debbie seems to mean well but is unfortunately a terrible teacher. Her lectures are boring and honestly I could barely even hear her. She stares at her own slides and doesn't see you when you raise your hand to ask a question. Her notes are poorly organized and written in sentence fragments that leave out crucial context. She has basically no office hours. In the first lecture, I thought it was weird how she placed such strong emphasis on how important it was to come to class on certain days; it quickly became clear that this was because everyone was about to realize how useless it was to go to her class. I skipped about half of them and did better than almost anyone on the midterm. The written homeworks were boring and felt like busywork. I answered them 100% correctly, and the TA even admitted as much, but regretted that he had to take off points by following the specific wording of Debbie's answers. The programming was better but was rare. In 4119 we implemented a toy cut-down version of TCP; how about implementing a toy cut-down version of a TLS handshake? That's what I tho…
I know he has some bad reviews here, surprising, but I felt compared to lot of other lecturers, he was funny, entertaining and engaging. He seemed keen and interested and in love with the various aspects of security. Also felt his research shone through his lectures as well as his breadth of knowledge in different aspects of networking (like knowledge of SIP) and security. I felt the course was interesting in a whole, covers crypto, javascript attacks, firewalls, SPAM analysis etc. I felt though there could have been more emphasis on OS attacks, overflows especially since the Prof. Angelos was the lecturer for Operating systems too. In terms of languages C/C++ was the main choice for the first couple of assignments, then there was some javascript and then some shell scripts for firewall and spam analysis (AWK scripts etc.). The TA (Georgios Kontaxis) was very sharp too, and had super fast response time to emails even at the most odd hours of the night. Good on him. I would rate this class 5/5 and the professor 5/5. I would also think its a great elective to take even if you are working on some other major. I think you would get a great overview of different aspects of security, and I think this is probably better than lot of other courses, in terms of interesting assignments and great lecturer. I thought the mid-term and final were decent, the final being slightly harder (its…
The materials in this class are very interesting and the programming assignments let you apply most of what you've learned in class. This class can be painful though - 3 hour lectures (weekly slides are about 150+ in length), plenty of readings (mix of rfc, online articles and research papers) and exposure to the openssl library. The documentation for openssl will only show you how functions are used, not how to properly use them. This class will not show you how to properly use the library and there aren't many resources on the internet to help you either. You get a choice between doing assignments in python and C. Pick wisely. Overall not too difficult - if you spend enough time.
Three long homeworks, two exams (one was tough, one wasn't).
5 assignments - %50, midterm - %20 and final - %30. The midterm and final were of average difficulty. Some assignments were very difficult and time consuming and others were of average difficulty (no easy ones).
Avoid this like the plague. Three-hour lectures are spent reading man pages (in roughly the tone of voice that you'd expect a man page to be read). Long, unguided homework assignments are spent mostly figuring out the details of Java libraries rather than doing actual work. Then they're graded seemingly at random... a friend got 25 points off for a non-preferred commenting style! A giant waste of time, and damn hard to sit through.
In defense of a wonderful professor: Prof. Keromytis is bright, extremely knowledgeable, prepared for class, funny (not dull), and cares about his students. My friends and I found him to be very approachable (not snotty or blatantly rude) and eager to help, though often it made sense to first go to the TA. His assignments covered some applied security technologies (SSL, RSA/AES encryption, SOCKS, DH key exchange, etc.) but not necessarily every single theoretical model discussed in class. C was the language of choice with two minor exceptions for Java. I rate this class 5/5.