K-INFO
HU
EN
Login

Information and Network Security

Information and Network Security
A tantárgyleírás hatályossága
Hatályosság kezdete:
2026. March 21.
Hatályosság vége:
Subject name (Hungarian, English)
Information and Network Security
Information and Network Security
Subject code BMEVITMAV52
Subject type
Training Level
Course types and hours (weekly/semester)
Course type lecture tutorial laboratory
hours (weekly) 4 0 0
type (linked/independent)
Assessment type félévközi érdemjegy
Credits 4
Subject coordinator
DR. Fehér Gábor
position: egyetemi docens
Responsible department
Távközlési és Mesterséges Intelligencia Tanszék
Faculty Villamosmérnöki és Informatikai Kar
Subject website http://www.tmit.bme.hu/vitmav52
Primary curriculum type
Direct prerequisites – Strong prerequisite none
Direct prerequisites – Weak prerequisite none
Direct prerequisites – Parallel prerequisite none
Direct prerequisites – Milestone prerequisite none
Direct prerequisites – Exclusion none

Objectives

Programme
Introduction
Objectives of the information and network security. Threats and attacks. History of cryptography and cryptanalysis. Monoalphabetic and polyalphabetic ciphers. Statistical tests in cryptanalysis: Index of coincidence method. Practice and examples.
Cryptography
Symmetric key encryption. Well known block ciphers: Data Encryption Standard (DES), 3DES, Advanced Encryption Standard (AES). Product cipher, Feistel cipher architecture, Substitution-permutation network. Meet in the middle attack. Block chaining. Modes of operation.
Stream ciphers. One Time Pad, the perfect cipher. Binary additive stream ciphers. Synchronous stream ciphers, asynchronous stream ciphers. Converting ciphers. Hardware realized ciphers. Linear Feedback Shift Register based ciphers. Software stream ciphers: RC4. Comparison of symmetric key ciphers.
Asymmetric key encryption, public key encryption. RSA algorithm and key generation. Enhancement on the RSA algorithm. Blinding. Digital Signature Algorithm (DSA). Signing and verification, Digital signature.
Hash functions. Cryptographic hashing. Size of the hash output. Iterative hash functions. Block cipher based hash functions. Well known hash functions: Message Digest 5 (MD5), Secure Hash Algorithm (SHA1). Keyed hash functions, HMAC.
Keymanagement
Keymanagement protocols. Basics: key agreement, -transport, -authentication, confirmation. Keymanagement protocol characteristics. Perfect Forward Secrecy. Key transport protocols: Point-to-point key update, Authenticated Key Exchange Protocol 2,  Shamir’s no key protocol, Wide Mouth Frog, Needham-Schroeder, Otway-Rees protocols. Using public key cryptography in key management. Diffie-Hellman key exchange (DH), multi user DH. Station-to-station protocol. Secret sharing.
Secure network communication
Attacks on network security. Layer 2 and Layer 3 network security. Attacks on routing. TCP session hijacking. Secure communication protocols: IPSec (AH, ESP), Transport Layer Security: TLS/SSL. Virtual Private Networks (VPN)
Firewalls, Intrusion Detection Systems
Network Address Translation (NAT). Firewall functions. Packet filters and Proxy firewalls. Examples for packet filter firewall configurations. Dynamic packet filtering. Firewall architectures. Demilitarized Zone (DMZ). Firewall’s future. Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS). Rule based and anomaly based detection. Network IDS and Host IDS. Honeypots.
Vulnerability analysis
Security of Wireless Networks
WiFi networks. WiFi protection: Wired Equivalent Privacy (WEP), WiFi Protected Access (WPA) and IEEE 802.11i protocols. WPA Temporal Key Integrity Protocol (TKIP) and Counter Mode CBC-MAC Protocol. IEEE 802.1X. Extensible Authentication Protocol (EAP).


The objective of the course is to provide theoretical and practical knowledge from today's information and network security topics. The course introduces the theory and practice of those equipment, methods and algorithms that support secure information sharing over computer networks.

Learning outcomes

Ez a tantárgy a KKK rendeletben meghatározott, következő kompetenciák fejlesztését szolgálja:

Knowledge

No learning outcomes recorded.

Skills

No learning outcomes recorded.

Attitudes

No learning outcomes recorded.

Autonomy and responsibility

No learning outcomes recorded.

Oktatási módszertan

4 lectures and practice per week. Practice during the theoretical class.

Tanulástámogató anyagok

Online források
• Alfred J. Menezes, Paul C. van Oorschot and Scott A. Vanstone, “Handbook of Applied Cryptography”, CRC Press, ISBN: 0-8493-8523-7; • Bruce Schneier, Applied Cryptography, Second Edition: Protocols, Algorthms, and Source Code in C, John Wiley & Sons, Inc., ISBN: 0471128457

Recommended preliminary knowledge for completing the subject

Knowledge type competencies
(azon előzetes ismeretek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
none
Skill type competencies
(azon előzetes képességek és készségek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
nincs
Recommended (non-compulsory) preliminary competencies
(azon ajánlott (nem kötelező) előzetesen megszerzendő kompetenciák összessége, amelyek jelentősen hozzájárulnak a tantárgy eredményes teljesítéséhez)
none
General rules
Requirements: • In the class period there are two in-class tests (ZH) around the 7th and 13th weeks. • Both in-class tests should be scored above 40%. The final grade score is based on the average of the two test scores.  Additional possibilities: In the delayed completion period there is a possibility to rewrite the in-class tests (ZH) once.
Assessment methods
In-term assessments

No detailed assessments provided.

Weight of in-term assessments

No weights provided.

Exam-period assessments

No detailed assessments provided.

Weight of exam elements

No weights provided.

Grade calculation

No grade thresholds provided.

Attendance requirements

No attendance requirements provided.

Rules for retake and resubmission

Not provided.

Short description

Not provided.

Detailed description

Not provided.

Recommended courses
none
Workload to complete the subject

No workload breakdown provided.

Validity of subject requirements
Requirements valid from:
Requirements valid until:
Curriculum placement

No curriculum placements recorded for this subject version.