This course provides a systems-oriented introduction to computer security, focusing on the mechanisms used to protect modern operating systems, applications, and computing platforms. The course examines how security policies are translated into concrete system mechanisms, how these mechanisms are implemented in modern systems, and how failures in software and hardware abstractions can undermine their security guarantees.
The course begins with memory safety, exploitation, and modern exploit mitigations before moving into kernel security and classical protection mechanisms such as access control, mandatory access control, and SELinux. We then study virtualization and confidential computing, followed by the Linux isolation primitives underlying modern containers and sandboxes, including namespaces, cgroups, capabilities, seccomp, and filesystem isolation. Students will use these mechanisms to understand how systems such as Docker and Bubblewrap actually construct security boundaries.
The course also covers compartmentalization, accelerator and heterogeneous-system security, confidential accelerators and machine-learning workloads, and emerging security challenges involving agentic systems. Throughout the course, the emphasis is on understanding the underlying mechanisms rather than treating modern security systems as black boxes.
The following schedule is tentative and subject to change throughout the semester. Topics, ordering, quiz dates, and the amount of time devoted to individual modules may be adjusted based on class progress, student background, and emerging systems-security developments.
All code used in class will be made available on GitHub when possible.
Short quizzes will be given after major course modules. These quizzes are intended to assess understanding of systems-security concepts, mechanisms, attacks, and design tradeoffs.
Module Quiz
Module Quiz
setuid and setgidResearch-based semester project proposals are due Thursday, September 24.
Students who wish to pursue their own research project must submit a proposal by this date. Students without an approved research proposal will complete the instructor-defined semester project.
Module Quiz
Module Quiz
This module examines the mechanisms from which modern Linux containers and application sandboxes are constructed.
chrootpivot_rootseccompno_new_privsunsharensenterStudents should leave this module understanding the individual mechanisms behind a container rather than viewing containers as a primitive provided by the operating system.
runcbwrap)systemd-nspawnModule Quiz
pledge and unveilModule Quiz
Modern applications, particularly machine-learning systems, increasingly depend on GPUs and other accelerators. This module examines how these devices interact with operating-system security mechanisms.
Module Quiz
There are no classes during Penn State’s Thanksgiving holiday.
The final two instructional weeks are reserved entirely for semester projects.
Students will present their systems, demonstrate their technical artifacts, explain their design decisions, discuss their security model and evaluation, and answer technical questions about their work.
Semester project presentations and demonstrations continue.
The semester project is the central component of the course and accounts for 70% of the final grade.
Students have two options for completing the semester project.
Students interested in conducting systems-security research may propose their own research project.
You will have approximately one month from the beginning of the semester to develop and submit a project proposal. Research-based project proposals are due Thursday, September 24.
During this period, you should investigate the problem, understand existing work, and determine whether the proposed idea represents a meaningful technical contribution.
The proposal should clearly describe:
Students choosing the research-project track are expected to conduct enough background investigation to establish the novelty of their idea. Discovering late in the semester that the proposed idea has already been extensively explored will negatively affect the project evaluation.
Research projects must include a substantive technical artifact. A Work-In-Progress result is acceptable when appropriately justified, but an idea or literature survey without a corresponding implementation and evaluation is not sufficient.
Research projects will be evaluated based on technical difficulty, novelty, quality of the artifact, quality of the evaluation, and demonstrated understanding of the security problem.
Students who do not wish to conduct a research-based project may complete the semester project provided by the instructor.
Students who do not submit an approved research proposal by September 24 will follow this project track.
The instructor-defined project will involve designing, implementing, analyzing, attacking, or defending a real system using techniques covered throughout the course. Detailed specifications, milestones, and evaluation criteria will be provided during the semester.
The instructor-defined project is not a lesser project option. Both project tracks are expected to require substantial systems-security engineering, experimentation, and technical understanding.
There are no traditional midterm or final exams for this course.
Your final grade will be determined as follows:
Quizzes will be given after major course modules and will focus on understanding the concepts, mechanisms, attacks, and design tradeoffs discussed in class.
There will be no required paper presentations or paper-reading component this semester. Relevant research papers and systems may still be discussed during lectures when they are useful for explaining important concepts or the development of modern systems-security mechanisms.
Students are permitted to use Generative AI (GenAI) tools as part of their coursework. However, if a student chooses to do so, it is their responsibility to verify the accuracy of any information, code, analysis, or claims produced by the AI. Any errors, hallucinations, insecure code, incorrect analyses, or misleading outputs generated by such tools remain the responsibility of the student.
Students must be able to explain and defend any work they submit, including code, vulnerability analyses, system designs, experimental results, and technical decisions. The instructor may ask students to explain any portion of submitted work in order to verify their understanding.
Students should not treat GenAI systems as an “answering oracle.” These tools should instead be used as assistants for learning, research, debugging, analysis, and engineering. They are not a substitute for understanding the underlying systems-security concepts.
For assignments where requested by the instructor, students may also be required to submit relevant GenAI interaction logs or otherwise document how GenAI tools were used.
Penn State welcomes students with disabilities into the University’s educational programs. Every Penn State campus has an office for students with disabilities. The Student Disability Resources website provides contact information for every Penn State campus. For further information, please visit the Student Disability Resources website.
In order to receive consideration for reasonable accommodations, you must contact the appropriate disability services office at the campus where you are officially enrolled, participate in an intake interview, and provide documentation. If the documentation supports your request for reasonable accommodations, your campus’s disability services office will provide you with an accommodation letter. Please share this letter with your instructors and discuss the accommodations with them as early in your courses as possible. You must follow this process for every semester that you request accommodations.
Many students at Penn State face personal challenges or have psychological needs that may interfere with their academic progress, social development, or emotional well-being. The university offers a variety of confidential services to help you through difficult times, including individual and group counseling, crisis intervention, consultations, online chats, and mental health screenings. These services are provided by staff who welcome all students and embrace a philosophy respectful of clients’ cultural and religious backgrounds, and sensitive to differences in race, ability, gender identity, and sexual orientation.
Penn State takes great pride in fostering a diverse and inclusive environment for students, faculty, and staff. Acts of intolerance, discrimination, or harassment due to age, ancestry, color, disability, gender, gender identity, national origin, race, religious belief, sexual orientation, or veteran status are not tolerated and can be reported through Educational Equity via the Report Bias webpage.