High-Level Modules

CE 40-817: Advanced Network Security · Fall 2025 · 12 modules · 25 sessions total

Each module is typically delivered across two sessions; the badge shows the actual count based on the schedule.

Module 1 —
Foundations, Ethics and Threat Landscape

Attacker models, Internet-scale risk, measurement ethics, course framing

Outcome: Shared vocabulary and scope for the rest of the course
Module 2 —
Visibility and Telemetry in an Encrypted Internet

Where signals live today (metadata, timing, endpoints) and limits under pervasive encryption

Outcome: Reason about blind spots and what each data source can and cannot tell you
Module 3 —
Secure Transport Protocols: TLS 1.3, QUIC and PKI

Handshake properties, forward secrecy, ECH, certificate ecosystem, operational pitfalls

Outcome: Evaluate transport posture and typical misconfigurations
Module 4 —
Identity, Access and Zero-Trust Networking

Network authentication and authorization, segmentation, device posture, VPN and zero-trust patterns

Outcome: Design policies that fail safely and scale
Module 5 —
Name Resolution Security and Privacy

DNS threat surface, DNSSEC basics, resolver models, DoH and DoT and SVCB and HTTPS trade-offs

Outcome: Balance authenticity and privacy in naming
Module 6 —
Routing and Interdomain Security

BGP fundamentals, hijacks and leaks, RPKI and ROV, operational best practices and failures

Outcome: Analyze routing incidents and propose mitigations
Module 7 —
Data Plane Policy and Middleboxes under Encryption

ACLs and segmentation, detection and response at L3 to L7, limits with QUIC, ECH, 0-RTT

Outcome: Know when policy works and when it does not without breaking privacy
Module 8 —
Availability and DDoS Resilience

Reflection and amplification, application layer attacks, anycast and CDN strategies, economics

Outcome: Architect layered defenses and understand collateral-damage trade-offs
Module 9 —
Wireless and Short-Range Security including Jamming

Wi-Fi and WPA3 pitfalls, BLE pairing and privacy, jamming models and mitigations

Outcome: Assess RF risks and practical countermeasures
Module 10 —
Privacy, Anonymity and Future Internet Directions

Traffic analysis and defenses, ethics of evaluation, path-aware networking and SCION ideas

Outcome: Balance privacy with defense needs and see where the Internet is headed
Module 11 —
IoT and Edge Systems Security

Identity and onboarding, constrained protocols MQTT and CoAP, segmentation and least privilege

Outcome: Map IoT risk to containment and governance patterns
Module 12 —
Cellular and Mobile Core Security (LTE and 5G)

Attach and auth flows, roaming and interconnect SS7 and Diameter, slicing and edge threats

Outcome: Reason about mobile-core trust boundaries and policy points