CSS454: Computer and Communication Security
Course Information
Basic Details
- Course Code: CSS454
- Course Title: Computer and Communication Security
- Semester: 2/2025
- Instructor: Assoc.Prof.Dr.Somchart Fugkeaw
- Email: somchart@siit.tu.ac.th
- Class Schedule: Tuesday, 1:00-4:00 PM
Recommended Textbooks
Primary Textbooks
-
William Stallings and Lawrie Brown
- Title: Computer Security: Principles and Practice
- Publisher: Pearson
- Published: July 28, 2023
- Edition: © 2024
-
B. A. Forouzan
- Title: Cryptography and Network Security
- Publisher: McGraw-Hill
- Edition: 3rd edition, 2015
-
Wm. Arthur Conklin, Greg White, et al.
- Title: Principles of Computer Security: CompTIA Security+ and Beyond
- Edition: Sixth Edition (Exam SY0-601)
- Published: October 28, 2021
Additional Resources
- Top security conferences:
- CSS
- AsiaCSS
- UNIX
- Eurocrypt
- EROSICS
- DBsec
Intuition: These conferences publish cutting-edge research in security. Referencing them keeps course content current with latest threats and defenses.
Course Content Overview
Topics Covered
- Introduction to basic theory and techniques in cryptography
- Symmetric and Asymmetric encryption
- Cryptanalysis techniques
- Hash and MAC (Message Authentication Code)
- Key Exchange and Key Agreement Protocol
- Identification and Authentication mechanisms
- Software Security
- Security in computer networks
- Security threats and Vulnerabilities
- Firewall and Intrusion Detection System (IDS)
- IT Security Management
Intuition: Course follows a bottom-up approach: starting with crypto fundamentals (encryption, hashing), then moving to system-level security (software, OS, network), and finally to organizational security (management, policies).
Grading Breakdown
| Component | Weight |
|---|---|
| Attendance & Participation | 5% |
| Quiz & Assignment | 10% |
| Project | 30% |
| Midterm Exam | 25% |
| Final Exam | 30% |
| Total | 100% |
Note: Project carries the highest weight (30%), emphasizing practical application of security concepts.
Tentative Course Outline
Week-by-Week Schedule
| Week | Topics |
|---|---|
| 1 | Security Overview |
| 2 | Symmetric Encryption |
| 3 | AES and Mode of Operations |
| 4 | Public Key Cryptography, Key Exchange |
| 5 | Digital Signature and Certificates |
| 6 | Post Quantum Cryptography: KEM, Dilithium, AEAD |
| 7 | Identification and Authentication, Access Control |
| 8 | Midterm Exam |
| 10 | OS Security and Software Security |
| 11 | Database Security |
| 12 | Cloud Security |
| 13 | Network Security |
| 14 | Firewall + IDS/IPS Security |
| 15 | IT Security Management & ISO 27001 |
| 16 | Wrap up & Project Presentation |
| 17 | Final Exam |
Intuition: Note Week 9 is missing (likely a break week). The course structure: Weeks 1-7 cover cryptography foundations, Week 8 midterm, Weeks 10-15 cover applied security (systems, networks, management), Week 16 presentations, Week 17 final.
Key Milestones
- Week 6: Introduction to Post-Quantum Cryptography (cutting-edge topic)
- KEM (Key Encapsulation Mechanism)
- Dilithium (Post-quantum digital signature)
- AEAD (Authenticated Encryption with Associated Data)
- Week 8: Midterm Exam
- Week 16: Project Presentation
- Week 17: Final Exam
Attendance Policy
Requirements
- Minimum Attendance: 70% of total classes
- Consequence: Students with <70% attendance are NOT allowed to take the final exam
Critical: Missing more than ~5 classes (out of 17) disqualifies you from the final exam, which is worth 30% of your grade.
Calculation
- Total weeks: ~17
- 70% attendance = at least 12 classes
- Maximum absences: 5 classes
Term Project
Overview
- Weight: 30% of final grade
- Purpose: Demonstrate ability to apply and implement security knowledge
- Format: Design and develop an application OR conduct research-based project
Requirements
- Must be related to Security-related topics
- Can be either:
- Application Development: Build a security tool/system
- Research-Based: Investigate a security problem/solution
Timeline
- Details will be discussed and posted in Google Classroom
- Information released: Before Midterm (before Week 8)
- Presentation: Week 16
Intuition: Start thinking about project ideas early (Weeks 1-4). Popular ideas: implementing encryption schemes, building intrusion detection systems, analyzing vulnerabilities, creating secure authentication systems.
Study Tips
Recommended Approach
- Read ahead before each lecture (use textbooks)
- Practice coding for cryptography implementations
- Stay updated on current security news and breaches
- Form study groups for project collaboration
- Review conference papers for deeper understanding
Key Success Factors
- Strong attendance (70% minimum required)
- Active participation (5% of grade)
- Early project planning (30% of grade)
- Consistent study for exams (55% combined)
Important Dates Summary
| Event | Week | Notes |
|---|---|---|
| Semester Start | Week 1 | Security Overview |
| Project Details Released | Before Week 8 | Check Google Classroom |
| Midterm Exam | Week 8 | Covers Weeks 1-7 |
| Project Presentation | Week 16 | Be prepared to demo |
| Final Exam | Week 17 | Comprehensive |
Contact Information
- Instructor: Assoc.Prof.Dr.Somchart Fugkeaw (Aj. Ohm)
- Email: somchart@siit.tu.ac.th
- Office Hours: TBA (check Google Classroom)
- Platform: Google Classroom (for announcements and materials)