Dr. Bill Young
CS378: Information Assurance and Security
Spring Semester, 2013
The following are some possible topics for your CS378 project. You'll
write a paper on topic.
The topics below are simply suggestions. You are free to define your
own topic or to revise one of these. However, your topic must deal
with a substantive issue in information assurance and security and must
be approved by Dr. Young. You will be submitting a report on the
topic and preparing a "poster presentation" on your topic.
You are strongly encouraged to work with a team of up to 4 students on the
project.
No two groups may choose the same topic, though topics may be
related. So if you find one of the following attractive, stake your
claim early. There is more than enough material for a book on any one
of the following topics, but some likely will require more digging
than others.
If you are feeling somewhat ambitious, Prof. Shmatikov often posts
lists of topics for projects for his security classes. You might look
there for additional ideas:
Prof. Shmatikov's courses.
- Defensive cyberweapons
- Hackerspace Global Grid
- Mesh networking
- Privacy and the government
- Hacking automobiles
- Hacking and some aspect of critical infrastructure
- Terrorism using Social Media
- The automation paradox
- Internet ID
- Cybergeddon: Is it Possible?
- Security/Cyberwarfare and Cloud Computing
- Metasploit
- Homomorphic encryption
- New Malware attacks on cell phones
- The Internet "kill switch" controversy
- Jail-breaking mobile devices
- Data retention rules for ISPs
- Titan Rain or similar attack
- Careful analysis of a specific malware attack
- Stuxnet
- Son of Stuxnet
- LFI's and php-injected JPEGs
- Weakness in AES
- Some aspect of laptop security
- Side Channel Attacks
- Behavioral (zero touch) authentication
- Full Disclosure and Hacker Ethics
- Internet censorship
- China vs. Google
- Something relating to cyberwarfare
- Cyberwar Rules of Engagement
- Net Neutrality controversy
- The Java Security Model
- Smartcard Security
- Integer Overflows
- Buffer Overflows
- Mobile/smart phone security
- Race Conditions
- Randomness
- Honeynets
- Security on Distributed Object Platforms
- The Trusted Computing Controversy
- Bluetooth Security
- RFID Tags
- VOIP Security
- Electronic Currency
- Single Sign-on
- Proof-Carrying Code
- SSL and TLS
- Password Generation
- Passwords and User Authentication
- SQL Injection Attacks
- Anti-virus software
- Electronic voting
- Cross Site Scripting
- Security and Cookies
- Taint Tracking
- Format String Attacks
- Host-based Intrusion Detection
- Network-based Intrusion Detection
- Security Planning Tools
- Security Policy Languages (KeyNote, XACML, etc.)
- TEMPEST
- WIFI Security
- Phishing and pharming
- Random Number Generators
- Inter-domain routing
- Hackers Toolkits
- Biometric Authentication
- Anonymous Networks
- Quantum Cryptography
- Whitelisting and blacklisting as security techniques
- Analysis of the effects of one of the regs (HIPAA, SOX, GLBA, etc)
- Information Censorship in China
- Economics of Spam
- Removable storage security
- Social engineering
- Organized Cyber Crime
- Operation Aurora
- Same-Origin Policy
- Networks and Crypto
- Post-Quantum Crypto
- Catfishing
- Others will be added as I think of them.