Staff
| Role | Name | Office | Office hours | |
|---|---|---|---|---|
| Co-instructor | Wajih Ul Hassan | Rice Hall 522 | Thursdays 9:00–10:30 AM | hassan@virginia.edu |
| Co-instructor | Muhammad Shoaib | Rice Hall 425 | Thursdays 12:00–12:30 PM, Fridays 12:00–1:00 PM | ewe4gy@virginia.edu |
| Teaching Assistant | Rui Zhao | Rice Hall 425 | Thursdays 11:30 AM – 12:00 PM, Fridays 1:00–2:00 PM | dkw7xn@virginia.edu |
Syllabus
1. What this course is
You will learn to attack systems so that you can defend them. We work at the level where security actually breaks: the stack frame, the parser, the browser origin, the audit log, and the AI agent that has been handed your credentials. The course is organized in four modules:
Not covered: cryptography, privacy, cryptocurrency, hardware security. Take a CS 4501/6501 offering for those.
2. Prerequisites
CS 3710 is required. You must arrive able to:
- write and debug C
- read x86 assembly and reason about the stack
- navigate a Unix shell without help
If you cannot do these three things, this course will not be a productive use of your semester.
3. Learning objectives
By the end you should be able to:
- Take an unfamiliar binary and determine, with a debugger, whether and how it can be made to do something it wasn't meant to do.
- Write a working exploit for a memory-corruption bug and explain precisely which mitigation would have stopped it.
- Find and exploit the standard web vulnerability classes, and patch them correctly.
- Reason about an AI-integrated system's threat model — identify where untrusted input meets privilege, and say what an attacker gets.
- Reconstruct what happened on a compromised machine from its artifacts.
- Judge a security claim. Read a paper or a vendor blog that says "we reduced attack success to near zero" and know what question to ask next.
4. Grading
Every assignment A1–A5 is worth 10%, split evenly: 5% for the code you submit (AI-OK) and 5% for a short oral about it (NO-AI). The two halves are graded separately — a weak oral does not lower your code score, and a strong code submission does not lift your oral. A6 is a bonus — no oral, and it sits on top of the 100% rather than inside it.
The assignment measures what you can build with all available tools. The oral, in a later week, measures what you understand without them. Here’s the rhythm of one assignment:
A0 is a required pass/fail onboarding gate and carries no points. What it gates is access: every
assignment after it assumes the signed pledge and the environment A0 sets up. Skipping it doesn’t cost
you points directly — it costs you A1.Quizzes (20%). There are 5, each 15 minutes, on paper,
closed-resource. A quiz runs at the start of class and the lecture follows it — plan to be there on
time. Every quiz is announced in advance and marked on the calendar below; each badge lists the
lectures it covers by number — Quiz 2 · Lec#7,8,9,10,11,12,13 is quizzed on the seven lectures labelled
Lec#7 through Lec#13 in the calendar.
Your lowest quiz is dropped, so 4 count at 5% each. If you miss a quiz, that is the one you drop — there is nothing to arrange and nothing to document. Miss a second one and it scores zero, barring a documented emergency.
The final exam (30%) is cumulative over all four modules. It is an individual, closed-resource, AI-free assessment written on paper and completed in person: Friday, December 11, 9:00–11:00 AM.
The per-assignment code / oral breakdown is on the Assignments page.
5. Policies
Late work
Assignments may be submitted up to two days late. Each started day costs 10 percentage points off that assignment’s score: a 92 becomes an 82 one day late and a 72 two days late. A day means a started 24-hour period after that assignment’s deadline, so ten minutes late is one day late. After 48 hours we do not accept the work. A missed quiz is simply the one you drop — nothing to arrange. Oral evaluations and the final exam cannot be made up except for documented emergencies; if something stops you attending, tell us as soon as you reasonably can. Advance notice is expected when circumstances allow — we know they don’t always.
Ethics pledge
See the ethics pledge. You must sign it in A0 before you receive the course materials and VM access.
Collaboration
All assignments are individual. You may discuss concepts
with anyone. You may not read, copy, or transcribe another student’s solution. Cite every source you use,
including AI, in AI-USE.txt — what counts as adequate disclosure is spelled out in the
AI policy.
Artificial intelligence
See the AI policy. The short version: AI is unrestricted on assignments provided you disclose it, and absent from oral evaluations, quizzes, and the final exam. Disclosure is never penalized. Non-disclosure is the violation.
Recording
Lectures are not recorded this semester.
6. Materials
No required textbook.
This schedule is subject to change. Check back often; major changes are announced in class.
Calendar
| Tuesday | Thursday | Friday |
|---|---|---|
Aug 25 Lec#1:Introduction & the Security Mindset
|
Aug 27 Lec#2:Authentication
|
|
01Systems & Software SecuritySept 1 – Oct 8 |
||
Sept 1 Lec#3:IA-32 Architecture
A0 out |
Sept 3 Lec#4:Buffer Overflow I
|
Sept 4 A0 dueA1 out |
Sept 8 Lec#5:Buffer Overflow II
|
Sept 10 Lec#6:Format String Vulnerabilities
|
|
Sept 15 Lec#7:Return-Oriented Programming
Quiz 1 · Lec#3,4,5,6 |
Sept 17 Lec#8:Control-Flow Integrity
A1 due |
Sept 18 A2 out |
Sept 22 Lec#9:Malware
|
Sept 24 Lec#10:Fuzzing & Memory Safety
|
Sept 25 |
Sept 29 Lec#11:Supply Chain Security MS
|
Oct 1 Lec#12:Code Obfuscation & Anti-Analysis
A2 due |
Oct 2 A3 out |
Oct 6 Fall Reading Days (Oct 3–6)
No class |
Oct 8 Lec#13:Co-Residency and Side Channel Attacks
|
|
02Web SecurityOct 13 – Oct 22 |
||
Oct 13 Lec#14:The Web & the Same-Origin Policy MS
Quiz 2 · Lec#7,8,9,10,11,12,13A3 dueA4 out |
Oct 15 Lec#15:Cookies, Sessions & CSRF MS
|
Oct 16 |
Oct 20 Lec#16:Cross-Site Scripting MS
|
Oct 22 Lec#17:SQL Injection & CAPTCHAs MS
|
Oct 23 A4 dueOral A3 · last day |
03Threat Detection & ForensicsOct 27 – Nov 12 |
||
Oct 27 Lec#18:Intrusion Detection
Quiz 3 · Lec#14,15,16,17 |
Oct 29 Lec#19:IDS & System Auditing MS
|
|
Nov 3 Election Day
No class |
Nov 5 Lec#20:Threat Rule Evasion MS
A5 out |
|
Nov 10 Lec#21:Data Provenance & Forensics
|
Nov 12 Lec#22:Tamper-evident Logging
|
Nov 13 |
04AI Systems SecurityNov 17 – Dec 8 |
||
Nov 17 Lec#23:The LLM & Agent Threat Model
|
Nov 19 Lec#24:Prompt Injection — and why the defenses keep failing MS
Prep — Willison — The Lethal Trifecta; Debenedetti et al. — Defeating Prompt…; The Attacker Moves Second A5 dueA6 out |
|
Nov 24 Lec#25:Jailbreaking Techniques
Quiz 4 · Lec#18,19,20,21,22 |
Nov 26 Thanksgiving recess (Nov 25–29)
No class |
|
Dec 1 Lec#26:Agents, Tools & MCP · AI as an offensive instrument
|
Dec 3 Lec#27:Red Teaming
A6 due |
Dec 4 |
Dec 8 Lec#28:Wrap-up & final-exam logistics
Quiz 5 · Lec#23,24,25,26,27 |
Dec 11 9:00–11:00 AM EXAMFinal Exam — Modules 1–4
Final · 30% |
|
Each assignment's out and due dates are in the calendar above. The oral follows in a later week; its calendar tag marks the last day that round can be taken.
MS marks a session presented by Muhammad Shoaib.