News
Written Re-Exam likely to be held on 21 October 2020Written on 21.09.20 by Nils Ole Tippenhauer For the previous Security class 19/20, we will offer a written re-examination for everyone who did not yet take the oral re-exam. The registration is open now. Date will be Oct 21 at 2pm, in GHH. Please register until 2 weeks before the re-exam. |
Written Re-Exam likely to be held in October 2020Written on 01.05.20 by Nils Ole Tippenhauer The oral re-examinations are now concluded. The written re-examination is planned to be held after the summer term, and before the winter term starts. There will be a dedicated timeslot then to conduct outstanding exams from the WS19/20. Any student who a) qualified for the exam in WS19/20, and b) did… Read more The oral re-examinations are now concluded. The written re-examination is planned to be held after the summer term, and before the winter term starts. There will be a dedicated timeslot then to conduct outstanding exams from the WS19/20. Any student who a) qualified for the exam in WS19/20, and b) did not yet take the oral re-examination will be eligible to take that written exam, likely in October 2020. We will update you in time about more concrete plans, once we have more information from the University. |
Second Exam will be oral for nowWritten on 11.04.20 by Nils Ole Tippenhauer We hope you are all healthy during the current lockdown. As it is currently unlikely that we will be able to have normal written re-exams for the Security class, we now plan to hold oral exams, in particular for people that need the exam to pass the class. We have created another registration here on… Read more We hope you are all healthy during the current lockdown. As it is currently unlikely that we will be able to have normal written re-exams for the Security class, we now plan to hold oral exams, in particular for people that need the exam to pass the class. We have created another registration here on CMS for students to indicate their interest to participate. We will have to see how many people require this exam, as we cannot host infinite number of oral exams due to our limited time. We will coordinate with the university afterwards in terms of LSF registrations etc. Please register for the oral exam within a week (until April 17). We then plan to hold them between April 17 and 24, all timeslots will be coordinated with you individually. You will require a computer with internet connection, we will use Zoom most likely (free to install on Win/OSX/Linux). Please contact Giancarlo and Nils (both in the same mail) if you have questions or comments. In general, the oral exam will work as following: We are going to talk about 2-3 topics, for at total maybe 25 minutes. Giancarlo and I will let you propose a first topic (from class). You will then explain that topic to us, and we will ask questions to see how well you have understood it from the lecture. After the first topic, we will select 1-2 further topics to discuss. A TA will take notes. Content-wise: everything covered in the lecture could be asked. Core concepts and high level understanding is more important than details (but those could eventually also be asked). I might also ask you to do a simple calculation or sketch. Please have some paper at hand for that. |
Written re-exam postponed/ possible Oral Examinations over SkypeWritten on 16.03.20 by Nils Ole Tippenhauer University just decided to postpone all written examinations until after April 24. This means our re-exam for Wednesday unfortunately cannot happen as scheduled. There is the option to have oral Skype examinations if students agree and there is an urgent need (e.g. exchange students, upcoming end… Read more University just decided to postpone all written examinations until after April 24. This means our re-exam for Wednesday unfortunately cannot happen as scheduled. There is the option to have oral Skype examinations if students agree and there is an urgent need (e.g. exchange students, upcoming end of studies, etc). We are now trying to understand how many students are in such a situation. Please contact us (gpellegrino@cispa.saarland and tippenhauer@cispa.saarland) if you have reasons that you cannot wait with the examination until after April 24. This also includes students for which we scheduled oral exams in the last days due to their travel history. We are sorry for the late notice, and hope everyone is healthy (and stays healthy). Regards, Nils Ole and Giancarlo |
Re-ExamWritten on 11.03.20 by Nils Ole Tippenhauer The mandatory registration on LSF for the re-exam will close by the end of today. So far, we expect to hold the exam as planned on March 18 from 2-4pm. Given the lower number of registrants so far, we will be able to place students at maximal distance to each other to reduce potential health issues.… Read more The mandatory registration on LSF for the re-exam will close by the end of today. So far, we expect to hold the exam as planned on March 18 from 2-4pm. Given the lower number of registrants so far, we will be able to place students at maximal distance to each other to reduce potential health issues. We will update you as soon as possible in case the situation changes. |
Exam: Results & InspectionWritten on 19.02.20 (last change on 21.02.20) by Simon Schwarz You can now find your exam results on your personal status page. The exam inspection will take place on Friday, 21. February from 13:00 to 15:00 in CISPA Room 0.06. Solutions to the exam were uploaded to the materials collection here on the CMS. |
Exam InformationWritten on 16.02.20 by Simon Schwarz The exam starts Monday 17.02. at 14:00 and will take 120 minutes. Please arrive a few minutes earlier! You can now find your assigned seat for the exam on your personal status page. If your matriculation number is less than 2573514, your assigned seat is in the Günter-Hotz Lecture Hall. Otherwise,… Read more The exam starts Monday 17.02. at 14:00 and will take 120 minutes. Please arrive a few minutes earlier! You can now find your assigned seat for the exam on your personal status page. If your matriculation number is less than 2573514, your assigned seat is in the Günter-Hotz Lecture Hall. Otherwise, your assigned seat is in Building E2.5, Lecture Hall 1. The exam will be a closed book exam. Cheatsheets / Calculators / ... are not allowed. Please make sure to bring your Student ID card to the exam. If you've got any questions regarding exam registration (i.e. you're registered but don't have a seat assigned) please contact us immediately. |
Exam: Admission and RegistrationWritten on 08.02.20 by Simon Schwarz All points for the MiniCTF are now finalized and published on your personal status page. If you reached half of the points (30 points) in the overall lecture, you are admitted to the exam. You have to register for the exam in HISPOS/LSF until 10.02. to be able to participate in the exam. If… Read more All points for the MiniCTF are now finalized and published on your personal status page. If you reached half of the points (30 points) in the overall lecture, you are admitted to the exam. You have to register for the exam in HISPOS/LSF until 10.02. to be able to participate in the exam. If your study course does not support LSF please register on the platform for your course and in the CMS (on your personal status page) until 10.02. |
MiniCTF is over + Dictionaries in Final examWritten on 07.02.20 by Nils Ole Tippenhauer The MiniCTF deadline passed at 4pm tonight. Final standings are: 1. Dieter Overflow🙅👨💻, and shared 2. place for Fs0ci3ty and Derivative Donkey. Congratulations to all three teams! 14 teams in total reached the full 10 points. We hope you enjoyed the event. In case you didn't fill the feedback… Read more The MiniCTF deadline passed at 4pm tonight. Final standings are: 1. Dieter Overflow🙅👨💻, and shared 2. place for Fs0ci3ty and Derivative Donkey. Congratulations to all three teams! 14 teams in total reached the full 10 points. We hope you enjoyed the event. In case you didn't fill the feedback questionnaire yet: https://forms.gle/fwGtjM2EnE6Na98D9 |
Last lecture tomorrow: Spectre/Meltdown + Exam Q&A + Preliminary MiniCTF resultsWritten on 06.02.20 by Nils Ole Tippenhauer The lecture tomorrow will have technical content on recent Spectre and Meltdown attacks, followed by a Q&A on the finals. We plan to finish with a quick summary of the (preliminary) MiniCTF results. Although the official MiniCTF deadline will only be at 4pm, the top 3 teams might have stabilized by… Read more The lecture tomorrow will have technical content on recent Spectre and Meltdown attacks, followed by a Q&A on the finals. We plan to finish with a quick summary of the (preliminary) MiniCTF results. Although the official MiniCTF deadline will only be at 4pm, the top 3 teams might have stabilized by then already. We also prepared a short anonymous and voluntary feedback questionnaire using Google Forms. Please consider filling it to provide feedback on individual topics and the exercises: https://forms.gle/fwGtjM2EnE6Na98D9 |
Talk on "Software-based Side-Channel Attacks and Defenses"Written on 05.02.20 by Giancarlo Pellegrino Dear students, As promised today during the lecture, on 11/02/20, one of the leading researchers on microarchitectural side channel attacks and author of the Meltdown and ZombieLoad attacks, Micheal Schwarz, will give a talk at CISPA. You are more than welcome to attend. Below are the… Read more Dear students, As promised today during the lecture, on 11/02/20, one of the leading researchers on microarchitectural side channel attacks and author of the Meltdown and ZombieLoad attacks, Micheal Schwarz, will give a talk at CISPA. You are more than welcome to attend. Below are the details. Best, When: 11/02/20, 10:30-12:00 Where: CISPA Lecture Hall Title: Software-based Side-Channel Attacks and Defenses |
Reminder: Office Hour at 16:00Written on 04.02.20 by Simon Schwarz Reminder: We will offer an Office Hour today at 16:00 in CISPA Room 0.06. |
MiniCTF has started!Written on 03.02.20 (last change on 03.02.20) by Simon Schwarz The MiniCTF has officially started! You can start solving challenges at https://minictf.scy-phy.net/! Each challenge will yield 2 points that count towards your admission for the exam (except for the challenge your team submitted). You can reach a maximum of 10 points from solving challenges in the… Read more The MiniCTF has officially started! You can start solving challenges at https://minictf.scy-phy.net/! Each challenge will yield 2 points that count towards your admission for the exam (except for the challenge your team submitted). You can reach a maximum of 10 points from solving challenges in the MiniCTF. The MiniCTF will run until Friday at 16:00. Please verify that your challenge is solvable on our platform (e.g. we included all the necessary files). If there are problems with your challenge, please contact your tutor. The feedback and points for the idea of the challenge are now released. We will award 3 additional points for challenge stability if your challenge runs smoothly during the MiniCTF. |
Tutorials & Office HourWritten on 02.02.20 (last change on 04.02.20) by Simon Schwarz There will be no tutorials next week (10.11-14.11). Instead, we will offer an office hour on Tuesday 04.02 at 16:00 in CISPA Room 0.06. The MiniCTF will start tomorrow at 12:00. We will announce more details then! |
MiniCTF: Feedback & Office HourWritten on 24.01.20 (last change on 27.01.20) by Simon Schwarz The feedback for your challenge proposal has been released and can be found on your personal status page. We will offer another Office Hour on Tuesday 28.02.2020 at 16:00 in Room 3.21 for any questions regarding your challenge. |
MiniCTF: Group Assignment & Office HourWritten on 16.01.20 (last change on 16.01.20) by Simon Schwarz You can now find your MiniCTF group on your personal status page. Remember to submit your challenge idea until 22.01.2020. We will offer an Office Hour on Tuesday 21.01.2020 at 16:00 in Room 2.22 at the CISPA for any questions about your submission. |
MiniCTF Rules and Guidelines are outWritten on 14.01.20 by Giancarlo Pellegrino A document with a complete list of rules, guidelines, and deadlines for the MiniCTF is online. See: https://cms.cispa.saarland/sec1920/dl/37/MiniCTF_rules_and_guidelines.pdf |
MiniCTF & Question Sheet 5Written on 13.01.20 by Simon Schwarz Remember to upload a document stating your team preferences until 15.01.2019. Remember to upload a document stating your team preferences until 15.01.2019. Question Sheet 5 has been released. This sheet is ungraded, you do not have to submit solutions for it. This sheet will be discussed in this week's tutorials. |
Distinguished Lecture Series talk by Thorsten Holtz (Ruhr University Bochum)Written on 09.01.20 (last change on 09.01.20) by Giancarlo Pellegrino As part of CISPA’s Distinguished Lecture Series, on Fri, January 10, at 11:00am s.t. in CISPA’s lecture hall, we are pleased to announce that Thorsten Holz (Ruhr University Bochum) will give a talk on: Fuzzing Hypervisors and Complex Interpreters Participation is optional and will not influence… Read more As part of CISPA’s Distinguished Lecture Series, on Fri, January 10, at 11:00am s.t. in CISPA’s lecture hall, we are pleased to announce that Thorsten Holz (Ruhr University Bochum) will give a talk on: Fuzzing Hypervisors and Complex Interpreters Participation is optional and will not influence your exercise points or grade. Please join if you are interested in the topic.
Title: Fuzzing Hypervisors and Complex Interpreters When: Fri, January 10, at 11:00am s.t. Where: CISPA’s lecture hall Abstract: In recent years, randomized fuzz-testing (“fuzzing”) has progressed rapidly, mainly driven by tools such as afl and lots of academic work on this topic. In practice, fuzzing is often superior to seemingly "smarter" approaches such as symbolic or concolic execution. We provide an overview of our recent results, including fuzzing hypervisors, grammar-based fuzzing of complex interpreters, and fuzz-testing of stateful systems. In total, the different methods enabled us to find hundreds of software bugs that lead to more than 100 CVEs. Bio: Thorsten Holz is full professor in the Horst Görtz Institute for IT Security at Ruhr-University Bochum. His research focuses on system security. He obtained his PhD in computer science from the University of Mannheim. He received the DFG Heinz Maier-Leibnitz-Price in 2011 and an ERC Starting Grant in 2014. He is one of the three spokespersons of the CASA (Cyber Security in the Age of Large-Scale Adversaries) BMBF Cluster of Excellence in Bochum.
/edit: highlighted that participation is optional |
Exercise Sheet 4Written on 07.01.20 by Simon Schwarz Exercise Sheet 4 has been released. This is a graded exercise sheet. Please submit your solution until 19.01.2020 in the CMS. For your submission please also consider the notes on the sheet. |
Tutorials & MiniCTFWritten on 03.01.20 by Simon Schwarz There will be no tutorials in the next week (06.01 - 10.01). The first tutorials of 2020 will take place in the week of 13.01-17.01. Please upload your group assignment for the MiniCTF until 15.01.2020. Please consider https://cms.cispa.saarland/sec1920/3/MiniCTF for details. |
Important Announcement: Graded MiniCTF starting mid of January 2020Written on 18.12.19 by Giancarlo Pellegrino Dear students, Please read this announcement very carefully, especially if you did not attend the lecture today. As announced today during the lecture, on 15/01//2020, it will take place the graded MiniCTF competition. This message is for all students, especially those that were not attending… Read more Dear students, Please read this announcement very carefully, especially if you did not attend the lecture today. As announced today during the lecture, on 15/01//2020, it will take place the graded MiniCTF competition. This message is for all students, especially those that were not attending the lecture. Your first deadline is on 15/01/2020. Please read below and stay tuned for more details!
I - What is the MiniCTF competition?The idea of the MiniCTF competition is to form groups of about four students. Each group will create one MiniCTF-style challenge. Then, all challenges will be made available for all students in a CTF competition.
II - How will it be graded?Grading is per group:
III - What are these milestones, and what are the deadlines?
​IV - Do you have any guidelines/tips for creating a good quality challenge?More details later, but, for now, you will need to keep in mind that a good challenge has four main ingredients:
|
Exercise Sheet 3Written on 03.12.19 by Simon Schwarz Exercise Sheet 3 has been released. This is a graded exercise sheet. Please submit your solution until 15.12.2019 in the CMS. For your submission please also consider the notes on the sheet.
|
Question Sheet 3 & Results Exercise Sheet 1Written on 22.11.19 by Simon Schwarz Question Sheet 3 has been released. This sheet is ungraded, you do not have to submit solutions for it. It will be discussed in the tutorials next week. We have finished correcting your submission. You can now see your points as well as feedback on your personal status page. |
Exercise Sheet 2Written on 18.11.19 by Simon Schwarz Exercise Sheet 2 has been released. This is a graded exercise sheet. Please submit your solution until 01.12.2019 in the CMS. For your submission please also consider the notes on the sheet. |
Distinguished Lecture Series talk by Yongdae Kim (KAIST)Written on 15.11.19 by Nils Ole Tippenhauer As announced in the lecture last week, there is a talk at CISPA before the lecture today, which might be of interest. Yongdae Kim from KAIST will talk on "Forecasting 5G Security from LTE Experience". The talk starts at 10:30 s.t. in the big CISPA lecture hall. Attendance is optional and not related… Read more As announced in the lecture last week, there is a talk at CISPA before the lecture today, which might be of interest. Yongdae Kim from KAIST will talk on "Forecasting 5G Security from LTE Experience". The talk starts at 10:30 s.t. in the big CISPA lecture hall. Attendance is optional and not related to grades or anything in the class. |
Question Sheet 2Written on 08.11.19 by Simon Schwarz Question Sheet 2 has been released. This sheet is ungraded, you do not have to submit solutions for it. It will be discussed in the tutorials next week. |
Exercise Sheet 1Written on 04.11.19 by Simon Schwarz Exercise Sheet 1 has been released. This is a graded exercise sheet. Please submit your solution until 17.11.2019 in the CMS. For your submission please consider the notes on the sheet. Exercise Sheet 1 has been released. This is a graded exercise sheet. Please submit your solution until 17.11.2019 in the CMS. For your submission please consider the notes on the sheet. |
Tutorial Assignment & Question Sheet 1Written on 25.10.19 by Simon Schwarz The tutorial assignment has been released. You can now see your tutorial on your personal status page. Tutorials will start next week (28.10-01.11.). Question Sheet 1 has been released. This sheet is ungraded, you do not have to submit solutions for it. It will be discussed in the tutorials next week. |
Question Sheet 0 & Office HourWritten on 18.10.19 (last change on 22.10.19) by Simon Schwarz Question Sheet 0 has been released. This sheet is ungraded, you do not have to submit solutions for it. We have set up a CTF platform for our practical tasks. You can reach it at https://sec19.scy-phy.net/. There will be no tutorial next week. Instead, we offer an office hour to deal with technical… Read more Question Sheet 0 has been released. This sheet is ungraded, you do not have to submit solutions for it. We have set up a CTF platform for our practical tasks. You can reach it at https://sec19.scy-phy.net/. There will be no tutorial next week. Instead, we offer an office hour to deal with technical problems and questions about this sheet. The office hour will take place on Tue. 22 Oct. from 10:00 to 12:00 in CISPA Room 0.06. |
Security
The Security core lecture ("Stammvorlesung") will be offered in winter term '19/'20. Tutorials will be assigned in the first/second week. Details to follow soon. Please check this website regularly to see updates. Our periodic schedule for the two lectures a week will be:
- Wednesday 12:15-13:45 (in Guenter-Hotz lecture room)
- Fri 12:15-13:45 (in Guenter-Hotz lecture room)
The first lecture will be on October 16. Registration in this CMS is required until 23.10.2019 at 4pm. LSF exam registration is required to participate in the exams (and well be possible until ~1 week before the finals).