Overview

This course examines the principles and practices used to protect computer networks, services, and data from accidental and malicious threats. Topics include security goals and threat models; attack surfaces and trust boundaries; network architecture and segmentation; common vulnerabilities; reconnaissance and scanning; packet structure and traffic analysis; firewalls, proxies, intrusion detection and prevention systems; virtual private networks; secure wireless networking; authentication, authorization, and accounting; access-control models; cryptography for networked systems; certificates and public key infrastructure; TLS and secure application protocols; secure DNS; and email security.

Students also study network hardening, patch and configuration management, logging, monitoring, alerting, security information and event management, vulnerability assessment, incident response, backup and recovery, and risk management. Laboratory activities use isolated, authorized environments to examine defensive configuration, packet capture, attack detection, and response procedures, with explicit attention to legal and ethical boundaries. Students develop the ability to interpret network evidence, identify weaknesses, design layered defenses, configure secure services, evaluate controls against realistic threats, and communicate residual risk.

Learning Outcomes

  • Explain security goals, threat models, attack surfaces, trust boundaries, and common network vulnerabilities.
  • Analyze network architectures and recommend segmentation, access-control, and defense-in-depth strategies.
  • Interpret packet captures, protocol exchanges, logs, and other network evidence to identify suspicious activity.
  • Configure and evaluate firewalls, proxies, intrusion detection and prevention systems, VPNs, and secure wireless services in authorized environments.
  • Explain the protocol-level protection provided by symmetric and public-key cryptography, certificates, public key infrastructure, TLS, secure DNS, and email security mechanisms.
  • Develop a network security plan that addresses risk, operational constraints, usability, cost, monitoring, maintenance, and recovery.
  • Assess vulnerabilities and recommend practical mitigations through hardening, patch management, configuration control, and layered defenses.
  • Produce an incident report that documents evidence, impact, response actions, recovery requirements, and residual risk.
  • Evaluate legal, ethical, and professional boundaries governing network security assessment and defensive operations.

Timetable

TypeLengthFrequencyPeriod
Lecture2 hoursWeeklyAll semester
Lab2 hoursWeeklyAll semester
Tutorial1 hourFortnightlyAll semester

Assessment Schedule

TypeDescriptionWeighting
AssignmentSecurity architecture and risk assessment plan20.00%
TestPacket analysis and defensive configuration practical20.00%
AssignmentIncident report based on analyzed network evidence15.00%
AttendanceLaboratory participation and authorized security exercises (10 × 2%)20.00%
ExamFinal examination25.00%

Teaching Staff & Programs

This course is delivered jointly by faculty from the participating programs listed below. In line with the Douchewater Way, the University of Sexology tailors core instruction directly to each cohort's specific discipline — adapting curriculum to program needs rather than forcing students into a one-size-fits-all model. Learn more about our approach at The Douchewater Way.