4.5 ECTS · Compulsory · Raúl Durán Díaz
You will learn the essential cryptographic mechanisms for protecting information, their mathematical foundations, and how to implement these mechanisms securely and efficiently in programming.
Read more
You will learn the essential cryptographic mechanisms for protecting information, their mathematical foundations, and how to implement these mechanisms securely and efficiently in programming.
The main objective of this subject is to analyse the basic mechanisms that guarantee the confidentiality and integrity of information, ensure its authorship and prevent its illegitimate repudiation. The basic cryptographic primitives will be studied together with their mathematical foundations, since this is really the only way to understand how they work and what their weaknesses are.
The applied focus of the subject will lead us to pay attention to the most up-to-date cryptography-oriented programming libraries at any given time. The fundamental concepts will enable students to use these libraries securely and efficiently, both when designing applications with cryptographic requirements and for the cryptanalysis and auditing of existing ones.
Lecturer in charge: Raúl Durán Díaz
Applied Cryptography · Official course guide
4.5 ECTS · Compulsory · Susel Fernández Melián
You will learn the main concepts of software and operating system security, and the main vulnerabilities and threats affecting these systems, as well as basic malware analysis and forensic analysis techniques.
Read more
You will learn the main concepts of software and operating system security, and the main vulnerabilities and threats affecting these systems, as well as basic malware analysis and forensic analysis techniques.
This subject introduces the main concepts covered by software and operating system security, their importance to the overall security of a system, the properties of secure software, as well as the main vulnerabilities and threats in software. Malware analysis techniques are introduced to understand how malicious code works and to assess the damage caused, and the particularities of security in web applications and services and applications for mobile devices are also covered, with their own specific traits and characteristics. In addition, topics related to the investigation of computer crimes such as cyberterrorism and cybercrime are addressed.
Lecturer in charge: Susel Fernández Melián
Fundamentals of Software and Component Security · Official course guide
4.5 ECTS · Compulsory · José Javier Martínez Herráiz
You will learn comprehensive information security management methods, including incident management, security audits and good security practices.
Read more
You will learn comprehensive information security management methods, including incident management, security audits and good security practices. You will also learn about national cybersecurity legislation and international standards.
This subject addresses matters that precede information security management, such as knowledge of national cybersecurity legislation and international standards on security audit methodologies and good security practices. It also covers security incident management and the various techniques used prior to incidents, such as the use of sensors that alert us to anomalies or security breaches, or the forensic analysis of intrusion evidence.
Lecturer in charge: José Javier Martínez Herráiz
Fundamentals of Information Security Management · Official course guide
4.5 ECTS · Compulsory · Marino Tejedor Romero
You will learn to analyse and use the protocols, network hardware and mechanisms for end-to-end secure communication of information over different types of networks and media, including the special challenges of wireless and mobile networks.
Read more
You will learn to analyse and use the protocols, network hardware and mechanisms for end-to-end secure communication of information over different types of networks and media, including the special challenges of wireless and mobile networks.
In this subject we will explore in depth the technical aspects related to communications security in different environments. We will analyse the protocols, network hardware and mechanisms for end-to-end secure communication of information over different types of networks and media. After reviewing the general fundamentals of secure communications (e.g. mutual authentication or secret exchange), the subject will address the security of Internet protocols at their different layers (mainly link, network and transport). Finally, the particular challenges of security in wireless communications will be studied, both local (Wi-Fi, Bluetooth) and mobile.
Lecturer in charge: Marino Tejedor Romero
Secure Communications · Official course guide
4.5 ECTS · Compulsory · Coordinator: Enrique de la Hoz · Taught by: Marino Tejedor Romero
You will learn security principles and good practices for the design and development of systems, including the specification of security requirements, risk analysis, code analysis and dynamic penetration testing, among others.
Read more
You will learn security principles and good practices for the design and development of systems, including the specification of security requirements, risk analysis, code analysis and dynamic penetration testing, among others.
A fundamental strategy for software and component security is the use of security principles and good practices throughout their entire life cycle. Achieving secure systems requires the use of methodologies or procedures for the analysis, design, implementation and testing of systems that treat security as a core element, establishing measurable security requirements and controls throughout the entire development cycle.
This subject covers the processes and techniques for ensuring the security of software and components throughout their entire life cycle, covering security requirements specification, abuse cases, risk analysis, code analysis, dynamic penetration testing, threat modelling, security operations and external reviews, among others.
Lecturer in charge: Enrique de la Hoz
Design and Development of Secure Systems · Official course guide
4.5 ECTS · Compulsory · Coordinator: Miguel Ángel Sicilia Urbán · Taught by: Valentín Martín Manzanero
You will learn to work with different types of technologies for intrusion detection, including NIDS, HIDS and SIEM systems, as well as log aggregation and correlation technologies.
Read more
You will learn to work with different types of technologies for intrusion detection, including NIDS, HIDS and SIEM systems, as well as log aggregation and correlation technologies.
The subject addresses the different types of systems, data types and technologies for detecting intrusions in networks and computer equipment, including NIDS, HIDS and SIEM systems, as well as log aggregation and correlation technologies. Systems aimed at cyber intelligence are also addressed, in their various aspects. The fundamentals and systems for organising knowledge for cybersecurity are also introduced, along with their use for classification and interoperability in the field.
Lecturer in charge: Miguel Ángel Sicilia Urbán
Information Systems for Cybersecurity · Official course guide
4.5 ECTS · Compulsory · Bernardo Alarcos Alcázar
You will learn to implement information security management systems (ISMS) for risk management and for establishing and monitoring security policies and contingency plans.
Read more
You will learn to implement information security management systems (ISMS) for risk management and for establishing and monitoring security policies and contingency plans.
Having control over the security level of an organisation or company that relies on ICT is essential to guarantee its objectives. This subject focuses on the ISO 27000 standard to address the methodology involved in setting up an information security management (ISMS) project, and to that end, some procedures covered by an ISMS are first examined, such as risk analysis and management, security policies and contingency plans. The National Security Framework (Esquema Nacional de Seguridad) is also addressed, and how to approach it from an ISMS perspective. Forensic analysis is also covered as part of the investigation following a security incident, including forensic analysis and the management of digital evidence so that it is valid in judicial proceedings.
Lecturer in charge: Bernardo Alarcos Alcázar
Information Security Management Systems · Official course guide
4.5 ECTS · Compulsory · Coordinator: Miguel Ángel Sicilia Urbán · Taught by: Enrique Caño Marín, Alberto Ballesteros Rodríguez
You will learn to use scientific programming tools to obtain, clean and transform cybersecurity-related data in order to apply different analytical, learning and processing techniques to it.
Read more
You will learn to use scientific programming tools to obtain, clean and transform cybersecurity-related data in order to apply different analytical, learning and processing techniques to it.
The subject introduces data science as a framework for cybersecurity data analysis, and covers the use of scientific programming tools to obtain, clean and transform cybersecurity-related data. Building on this know-how, the fundamentals of different analytical techniques are addressed, including exploratory analysis, statistical techniques and supervised and unsupervised machine learning, as well as natural language processing techniques and social network analysis. Finally, scalable technologies for processing this data on distributed computing engines are introduced.
Lecturer in charge: Miguel Ángel Sicilia Urbán
Data Analysis for Cybersecurity · Official course guide