Roboforbes

COMS W4187

Security Architecture & Engineering · Computer Science

Who teaches COMS W4187

What students said

Steven Bellovin · 2017 · 2017

Four assignments, two week turnaround for each. They required a good bit of time, but nothing that was rocket science.

Steven Bellovin · 2017 · 2017

The bad: the homework requirements are left with intentional vagueness. It wasn't until midway through the semester that it was clarified that this was by design and that Steve's philosophy is that in the real world there is ambiguity, so programmers will be expected to apply their own judgment in assumptions when writing a program. Having worked in cyber security, I don't totally agree... but that being said, it's good to know upfront that you have a lot of latitude in defining the requirements so long as you document your decisions in your readme. The assignments themselves were time consuming, although not necessarily hard. The thought process is different than most other programming classes: you can't merely write a program to fulfill an outcome, and have to consider how the program can be exploited by attackers. Your goal in writing is to consider the flaws and add robustness to reduce exploit vectors. The midterm and final were open notes/open book and scenario based, so it wasn't a matter of regurgitating material as you had to consider circumstances and apply what was covered in lecture. More CS courses should adopt this format. The lectures were fantastic, and kept pace with real world developments in security. The class was at a particularly interesting time late in the 2016 election season when there was a lot of pub about Hillary Clinton's E-mail server and the hac…

Steven Bellovin · 2017 · 2017

four programming assignments in c/c++ that take a fair amount of time, midterm and final are open book/open notes

Steven Bellovin · 2017 · 2017

I mostly agree with the reviews below but would add that Bellovin curves down (almost the entire class would have gotten an A or A- this semester based on numerical scores and so to change this a 93 was downgraded to a B+). A larger issue not mentioned here is that the assignments lacked foresight and the grading seemed arbitrary. There were several instances when instructions had to be clarified at the last minute before something was due or the rubric itself was incorrect and the grade assigned needed to be revised. A fourth homework was assigned during the week of final exams which should have been announced earlier or released during the semester. I also think it's better policy to make the course requirements more challenging and curve up than to make the requirements trivial and to curve down (this is especially true when based on the results of a final that students cannot see since the semester is over). Not an incredibly demanding course but not particularly substantive or rewarding either.

Steven Bellovin · 2017 · 2017

Not too bad. We had four assignments in total. 3 were about building a secure program (each assignment focused on a different aspect of security). The last assignment was hacking a program which was fun.

Steven Bellovin · 2017 · 2017

I'm surprised this course doesn't have more positive reviews. It should. It's a lot of fun and you learn a good amount. The course essentially covers the whole spectrum when it comes to building a secure computer system. We touch on everything from buffer overflows, to real world cryptography issues, to social engineering attacks. This gave us a good overview of what security is about in a computing setting. Prof Bellovin is great. He's clearly extremely passionate amount the material and does a good job presenting it. He's a bit of a legend in the computer security world, and so has lots of great stories to tell; some of them even made us laugh. Definitely recommended.

Steven Bellovin · 2017 · 2017

Workload: very light. Only 4 homeworks. The three programming assignments remind me of labs in AP. We used C or C++ to implement some security-critical toy program like a print spooler or a command parser/sanitizer. These were kind of interesting, but I think it would be more fun if we knew that the graders would try to exploit our programs instead of grading them based on a checklist of features / requirements. In the last one, we get a binary and are told to attack it (more open ended). I didn't like the way the homeworks were bunched up at the end. We nearly got through the first half of the semester without turning in anything.

Steven Bellovin · 2017 · 2017

Security Architecture is a great idea for a course, but I don't like how such an important topic gets watered down so much. In lecture, we just go over a bunch of security concepts like permissions and buffer overflows at a high level. Prof. Bellovin seems to avoid going into technical details when possible, so the lectures are not very information dense. (When I miss class, I usually watch at 1.25x and that speed feels about right.) Some lectures, Prof. Bellovin brings out his funny side and cracks a bunch of jokes, which is pretty nice.

Steven Bellovin · 2017 · 2017

On a scale of 1-10 with 10 being the hardest, I'd say 3-5 depending on your background and how interesting security is to you.

Steven Bellovin · 2017 · 2017

I would recommend this class to anyone except the following two groups: 1) You hate programming in C/C++ 2) Thinking "outside the box" and "thinking like the bad guy" isn't your thing. Otherwise, I heartily recommend the course. Professor Bellovin's lectures are entertaining -- I actually looked forward to going to the lectures. His lectures are obviously well prepared; he seems to reuse the same slides but updates them the night before to keep them relevant. The lectures are organized and lively -- with a nice touch of sarcasm. The assignments are mostly about building a secure program that manages files. Watch out -- just because you "meet the specs" doesn't mean you will get full credit (or even a good grade). Unlike other classes where the professor would promise "you can assume you will get proper input," here you can assume the graders will be very creative about how they can cause your program to produce errors. You have to validate inputs like crazy. Writing the actual program isn't hard, but you will use some unusual/unfamiliar c libraries so don't start too late because you need a day or two to familiarize yourself with the documentation. Definitely do assignment 0 to get your C/C++ up to scratch (and you WILL need it for assignment 1). If you start a week early on pretty much any assignment, it will be a breeze. If you start 2-3 days before the deadline, you will be…

More Computer Science courses

Plan your semester on Roboforbes — free