Design and Analyze Secure Networked Systems

所在平台: Coursera

课程主页: https://www.coursera.org/learn/design-secure-networked-systems

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:设计与分析安全网络系统 课程概述:本MOOC课程将带领学员学习基本的网络安全概念,以及如何识别网络系统中的漏洞和威胁。我们将应用CIA(机密性、完整性、可用性)基本安全服务来处理最近的网络攻击事件,如OPM数据泄露。学员将学习风险管理框架,以分析网络系统中的风险,并应用基本的安全设计原则来保护数据和确保计算机系统的安全。我们将评估程序和数据的可信性,展示验证其完整性和真实性的正确方法。此外,我们还将应用最小权限原则,以控制不同用户组和系统进程的共享访问权限。在亚马逊云实例上,我们将使用GnuPG软件生成公钥和私钥对,用于签署和验证文件以及加密文档。最后,学员将学习如何在网络服务器上发布软件及其相关签名和发布密钥,及在PGP密钥服务器上发布公钥以供他人获取。 课程大纲: 1. **网络安全概念与安全原则** - 本模块将介绍基本的网络安全概念,帮助学员识别网络系统中的漏洞根本原因,并区分来自内部和外部的威胁。我们将分析最近网络攻击事件的促成因素,并讨论基本安全服务的防御和处理方法。我们还将介绍风险管理框架,以分析网络系统中的风险,并应用基本安全设计原则来保护数据和确保计算机系统的安全。 2. **保护数据访问与验证信任来源** - 在本模块中,我们将应用最小权限原则,控制用户和系统进程的适当访问权限。通过使用Unix文件访问机制的项目文档访问控制示例,我们将演示这种访问控制的重要性。以OPM数据泄露事件为例,强调充分数据保护原则的必要性。 3. **使用GPG进行软件签名/验证** - 本模块将介绍GPG软件工具,用于生成公钥/私钥对,以签署和验证文档,以及加密文档,并将在我们的网络服务器和PGP密钥服务器上发布公钥,供他人检索。学员还将学习如何验证常见的开源软件包,如Apache和Putty,并了解如何签名软件和正确列出软件包的PGP签名及我们的签名公钥。 4. **成为CA,设置安全服务器和客户端证书** - 本模块将讲解公钥基础设施(PKI)、CA的运作以及证书签署和验证流程。我们将利用Linux系统中的命令工具作为组织的CA,学习如何为客户端或服务器(包括安全电子邮件或安全网页访问)签署证书请求。学员还将学习如何生成服务器证书请求、将其发送给CA进行签署,并在Apache网站上安装签署的证书以实现安全网页访问。同时,将指导学员在浏览器和邮件客户端上设置客户端证书,以实现相互认证及签名和加密电子邮件。

课程大纲

Name:Cybersecurity Concepts and Security Principles

Description:In this module, we will introduce the basic cyber security concepts, enable you to identity root causes of vulnerabilities in a network system and distinguish them from the threats from both inside and outside. We will analyze the enabling factors of recent cyber attack incidences and discuss the basic security services for their defense and triage. We will introduce the risk management framework for analyzing the risks in a network system, and apply the basic security design principles to protect the data and secure the computer systems. Trust is critical and in the center of any secure systems. We will examine the source and authenticity of the programs and data installed in systems we used daily and show the proper way to check their integrity, and verify their authenticity.

Name:Protect Data Access and Verify Source of Trust

Description:In this module we apply principle of least privileges for controlling the proper access given to users and system process. We will demonstrate such an access control by using an example of project document access control using the Unix file access mechanism. We use OPM data breach example to show the impact and the need for principle of adequate data protection. Trust is critical and in the center of any secure systems. We will examine the source and authenticity of the programs and data installed in systems we used daily and show the proper way to check their integrity, and verify their authenticity.

Name:Using GPG to Sign/Verify Software

Description:In this module, we introduce GPG software tool for generating public key private key pair for signing/verifying the documents and to encrypt documents, and publish our public key on our web server and PGP key server for others to retrieve. We will use GnuPG software tool to verify the common opensource software packages such as apache and putty. We will also learn how to sign software and the proper way to list the software package, their pgp signature, and our signing public key on a web site.

Name:Be a CA, Setup Secure Server and Client Certificate

Description:In this module, we will learn the Public Key Infrastructure (PKI), how CA operates, and the certificates signing and verification process. We will utilize the utility command in a Linux system to serve as a CA for an organization, learn how to sign certificate request for clients or servers both secure email or secure web access purpose. We will earn how to generate server certificate requests as a webmaster, send them to CA for signing and install the signed certificates in Apache web server for secure web access. We will also set up apache web server for requiring clients to present their client certificates for mutual authentication. We will also guide you to set client certificate on browser for mutual authentication and on a mail client for signing and encrypting emails.

课程评论(0条)

课程详情

In this MOOC, we will learn the basic cyber security concepts, how to identify vulnerabilities/threat in a network system. We will apply CIA basic security services in the triage of recent cyberattack incidents, such as OPM data breach. We will learn the risk management framework for analyzing the risks in a network system, and apply the basic security design principles to protect the data and secure computer systems. We will examine the trustworthiness of programs and data installed in our systems and show the proper way to verify their integrity and authenticity. We will apply principle of least privileges for controlling the shared access given to different groups of users and system processes. On Amazon Cloud instances, we will use GnuPG software to generate public/private key pair for signing/verifying documents and open source software, and for encrypting documents. We will learn how to publish software, the related signature and release key on web server and publish public key to PGP key server for others to retrieve. We will learn Public Key Infrastructure (PKI) and Linux utility to serve as a CA for an organization, learn how to sign certificate request for clients or servers in secure email and web applications.

课程标签

0人关注该课程

主题相关的课程