Course description. This course surveys research on surveillance technologies and technical countermeasures. Readings come mostly from the computer science research literature, with some legal and policy readings to establish context. Course work will include reading and discussion, a few short writing assignments, and a substantial student-chosen course project. The course is designed for students with a solid grounding in computer science. Students unsure of their suitability of the course should contact the instructor.
Instructor. Edward W. Felten
PUBLIC VERSION: Members of the public who want to participate are invited to join the public online quasi-course.
Meetings. Class meets on Mondays and Wednesdays, 3:00-4:20 pm, in Sherrerd 306.
Online forum. For general questions and discussion please use the course's Piazza group.
Grading. Class participation and writing (50%), course project (50%).
Schedule. The schedule and readings are subject to change.
Understanding the Form, Function, and Logic of Clandestine Insurgent and Terrorist Networks. Derek Jones. Joint Special Operations University Report 12-3, U.S. Special Operations Command, 2012. Chapter 3.
9/11 Commission Report. National Commission on Terrorist Attacks upon the United States. Chapters 3, 11.3, 11.4, 13.
The System of Foreign Intelligence Surveillance Law. Peter P. Swire. George Washington Law Review vol. 72, 2004.
Secrecy, Flagging, and Paranoia: Adoption Criteria in Encrypted Email. Shirley Gaw, Edward W. Felten, and Patricia Fernandez-Kelly. ACM Conference on Computer-Human Interaction, 2006.
The Design, Implementation and Operation of an Email Pseudonym Server. David Mazieres and M. Frans Kaashoek. ACM Conference on Computer and Communications Security, 1998.
Users Get Routed: Traffic Correlation on Tor by Realistic Adversaries. Aaron Johnson, Chris Wacek, Rob Jansen, Micah Sherr, and Paul Syverson. ACM Conference on Computer and Communications Security, 2013.
The Parrot Is Dead: Observing Unobservable Network Communications. Amir Houmansadr, Chad Brubaker, and Vitaly Shmatikov. IEEE Symposium on Security and Privacy, 2013.
Information Hiding: A Survey. Fabien A.P. Petitcolas, Ross J. Anderson, and Markus J. Kuhn. Proceedings of the IEEE 87(7):1062-78.
The Most Dangerous Code in the World: Validating SSL Certificates in Non-Browser Software. Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh, and Vitaly Shmatikov. Conference on Computer and Communications Security, 2012.
Touching from a Distance: Website Fingerprinting Attacks and Defenses. Xiang Cai, Xin Cheng Zhang, Brijesh Joshi, and Rob Johnson. ACM Conference on Computer and Communications Security, 2012.
APT1: Exposing One of China's Cyber Espionage Units. Mandiant technical report. 2013.
On the Importance of Eliminating Errors in Cryptographic Computations. Dan Boneh, Richard A. DeMillo, and Richard J. Lipton. J. Cryptology 14(2), 2001.
Factoring RSA keys from certified smart cards: Coppersmith in the wild. Daniel J. Bernstein, Yun-An Chang, Chen-Mou Cheng, Li-Ping Chou, Nadia Heninger, Tanja Lange, and Nicko van Someren. To appear, ASIACRYPT 2013.
Cookieless Monster: Exploring the Ecosystem of Web-based Device Fingerprinting. Nick Nikiforakis, Alexandros Kapravelos, Wouter Joosen, Christopher Kruegel, Frank Piessens, Giovanni Vigna. IEEE Symposium on Security and Privacy, 2013.