Study Guide for Midterm
This is simply a guide of topics that I consider fair game for the midterm. I don't promise to ask you about them all, or about any of these in particular; but I may very well ask you about any of these.
-
Fundamentals
-
What is security?
-
Basics of risk analysis
-
Relationship of security policy to security
-
Policy vs. mechanism
-
Assurance and security
-
Bad Programming and Good Programming
-
Cryptography
-
Types of attacks: ciphertext only, known plaintext, chosen plaintext
-
Caesar cipher, Vigenère cipher, one-time pad, DES
-
Public key cryptosystems; RSA
-
Confidentiality and authentication with secret key and public key systems
-
Electronic mail
-
Ordinary mail: security issues
-
PEM: how it works, security issues
-
Certificates
-
PEM Hierarchy
-
Web of trust
-
Identity
-
People and processes
-
Computers
-
Cookies and such
-
Anonymity: remailers and proxy web browsers
-
Authentication
-
Passwords
-
Challenge-response
-
How UCD does authentication for MyUCDavis
-
Any of the handouts
Here is a PDF version of this document.