Subject » BMEVITMAV52
Information and Network Security
Information and Network Security
A tantárgyleírás hatályossága
Hatályosság kezdete:
2026. March 21.
Hatályosság vége:
—
| Subject name (Hungarian, English) |
Information and Network Security
Information and Network Security
|
||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Subject code | BMEVITMAV52 | ||||||||||||
| Subject type | — | ||||||||||||
| Training Level | — | ||||||||||||
| Course types and hours (weekly/semester) |
|
||||||||||||
| Assessment type | félévközi érdemjegy | ||||||||||||
| Credits | 4 | ||||||||||||
| Subject coordinator |
DR. Fehér Gábor
position: egyetemi docens
contact:
feher.gabor@vik.bme.hu
|
||||||||||||
| Responsible department |
Távközlési és Mesterséges Intelligencia Tanszék
|
||||||||||||
| Faculty | Villamosmérnöki és Informatikai Kar | ||||||||||||
| Subject website | http://www.tmit.bme.hu/vitmav52 | ||||||||||||
| Primary curriculum type | — | ||||||||||||
| Direct prerequisites – Strong prerequisite | none | ||||||||||||
| Direct prerequisites – Weak prerequisite | none | ||||||||||||
| Direct prerequisites – Parallel prerequisite | none | ||||||||||||
| Direct prerequisites – Milestone prerequisite | none | ||||||||||||
| Direct prerequisites – Exclusion | none |
Objectives
Programme
Introduction
• Objectives of the information and network security. Threats and attacks. History of cryptography and cryptanalysis. Monoalphabetic and polyalphabetic ciphers. Statistical tests in cryptanalysis: Index of coincidence method. Practice and examples.
Cryptography
• Symmetric key encryption. Well known block ciphers: Data Encryption Standard (DES), 3DES, Advanced Encryption Standard (AES). Product cipher, Feistel cipher architecture, Substitution-permutation network. Meet in the middle attack. Block chaining. Modes of operation.
• Stream ciphers. One Time Pad, the perfect cipher. Binary additive stream ciphers. Synchronous stream ciphers, asynchronous stream ciphers. Converting ciphers. Hardware realized ciphers. Linear Feedback Shift Register based ciphers. Software stream ciphers: RC4. Comparison of symmetric key ciphers.
• Asymmetric key encryption, public key encryption. RSA algorithm and key generation. Enhancement on the RSA algorithm. Blinding. Digital Signature Algorithm (DSA). Signing and verification, Digital signature.
• Hash functions. Cryptographic hashing. Size of the hash output. Iterative hash functions. Block cipher based hash functions. Well known hash functions: Message Digest 5 (MD5), Secure Hash Algorithm (SHA1). Keyed hash functions, HMAC.
Keymanagement
• Keymanagement protocols. Basics: key agreement, -transport, -authentication, confirmation. Keymanagement protocol characteristics. Perfect Forward Secrecy. Key transport protocols: Point-to-point key update, Authenticated Key Exchange Protocol 2, Shamir’s no key protocol, Wide Mouth Frog, Needham-Schroeder, Otway-Rees protocols. Using public key cryptography in key management. Diffie-Hellman key exchange (DH), multi user DH. Station-to-station protocol. Secret sharing.
Secure network communication
• Attacks on network security. Layer 2 and Layer 3 network security. Attacks on routing. TCP session hijacking. Secure communication protocols: IPSec (AH, ESP), Transport Layer Security: TLS/SSL. Virtual Private Networks (VPN)
Firewalls, Intrusion Detection Systems
• Network Address Translation (NAT). Firewall functions. Packet filters and Proxy firewalls. Examples for packet filter firewall configurations. Dynamic packet filtering. Firewall architectures. Demilitarized Zone (DMZ). Firewall’s future. Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). Rule based and anomaly based detection. Network IDS and Host IDS. Honeypots.
• Vulnerability analysis
Security of Wireless Networks
• WiFi networks. WiFi protection: Wired Equivalent Privacy (WEP), WiFi Protected Access (WPA) and IEEE 802.11i protocols. WPA Temporal Key Integrity Protocol (TKIP) and Counter Mode CBC-MAC Protocol. IEEE 802.1X. Extensible Authentication Protocol (EAP).
The objective of the course is to provide theoretical and practical knowledge from today's information and network security topics. The course introduces the theory and practice of those equipment, methods and algorithms that support secure information sharing over computer networks.
Learning outcomes
Ez a tantárgy a KKK rendeletben meghatározott, következő kompetenciák fejlesztését szolgálja:
Knowledge
No learning outcomes recorded.
Skills
No learning outcomes recorded.
Attitudes
No learning outcomes recorded.
Autonomy and responsibility
No learning outcomes recorded.
Oktatási módszertan
4 lectures and practice per week. Practice during the theoretical class.
Tanulástámogató anyagok
Online források
• Alfred J. Menezes, Paul C. van Oorschot and Scott A. Vanstone, “Handbook of Applied Cryptography”, CRC Press, ISBN: 0-8493-8523-7; • Bruce Schneier, Applied Cryptography, Second Edition: Protocols, Algorthms, and Source Code in C, John Wiley & Sons, Inc., ISBN: 0471128457
Recommended preliminary knowledge for completing the subject
Knowledge type competencies
(azon előzetes ismeretek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
none
Skill type competencies
(azon előzetes képességek és készségek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
nincs
Recommended (non-compulsory) preliminary competencies
(azon ajánlott (nem kötelező) előzetesen megszerzendő kompetenciák összessége, amelyek jelentősen hozzájárulnak a tantárgy eredményes teljesítéséhez)
none
General rules
Requirements:
• In the class period there are two in-class tests (ZH) around the 7th and 13th weeks.
• Both in-class tests should be scored above 40%. The final grade score is based on the average of the two test scores.
Additional possibilities:
In the delayed completion period there is a possibility to rewrite the in-class tests (ZH) once.
Assessment methods
In-term assessments
No detailed assessments provided.
Weight of in-term assessments
No weights provided.
Exam-period assessments
No detailed assessments provided.
Weight of exam elements
No weights provided.
Grade calculation
No grade thresholds provided.
Attendance requirements
No attendance requirements provided.
Rules for retake and resubmission
Not provided.
Short description
Not provided.
Detailed description
Not provided.
Recommended courses
none
Workload to complete the subject
No workload breakdown provided.
Validity of subject requirements
Requirements valid from:
—
Requirements valid until:
—
Curriculum placement
No curriculum placements recorded for this subject version.