Type to search.

CPSC_V 541H Topics in Computer Security and Privacy: Network Security

Class: Monday and Wednesday, 2:00-3:30 PM. We finish at 3:20: the last ten minutes of the slot are yours for getting to your next class.

Location: SWNG-Floor 2-Room 206

Instructor: Nguyen Phong Hoang (nphoang@ubcnet.ca)

Office hours: Monday and Wednesday, one hour before class (1PM-2PM) at ICCS 301, with a Zoom option (by appointment)

Piazza: Link. Passcode will be announced in class.

First class: Wednesday, September 9, 2026. Last class: Wednesday, December 2, 2026. The final week of term is deliberately class-free so you can focus on your final report and on other courses’ exams.

0. Overview This graduate-level course explores the technical and societal dimensions of network security through a thematic and research-oriented lens. Students will study core vulnerabilities in modern networks, explore state-of-the-art defenses, analyze real-world abuse, and investigate privacy technologies. New this year, the course closes with a module on how AI systems have changed network security: as attack surface, as attack tool, and as measurement target. Emphasis will be placed on primary research papers, hands-on experimentation, and a final independent research project.

1. Prerequisites While there are no formal prerequisites for this course, it is recommended that students have some understanding of computer networks (e.g., undergraduate-level networking course or equivalent experience of CPSC 317). Security knowledge is not required but will be helpful. The course will involve hands-on activities and a final project, so students should be comfortable with programming, command-line tools, and basic network protocols. Students should also have a strong interest in network security and be willing to engage in discussions and activities that challenge their understanding of security concepts. Topics that an undergraduate networking course already covers are treated here through their research questions and measurement methodology, not their mechanics. The in-class packet-capture CTF assumes CPSC 317-level comfort with capture tools.

2. Learning Objectives By the end of the course, students will be able to:

  • Analyze and critique security vulnerabilities in core Internet protocols
  • Apply security tools to capture, scan, and inspect network traffic
  • Understand adversarial strategies, including phishing, botnets, and censorship
  • Explore and evaluate privacy-enhancing technologies like Tor and encrypted DNS
  • Reason about the security and privacy of AI systems as networked services
  • Read, review, and discuss research papers the way a program committee does
  • Conduct and communicate original research in network security

3. Course Format

  • Seminar discussions based on recent and classic research papers
  • Hands-on labs and tool-based exercises (packet-capture CTF, Shodan and Censys, censorship measurement, agentic-AI CTF)
  • Media case studies (Netflix cybercrime documentaries)
  • A mock program committee: students review each other’s project drafts on HotCRP and discuss them PC-style
  • Final project with proposal, presentation, and technical report that is suitable for publication
  • No quizzes and no exams

4. Thematic Modules and Tentative Schedule

Mechanism refreshers are posted as per-session background material, so the lecture in the room starts from the research questions rather than from how a protocol works.

The ⚔️🛡️😈 column names the presenter, who plays the attacker; the rest of the room defends. Slots marked open are claimed at paper sign-up, which closes Friday, September 18.

One paper per discussion session is a must read. Those sessions mark one reading (respond). That is the paper everyone reads and posts a response about on Piazza by 10 AM on the day of that session. The other readings for that day are context: skim them, or lean on them as background if the topic is new to you.

Sessions with no (respond) marker carry no response. That covers the two Netflix & learn screenings, where the graded one-page review is already the written work; the hands-on days, whose readings are a tutorial and a tool page rather than a paper with results to argue with; today’s introduction; the mock PC meeting, where the reading is your classmates’ drafts; and the final presentations.

When a student claims a session at paper sign-up, the paper they propose becomes that session’s must read and replaces the one marked here, so the room arrives having read what the presenter is about to argue. Proposing your own paper is an equal option, not a fallback for when the list disappoints you. On the sessions I present myself, the marked paper stands.

Four conditions on a proposed paper. It needs my approval by the September 18 sign-up deadline; it must be from a top venue (USENIX Security, S&P, CCS, NDSS, IMC, SIGCOMM, PETS) within roughly the last three years; it must be a full paper with an evaluation or measurement section, because a response has to have evidence to argue with; and the substitution must be posted at least seven days before the session, so the room can actually read it. Propose later than that and the marked paper stays the must read while yours becomes a second reading you present. One must read per session either way: a proposed paper replaces the marked one, it never adds a second response.

You are exempt from the response for the session you present. Everyone else responds, including on the sessions I present myself.

DateTopicReadings and notes⚔️🛡️😈
Module 1Logistics, foundations, and ethics
Wed Sep 9 Introduction and logistics; how to read a paper How to Read a Paper (SIGCOMM CCR 07)
Writing Reviews for Systems Conferences (Roscoe 07)
Why Offensive Security Needs Engineering Textbooks (;login: 14).pdf)
Phong
slide
Mon Sep 14 Ethics and the law Legal Issues Surrounding Monitoring During Network Research (IMC 07)
The Menlo Report (2012)
Encore (SIGCOMM 15) (respond)
Security Trolley Problems (USENIX Sec 23)
OpenAI / Hugging Face hacking incident (2026)
Phong
slide
Wed Sep 16 Netflix & learn: adult privacy IBSA protection (USENIX Sec 24)
Non-Consensual Synthetic Intimate Imagery in 10 Countries (CHI 24)
AI Nudification Ecosystem (USENIX Sec 25)
Phong
slide
Module 2Core protocols and classic attacks
Mon Sep 21 TCP/IP Netflix review due EoD (AoE)
A Look Back at TCP/IP Security Problems (ACSAC 04)
Off-Path TCP Exploits (USENIX Sec 16)
Weaponizing Middleboxes (USENIX Sec 21)
Off-Path TCP Hijacking in Wi-Fi Networks (NDSS 25)
ReDAN: Remote DoS against NAT Networks (NDSS 25)
Phong
slide
Wed Sep 23 Packet capture and processing (hands-on CTF) Please come with tcpdump/tshark/wireshark pre-installed.
Beej's Guide to Network Concepts
Zeek
Bro (USENIX Sec 98)
Retina (SIGCOMM 22)
Phong
Mon Sep 28 BGP and routing security China Telecom incident (PAM 13) (respond)
Why Is Securing Routing Taking So Long (CACM 14)
SoK RPKI Security (USENIX Sec 25)
ru-RPKI-ready (IMC 25)
Ivory Tower Syndrome (USENIX Sec 26)
Phong
slide
Wed Sep 30 NO CLASS (National Day for Truth and Reconciliation)
Mon Oct 5 Emerging Domain Name Encryption Technologies Kaminsky guide (2008)
DNS Cache Poisoning Reloaded (CCS 20)
Domain Name Encryption Is Not Enough (PETS 21)
Path to Encrypted DNS with DDR (PETS 25)
ECH in Censorship Circumvention (FOCI 25)
IP-based Website Fingerprinting in IPv6 (PETS 26)
Sumeer
Module 3Network reconnaissance and detection
Wed Oct 7 Port scanning, Internet-wide measurement, and recon hands-on Art of Port Scanning (Phrack 97)
ZMap (USENIX Sec 13)
LZR (USENIX Sec 21)
Have You SYN Me? (IMC 24)
SYN Payloads in the Wild (IMC 25)
Second half hands-on: Shodan and Censys.
Project proposal due Thu Oct 8, 23:59 AoE
⚔️ open
Mon Oct 12 NO CLASS (Thanksgiving)
Wed Oct 14 Intrusion detection in the ML era Outside the Closed World (S&P 10)
Dos and Don'ts of ML in Security (USENIX Sec 22) (respond)
SoK Encrypted Traffic Classifiers (S&P 25)
⚔️ Nia
Mon Oct 19 Botnets, (D)DoS attacks and defenses Mirai (USENIX Sec 17)
Loopy Hell(ow) (USENIX Sec 24)
DDoS-for-hire Takedown Aftermath (USENIX Sec 25) (respond)
From Mirai to Gorilla (USENIX Sec 26)
⚔️ Robin
Wed Oct 21 Netflix & learn: US surveillance In-class screening; 1-page review due EoD (AoE) of the next class Phong 🎬
Module 4Distributed threats and abuse
Mon Oct 26 Email and spam Network-Level Behavior of Spammers (SIGCOMM 06)
Neither Snow Nor Rain Nor MITM (IMC 15)
SPF Beyond the Standard (USENIX Sec 24)
LLM-Generated Malicious Emails (IMC 25) (respond)
⚔️ open
Wed Oct 28 Phishing and social engineering in the LLM era Social Phishing (CACM 07)
Credential Spearphishing (USENIX Sec 17)
Efficacy of Phishing Training (S&P 25) (respond)
Personalized Phishing with LLMs (USENIX Sec 26)
Milestone check-in due Fri Oct 30
⚔️ open
Module 5Internet freedom
Mon Nov 2 Internet censorship: platforms and measurement ICLab (S&P 20)
Censored Planet (CCS 20)
GFW DNS Censorship (USENIX Sec 21)
A Wall Behind A Wall (S&P 25)
Geedge Networks Leak Analysis (USENIX Sec 26) (respond)
⚔️ open
Wed Nov 4 Censorship today and circumvention (hands-on) Geneva (CCS 19)
GFWeb (USENIX Sec 24)
Snowflake (USENIX Sec 24)
QUIC SNI Censorship of the GFW (USENIX Sec 25) (respond)
IRBlock: GFW of Iran (USENIX Sec 25)
UPGen (USENIX Sec 25)
Hands-on: OONI / Censored Planet data
⚔️ Roman
Nov 9 / Nov 11 NO CLASS (midterm break)
Module 6Privacy and anonymity
Mon Nov 16 Online privacy and tracking The Web Never Forgets (CCS 14)
Finding You (Citizen Lab 23)
Canvassing the Fingerprinters (IMC 25) (respond)
What WeChat Knows (PETS 25)
⚔️ Dieter
Wed Nov 18 Anonymous communications and traffic fingerprinting Tor (USENIX Sec 04)(respond)
I2P Anonymity Network (IMC 18)(respond)
WF against Traffic Drift (NDSS 26)
Draft paper to HotCRP due Fri Nov 20
⚔️ Huzaifa
Module 7AI meets network security
Mon Nov 23 AI systems on the network (hands-on prompt-injection CTF) What Was Your Prompt? (USENIX Sec 24) (respond)
Somesite I Used To Crawl (IMC 25)
Token-Length Side Channels on LLM APIs (USENIX Sec 26)
Peer reviews due Tue Nov 24 EoD
⚔️ Ritik
Module 8Wrap-up
Wed Nov 25 Mock program committee meeting Project drafts discussed PC-style on HotCRP All 🛡️
Mon Nov 30 Final project presentations I All
Wed Dec 2 Final project presentations II (LAST CLASS) All
Mon Dec 7 NO CLASS: report-writing week Final report due Sun Dec 20, 23:59 AoE. Venues with nearby deadlines: ACM IMC, PETS, ACM CoNEXT, FOCI

Session tags in the notes below: [L] instructor lecture, [D] paper discussion, [H] in-class hands-on or CTF, [N] Netflix & learn. A [D] session has a reading response due at 10 AM that day, and these tags are the only place that marks which sessions those are, so check them when you plan which five responses to submit. A [D] slot that nobody claims at sign-up defaults to me.

Session notes, background keywords, and open project questions

What the table cannot hold: what each session actually does, what to look up beforehand, and the open questions.

Most discussion sessions carry an open questions line: current research directions a term project, or a thesis chapter, could pick up. Treat those lines as a standing menu of project ideas, and read them in the first two weeks rather than the week the proposal is due.

Each topic pairs core papers that earned their place in earlier offerings with recent work from USENIX Security, IEEE S&P, CCS, NDSS, IMC, SIGCOMM and PETS. Every session stays practical: a capture to read, a tool to run, a measurement to question.

The background keywords are what to shore up before class if a topic is new to you. Where a session assumes a mechanism it does not teach, I post a refresher deck on Piazza before that session, so you can pick it up out of class and keep the room’s time for the research questions. Ask on Piazza if a session you are worried about has no deck posted.

Module 1. Logistics, foundations, and ethics

Wed Sep 9. Introduction and logistics; how to read a paper [L] Why network security; the security mindset; course mechanics; the project menu opens. We close with the reading method used all term: the three-pass read, and what a review contains.

  • Background keywords: threat model, security mindset, three-pass reading, anatomy of a conference paper.

Mon Sep 14. Ethics and the law [L][D] Menlo and Belmont principles; measurement ethics; Canadian computer law; responsible disclosure. Sets the rules for every project.

  • Background keywords: Menlo Report, Belmont Report, informed consent, beneficence, research ethics board, responsible disclosure, Criminal Code s. 342.1.
  • Open questions: what Menlo says about scraping for AI training data; ethics of measuring from users’ devices in censored regions.

Wed Sep 16. Netflix & learn: adult privacy [N] Screening and discussion. The reading around it runs from dating-app location leakage, through image-based sexual abuse, to the nudification-app ecosystem, which is where the deepfake era took this topic.

  • Background keywords: image-based sexual abuse (IBSA), nonconsensual intimate imagery, location trilateration, platform moderation and takedown, deepfakes.
  • Reading at three scales: Qin is 52 interviews, Gibson is 20 nudification websites, and the CHI paper surveys 10 countries. Between them you can argue about how common this is rather than guess, which is what the review asks you to do.

Module 2. Core protocols and classic attacks

Mon Sep 21. TCP/IP [L][D] The trust assumptions baked into IP and TCP, and the attacks they invite.

  • Background keywords: IP spoofing, sequence-number prediction, on-path vs off-path attacker, RST injection, shared-counter side channel, reflection and amplification, middlebox.
  • How the readings fit together: Bellovin names the protocol-level flaws in 1989 and grades his own predictions in 2004; Cao turns a hardening measure into an oracle by way of a shared counter; Bock shows censorship middleboxes reflecting and amplifying that same trust; Wang repeats Cao’s trick over Wi-Fi with a packet-size side channel instead of a counter; and ReDAN carries the same off-path reasoning into NAT, where the shared state is the translation table. The response prompt writes itself: what is genuinely new in Wang versus Cao?

Wed Sep 23. Packet capture and processing [H][L] Hands-on with tcpdump and tshark: what modern traffic (QUIC and TLS 1.3) does and does not reveal, then an in-class packet-capture CTF. Monday’s TCP/IP session is the setup for this one, so you arrive already knowing what the header fields and the handshakes mean.

  • Background keywords: pcap, BPF filter syntax, tshark display filters, TCP three-way handshake, TLS 1.3 handshake, SNI, QUIC, flow records.
  • Why the respond paper changed: Bro stays required as background and the lecture still covers its architecture, but the response anchor is now the QUIC censorship paper. QUIC v1 Initial packets are protected with keys derived from the connection ID and a published salt, so anyone on path can read the ClientHello. That means you can verify the paper’s core mechanism yourself, with tshark, during the same session.

Mon Sep 28. BGP and routing security [L][D] Route hijacks and leaks; why securing routing is taking decades; RPKI in the real world. We start at deployment reality and measurement, not at how BGP works.

  • Background keywords: autonomous system, eBGP session, prefix hijack vs route leak, MOAS conflict, RPKI, ROA, route origin validation, IRR.
  • Open questions: why RPKI adoption stalls where it does; passive hijack detection at scale; routing seen from under-measured regions.

Mon Oct 5. DNS and encrypted DNS [L][D] DNS as attack surface and surveillance chokepoint; DoH, DoT and DoQ; ECH and what encryption still leaks.

  • Background keywords: recursive vs authoritative resolver, cache poisoning, source-port and 0x20 randomization, DoH/DoT/DoQ, DDR, Encrypted Client Hello, resolver centralization.
  • Reading note: discussion anchors on SADDNS and the 2025 measurements. The illustrated Kaminsky guide is background for anyone new to cache poisoning, and is not discussed in class.
  • Open questions: who benefits from encrypted DNS given resolver centralization; how ECH adoption and censor response co-evolve; what post-quantum key exchange does to handshake fingerprintability. No full ECH deployment measurement has appeared at a main venue yet, so that gap is open ground for a project.

Module 3. Network reconnaissance and detection

Wed Oct 7. Port scanning, Internet-wide measurement, and recon hands-on [L][D][H] How the Internet gets mapped, from Phrack to Censys: paper discussion in the first half, then hands-on with the scariest search engines on the Internet, querying Internet-wide scan data rather than scanning hosts yourself.

  • Background keywords: SYN vs connect scan, banner grabbing, scan rate and blocklist etiquette, network telescope, Shodan and Censys query syntax.

Wed Oct 14. Intrusion detection in the ML era [L][D] From Bro to learned detectors, taught with skepticism: base rates, evasion and evaluation hygiene.

  • Background keywords: signature vs anomaly detection, base-rate fallacy, precision and recall, class imbalance, label quality and ground truth, concept drift, adversarial evasion.
  • Open questions: whether traffic “foundation models” survive deployment; what an operator needs before trusting a learned detector.

Mon Oct 19. Botnets, (D)DoS attacks and defenses [L][D][H] Volumetric to application-layer DoS; the booter economy; IoT botnets. In-class DoS reasoning exercise on isolated infrastructure.

  • Background keywords: amplification factor, reflector, booter and DDoS-for-hire, command and control, default credentials, sinkholing, takedown, backscatter.

Wed Oct 21. Netflix & learn: US surveillance [N] Screening and discussion. Connects forward to the government-threats thread in Modules 5 and 6.

  • Background keywords: bulk collection, metadata vs content, lawful interception, upstream collection, whistleblowing.

Module 4. Distributed threats and abuse

Mon Oct 26. Email and spam [L][D] Why email security is still hard; the spam value chain; what LLMs change.

  • Background keywords: SMTP, MX record, STARTTLS, SPF, DKIM, DMARC, open relay, blocklist, spam value chain.
  • Open questions: measuring AI-generated abuse without ground truth; whether detection or economics is the winning defense.

Wed Oct 28. Phishing and social engineering in the LLM era [L][D] Human-centric security; spearphishing detection; AI-written lures and deepfake voice.

  • Background keywords: spearphishing, business email compromise, typosquatting and homoglyphs, click rate, embedded phishing training, voice cloning.
  • Focus: evidence rather than taxonomy. What detection and training research actually shows, and what LLMs change.

Module 5. Internet freedom

Mon Nov 2. Internet censorship: platforms and measurement [L][D] How nation-state censorship works and how the field measures it at scale. This one is my home turf.

  • Background keywords: DNS injection, TCP RST injection, SNI filtering, on-path vs in-path censor, deep packet inspection, vantage point, remote measurement, false positives in censorship detection.
  • Focus: how the measurement platforms know what they claim to know, then a decade of inference tested against the Geedge leak.
  • Open questions: longitudinal coverage vs depth; remote measurement validity; measuring throttling rather than blocking; what the Geedge leak confirms and overturns about a decade of inference.

Wed Nov 4. Censorship today and circumvention [L][D][H] GFW internals and recent escalations, and the evasion cat-and-mouse they feed. The hands-on works with OONI and Censored Planet data, so bring a laptop and expect to need an Internet connection.

  • Background keywords: residual censorship, TCB teardown and packet fragmentation, domain fronting, pluggable transport, obfs4, active probing, probe resistance, WebRTC.
  • Reading note: GFWeb frames the session and the response anchors on the QUIC SNI paper, so read GFWeb for its measurement pipeline and save your argument for the 2025-26 escalations. UPGen and IRBlock are the two I would most like to see presented here.

Module 6. Privacy and anonymity

Mon Nov 16. Online privacy and tracking [L][D] Web tracking mechanisms; location leakage; the regulatory layer (GDPR, BC PIPA); who filters the filters.

  • Background keywords: third-party cookie, canvas fingerprinting, cookie respawning, cross-device tracking, SS7 location disclosure, GDPR, BC PIPA, consent notice.
  • Reading note: the anchors here are the 2025 measurement studies.

Wed Nov 18. Anonymous communications and traffic fingerprinting [L][D] Onion and garlic routing; anonymity system measurement; what encrypted traffic still reveals.

  • Background keywords: onion routing, garlic routing, circuit, guard and exit relay, website fingerprinting, closed vs open world evaluation, traffic drift, padding defense.
  • Focus: proxy, VPN, Tor and I2P mechanics are compressed to minutes. We read Tor and I2P as research papers, for their design rationale and measurement method, then spend the session on what traffic analysis still infers despite them.

Module 7. AI meets network security

Mon Nov 23. AI systems on the network: attacks on and with LLMs [L][D][H] The new attack surface: prompt injection as an untrusted-input problem; what encrypted LLM traffic leaks; AI crawlers reshaping web operations. In-class agentic-AI CTF, a prompt-injection game.

  • Background keywords: direct vs indirect prompt injection, system prompt, tool use and agentic loops, token streaming, KV cache, robots.txt and crawler opt-out, packet-length side channel.
  • Open questions: side channels on inference traffic; measuring the agentic web; who gets crawled and who can refuse.

Module 8. Wrap-up

Wed Nov 25 mock program committee meeting [H]. Mon Nov 30 and Wed Dec 2 final project presentations. Mon Dec 7 no class. These sessions have no assigned readings and no reading responses, so the only preparation is your own draft, your reviews and your talk. The mechanics are in the grading section below.

5. Grading The course will be graded based on the following components. There are no quizzes and no exams. The weights are unchanged from the version published on September 8. What is new in this revision is that two components take part of their mark from the room: your classmates score the substance of your paper presentation, and they rate the reviews you write. I still mark every component myself, peer input is averaged into my marking rather than replacing it, the total your classmates can move is capped at about three points of your final grade, and I keep final responsibility for every grade. Nothing your classmates assign sets any part of your project grade. Revised September 9, 2026, in the first week of term.

Final research project (45%)
The centerpiece of the course: an independent research project, alone or in pairs (pairs must discuss with the instructor first), aiming at a technical report suitable for publication. Milestones: a one-page proposal due October 8 (5%), with at least one feedback meeting with Phong during the first month; a one-page milestone check-in with data in hand due October 30 (5%); a full draft to the course HotCRP by November 20 (ungraded, but required so peers can review it); a final presentation on November 30 or December 2 (10%), in a 15-minute slot: a 12-minute talk plus 3 minutes of questions; and the final report, at least 6 pages in ACM SIGCOMM format, due December 20 AoE (25%). Projects can range from a network measurement study, to a new security tool or technique, to the analysis of a real-world security issue. Negative results with sound methodology are welcome. No part of this 45% is assigned by your classmates. They review your draft and they question your final talk, but what they produce is feedback, not marks: I am the only person who has read your data, so I am the only person who scores it. The final report carries one required appendix, at most one page and outside the page minimum: a change log giving each substantive review point you received, with one line on what you changed and where, or a defended refusal, plus your own score against the report rubric and two lines on why you gave it. The change log is checked against your actual HotCRP reviews. A missing appendix costs you under Writing and presentation.
Paper presentation (15%)
Each student presents one research paper from the reading list, or a relevant paper of their choice from a top venue within roughly the last three years, approved by the instructor. Sign-up closes Friday, September 18. A paper you propose becomes the must read for your session and replaces the one marked in the schedule, provided I approve it and it is posted on Piazza at least seven days before your session, so the room has time to read it and respond to it. Propose it later than that and the marked paper stands as the must read while yours becomes a second reading you present. It has to be a full paper with an evaluation or a measurement section, because the room has to be able to argue with its evidence, and it cannot be one of my own papers. Presentations follow a fixed format: 20 minutes of presentation plus 10 minutes of discussion that the presenter moderates. I score every talk myself against the five-part rubric shared in advance: content and correctness (30%), critical analysis (25%), delivery and clarity (20%), discussion facilitation (15%), and Q&A handling (10%). The room scores the substance of the talk, once, on an unsigned slip handed in as you leave: one overall score from 1 to 5 plus one sentence saying why, judging what the talk taught you about the paper and how real its critique was. Use the whole scale, because a slip that gives every talk a 5 carries no information. I then discard the highest and the lowest slip, average what is left, and compare that average against the average across all student talks this term. The difference is doubled, rounded to the nearest quarter point, and capped at 1.5 points either way, so the cap is reached once the room puts your talk three quarters of a point away from its own average. That adjustment moves my rubric mark and nothing else. Nobody but me scores delivery, pace, slides, spoken English, discussion facilitation or Q&A handling, because those are exactly the places where an accommodation or a first language would end up inside someone else’s number. If fewer than four slips come in for a talk, there is no adjustment and my mark stands. Presenting an additional paper can replace a lower component score.
Netflix & learn (10%)
We will watch a cybercrime documentary and write a short review. This year, we continue with episodes from the Netflix series ‘Web of Make Believe: Death, Lies and the Internet’. The review should summarize the main points of the documentary, discuss the relevance to security and privacy, and provide a critical analysis of the content. The review should be submitted as a written report no longer than 1 page, due by the end of the day (AoE) of the next class after each screening.
Reading responses (10%)
For paper-discussion sessions (any session with assigned papers and a student presenter), submit a short response by 10 AM on the day of that session: three bullets with the key idea, one critique, and one question you would raise in discussion, at most 150 words. Responses are due on every session marked (respond) in the schedule, including the two I present myself, and the only exemption is the session where you are the presenter. Only your best 5 responses count, so this is deliberately light: the goal is showing up prepared, not weekly busywork. Your classmates never mark these. Marking three bullets is not a skill worth practicing and it would mean a new peer round almost every week.
Peer reviews & mock PC meeting (10%)
Each student writes structured reviews of two classmates’ project drafts on HotCRP, due November 24, using the review form we practice in week 1. Two reviews, not three: writing more of them makes each one worse, and these reviews exist to help the author rather than to score the draft. The mock program committee meeting on November 25 discusses each draft the way a real PC discusses submissions, ordered by topic, with the reviewer who champions a paper speaking to it first, and every student speaks to at least one paper they reviewed. Six of the ten points are the reviews and four are the meeting. Two reviews in on time and on form earn 4.5 of those 6 by default, and what moves you off that default is student judgment. On the morning of November 25 I open all reviews to the whole class, and you rate each other’s reviews in HotCRP using its own vocabulary: good review, needs work, too short, too vague, too narrow, not correct, disrespectful. After the meeting, each author sends me a private Piazza post rating how helpful each review they received was, with one sentence each. You reach 6 of 6 when most raters call your reviews good reviews and both of your authors found them helpful. You drop to 3 of 6 or below when two or more people flag the same problem in a review and I agree with them on my own read, and to 0 for a review you did not write. I read one of your two reviews closely, plus every review that two or more people flagged, and my read decides the mark. Reviews are graded on specificity, meaning comments tied to a section, a figure or a number, and never on whether your scores agreed with the other reviewer or with mine. The November 20 draft is a hard gate on this component, because a missing draft costs two classmates their reviewing assignment as well as costing you your own feedback. This is deliberate training for the peer-review work every researcher does.
Participation (10%)
Active participation in class discussions and activities is essential for success in this course. Students are expected to engage in discussions, ask questions, and provide feedback to their peers, especially during hands-on activities and paper presentations where you will play the role of defenders to challenge the attacker’s assumptions. On presentation days, every attendee is expected to ask at least one question. No part of this mark comes from your classmates scoring you. What your classmates supply here is the questions you have to answer, not a number.
Hands-on CTFs (up to 5% extra credit)
In-class hands-on activities (packet-capture CTF, reconnaissance with Shodan and Censys, censorship measurement, and an agentic-AI prompt-injection CTF) run on the instructor’s isolated infrastructure and can earn up to 5% extra credit. Small prizes, budget permitting.
Peer marks: the cap, the anonymity, and the appeal valve
Two places, and only two: an adjustment of at most 1.5 points out of the 15 for your paper presentation, and up to 1.5 of the 6 review-quality points inside the peer-review component. That is the whole exposure, about 3 points of your final grade, and I moderate both. Why bother: research on peer marking of talks finds that the average of a handful of peers is about as reliable as one instructor, and that a single instructor’s own reliability on a talk is lower than people assume, so averaging the room’s judgment into mine is a better measurement than mine alone. Learning to assess is also half of what a program committee does, and this course is about how a PC works. Where peer marks stop, and why: not on your project, because in a room where every draft is competent a peer score has nothing left to discriminate, and studies where several peers marked written work with a rubric missed genuinely weak submissions; not on delivery, spoken English or Q&A, because an accommodation is confidential and a first language is not an assessment criterion; not on participation, where scoring each other would reward volume and friendship. On anonymity, here is exactly what I can promise. Presentation slips are unsigned, and I pass you the typed sentences and the aggregate rather than individual scores, but a small room means handwriting is recognizable, so treat a slip as unsigned rather than anonymous. HotCRP reviews are blind to the author until after the November 25 meeting, and HotCRP’s review ratings are anonymous by design and never shown to the author of the review. Author helpfulness ratings are anonymous to the reviewer but visible to me. The mock PC meeting itself is deliberately not anonymous: reviewers speak as themselves, defend what they wrote, and answer the author, because defending a review out loud is the skill being taught and it is also the reason a review you did not write yourself will not survive the room. I always know who wrote and rated what. I do look at whether someone’s numbers sit far from everyone else’s on the same talk or the same review, not to grade agreement, but because a small room is the easiest place to run a rating ring and also the easiest place to spot one. Drafts are confidential exactly as a real submission is: pasting a classmate’s unpublished draft into an external AI service is prohibited here for the same reason CCS and USENIX Security prohibit it for their reviewers, and a hidden instruction planted in a draft to steer an AI-assisted reviewer is fabrication under section 8. If you think a peer-influenced mark is wrong, email me within seven days and I will re-mark that component myself, from my own notes, and my mark stands. Every slip, rating and score is kept so that any grade in this course can be reconstructed line by line.

5.1 The research project in detail

This is the full project guide: what counts as a project, what to hand in at each milestone, what infrastructure you can use, the ethics checklist, and the rubric. Component weights are in the Final research project (45%) entry above.

Start now. Decide a direction in the first four weeks, and meet with me at least once during that first month before you write the proposal.

What counts as a project, and what does not

The goal is a small but real piece of network-security research, written up at workshop-paper quality. Past 538H projects have gone on to become real publications and thesis chapters. That is the bar we aim for, with a scope you can actually finish in one term.

Pairs are expected to do roughly twice the work of a solo project, so talk to me before you commit to one.

Any of these four shapes is welcome, as long as it produces new evidence or a new artifact:

  • Measurement study. Measure something real about the Internet: deployment of a protocol, a censorship or filtering behavior, a privacy leak, a misconfiguration at scale, an abuse ecosystem. This is the most natural fit for the course and for my own expertise.
  • Security analysis. Take a protocol, product, or deployment and find, characterize, and responsibly analyze a weakness.
  • Tool or system. Build something useful (a measurement tool, a defense, a detector) and evaluate it against real data or traffic.
  • Reproduction and extension. Reproduce a recent paper’s central result, then extend it: a new vantage point, a new dataset, a new year. Reproductions are genuinely valued and they de-risk your term.

Two things do not qualify: a project that only surveys the literature, and a project that only re-runs someone’s released tool without adding evidence of your own.

Milestones and what to hand in
Milestone Due What to hand in
Proposal and feedback meeting Thu Oct 8 (AoE) One page: your question, why it matters, what you would measure or build, feasibility, infrastructure needs. Meet with me at least once during the first month.
Milestone check-in Fri Oct 30 One page showing you have data or a working prototype in hand: preliminary results, and whatever is blocking you.
Draft paper Fri Nov 20 Full draft in SIGCOMM format, submitted to the course HotCRP. Ungraded, but required, because your classmates review it.
Final presentation Mon Nov 30 or Wed Dec 2 15-minute slot: a 12-minute conference-style talk plus 3 minutes of questions. Five slots per session, so the two days hold ten talks.
Final report Sun Dec 20 (AoE) Camera-ready paper that incorporates the reviews you received.

The early milestones exist to force data collection to start early. In past offerings, the single biggest project risk was leaving measurement to the final weeks and then being blocked by infrastructure or by slow collection. Aim to have some data by the check-in, even if it is imperfect.

Infrastructure, and the resilience requirement

You have several options. Pick early, and have a backup.

  • Course cloud credits. I can provide limited cloud credits (AWS, GCP, or DigitalOcean) on request. Ask for them in your proposal, or earlier, in your first-month meeting.
  • Your own VPS or lab machine. Fine, but do not run measurements that could get a personal account terminated mid-term.
  • Research testbeds and public data. RIPE Atlas, university looking glasses, public scan datasets (Censys, Rapid7, RIPE, CAIDA, OONI, Censored Planet, Tranco lists) and Certificate Transparency logs are excellent, ethically clean starting points that need no risky active measurement of your own.

Resilience requirement

We learned this one the hard way. In a past term, central IT locked down a campus subnet that students were measuring from, one week before the deadline, and that halted several projects. Because of that:

  1. Do not depend on a single vantage point or a single institutional network.
  2. Archive your raw data continuously to durable storage, never only on the collecting host.
  3. If your project needs any special network arrangement, raise it with me by the proposal so it can be pre-cleared.

Guaranteeing you are never locked out of your own data a week before the deadline is a shared responsibility, and these three rules are how we hold up our end.

Ethics checklist and the sign-off rule

Network-security research can harm real people and systems. Before you collect any data that touches a system or user outside the course infrastructure, submit a short ethics note, about half a page, answering these four questions:

  1. Who or what could be harmed by this measurement, and how do you minimize that harm? Rate limits, opt-out, not probing vulnerable hosts, not deanonymizing individuals.
  2. Are you collecting any personal data? If so, why is it necessary, how is it stored, and when is it deleted?
  3. Does your active measurement risk being read as an attack, for instance scanning, probing, or spoofing? How do you scope it and how do you announce it?
  4. If you find a vulnerability, what is your responsible-disclosure plan?

I sign off before collection begins. When in doubt, ask first: “I did not think it would matter” is not a defense. We follow the principles of the Menlo Report, linked under Legality and Ethics below, and of the Belmont Report.

Report format and grading rubric

Format

The final report uses the ACM SIGCOMM conference format (ACM sigconf), at least 6 pages plus references. Your report should read like a real submission: clear problem statement, related work, methodology, results with figures, limitations, ethics, and reproducibility notes. A paper skeleton, LaTeX source plus an Overleaf link, will be posted on Piazza.

Rubric

The same rubric applies to the final report and to the final talk.

Dimension Weight What “excellent” looks like
Problem and motivation 15% Clear, well-scoped, matters to the field
Methodology and rigor 25% Sound method, honest about limitations, reproducible
Results and analysis 25% Real evidence, correctly interpreted, good figures
Ethics and responsibility 10% Thoughtful, followed the checklist
Writing and presentation 15% Reads like a workshop paper, and a clear talk
Novelty and effort 10% Genuine new evidence or artifact for the scope

Negative results can score full marks, as long as the method is sound and the analysis is honest. Good process is rewarded over lucky outcomes.

5.2 Reading, presenting, and reviewing

These are the mechanics you will use most weeks. Section 5 gives the weight and the deadline for each component; this section is how the work itself is done.

How to read a paper, and the three-bullet response format

The three-pass read

You are not expected to understand every line. Read in three passes:

  1. The five-minute pass. Title, abstract, intro, section headings, figures, conclusion. Answer: what problem, what is the claimed contribution, does it matter?
  2. The one-hour pass. Read for the main idea and the evidence. Note the method, the dataset or measurement, and the key result figure. Mark what you do not understand rather than stalling.
  3. The critical pass. Ask: do the claims follow from the evidence? What is the threat model or the measurement vantage? What is the biggest limitation? What would you do next?

Most papers deserve the first pass only. That is a decision, not a failure. This is also the method behind your reading responses and your reviews, and in the first lecture we work through all three passes together on one paper.

What goes in the three bullets

  • Key idea: the problem and the core insight, in your own words.
  • Critique: the most questionable assumption, method gap, or limitation (or the most convincing strength, if you must).
  • Question: one thing you would raise in discussion, which you should expect to ask out loud on the day.

A response that is fluent but generic scores low. One that is rough but specific to the evidence scores high.

Your response is your entry ticket to discussion, and it is what guarantees every presenter a prepared and engaged audience. The deadline, the word limit, the best-5 rule and the presenter exemption are under Reading responses in section 5.

From reading to reviewing

A good reading response is a good review in miniature: it identifies the contribution, weighs the evidence, and gives feedback that is constructive, specific and respectful. That is exactly what the peer reviews on HotCRP and the mock program committee ask of you, so the weekly bullets are training for the review round rather than a separate exercise.

Presenting a paper: the clock, and a structure that works

The clock

The clock is strict and I hold you to it, so that sessions stay balanced and student talks never take more than half a session. Practice to fit. The exact split is under Paper presentation in section 5. This is the paper talk, not the final project talk, which is shorter and described under Final research project.

Structure that works

Segment Time What it does
Motivation and problem 2-3 min Why should the room care?
Background 2-3 min Just enough to follow the paper
Approach and method 6-8 min The heart of the talk, use the paper’s own figures
Key results 4-5 min The evidence, honestly presented
Critical analysis 2-3 min Limitations, your own critique, open questions
Discussion 10 min You moderate. Bring 2-3 seed questions in case the room is quiet

The critical analysis is the segment that separates a good talk from a summary. You do not have to agree with the paper: the best presentations take a position and defend it, so present a paper you find genuinely interesting.

How presentations are graded, and what the audience owes

Rubric

Peers and I score the same five dimensions, and you get the rubric before you present. The weights are shares of your paper-presentation grade.

Dimension Weight Excellent
Content and correctness 30% Accurate, right depth, key idea made clear
Critical analysis 25% Real, specific critique, not just a summary
Delivery and clarity 20% Well-paced, clear slides, on time
Discussion facilitation 15% Draws the room in, handles questions well
Q&A handling 10% Answers directly, says “I don’t know” honestly

What the audience owes

Discussion should never rest on me alone. Every attendee has a job on presentation days, set out under Participation in section 5, and the questions you ask there count toward that grade. Framing a real question is also practice for the reviews you write later in the term, and it is what makes a presenter face a room that actually read the paper.



6. Academic Integrity

7. Legality and Ethics

Through this course, we will discuss various security tools and techniques that can be used for both defensive and offensive purposes. By introducing these tools, the course aims to provide students with a better understanding of network security concepts and challenges. However, it is the responsibility of the students to ensure that they use these tools in a legal and ethical manner. Course projects frequently measure live networks: any measurement that touches systems or users outside the course infrastructure requires instructor sign-off before data collection begins. If you have any questions or concerns about the legality or ethics of using a particular tool or technique, please discuss it with the instructor.

8. Use of AI Tools

We study AI-era security, so pretending AI assistants do not exist would be strange. The policy is use-with-accountability: AI tools may help you probe a paper or polish your writing (with a one-line disclosure), and AI coding assistants are permitted for project code, but reading responses and reviews must reflect your own judgment in your own words, peers’ unpublished drafts must never be pasted into external AI services, and AI-fabricated citations, data, or results are academic misconduct. You remain responsible for understanding everything you submit.

9. Late Policy

We understand that unexpected circumstances may arise that prevent you from submitting an assignment on time. Thus, we will allow a total of 72 hours of late submission for the entire semester. You can use this time for any submission throughout the semester with 1 hour being the minimum unit. Once you have used up all the hours, each late submission will incur a 25% penalty per day. Reading responses are the one exception: they are not accepted late because they feed same-day discussion, and the best-5 rule absorbs misses. If you need more time due to extenuating circumstances, please contact the instructor as soon as possible.