CS361, Web Security, Fall 2017

Lecturer: Nick Nikiforakis
Teaching Assistant: Harpreet Singh Chawla (office hours)
Time:MW 5:30 PM - 6:50 PM
Office Hours: Thursday 4:00 PM - 5:00 PM, Friday 4:00PM - 5:00 PM, and by appointment
Contact: nick[email squiggly thingy] cs.stonybrook.edu

  • Most of your requests (clarifications, questions about upcoming deadlines, projects, etc.) should be publicly asked on Piazza, so that other students can benefit from Q&As.
  • If you need to ask me something personal (that does not apply to the entire class), then you can send me an email. If you need to reach me through email, make sure your title starts with "[CSE 361]" (without the quotes). Mislabeled or unlabeled emails will, most likely, not be read.


Class Description

In this class, we will together explore the concepts behind web security. We will look at the core principles behind secure (and insecure) systems and how these principles apply to web applications. We will learn how the web works, how to find vulnerabilities, how attackers compromise web applications, and how to avoid these vulnerabilities when implementing and deploying your own web applications.

The course will consist of lectures, hands-on labs (likely done on the laptops of the students in class), a few select paper presentations by teams of students, and one (or two) small projects.

Some of the topics that we will cover are the following:


Following a long-standing tradition in security courses, there is no official textbook for this course. I am drawing inspiration mostly from the following books:

Requirements and Grading

Subject to minor tweaks throughout the semester.

Schedule and Reading Assignments

Date Topic Reading Assignment(s)
8/28/2017Introduction, Motivation and DefinitionsReflections on Trusting Trust
9/04/2017Labor Day, no class
9/06/2017Authentication (continued)
9/11/2017Authentication (continued)
9/13/2017How the web works (Part1)


