Towson University
AIT 600.103
Information Technology Infrastructure

Spring 2006

Professor Randall K Nichols

Office: 
Carlisle, PA
Availability: 
10:00AM - 3:00AM EST (email or phone)
Office Phone: 
717-258-5693
Mobile Phone: 
717-329-9836
E-Mail: 
profrknichols@comcast.net
Course Website: 
www.infosec-technologies.com
Classroom: 
See CSC security check-in desk for room assignment
Class Times: 
1730 – 2045, Mondays (CSC)
Class Dates: 
1/30/2006 to 4/24/2006; Final Team Project due 5/1/2006
Prerequisites: 
CAIT Core Course

Textbooks

1) Chris Britton and Peter Bye, IT Architecture and Middleware: Strategies for Building Large Integrated Systems, 2nd Ed, New york: Addison Wesley, 2004, ISBN: 0-321-24694-2 [IT]

2) Paul Campbell, Ben Calvert, Steven Boswell, Cisco Learning Institute, Security+ Guide to Network Security Fundamentals, Course Technology Incorporated, 2003, ISBN 0-619-12017-7 [with CDROM] [NS]

3) Bruce Schneier, Beyond Fear: Thinking Sensibly About Security in an Uncertain World, Copernicus, 2003. ISBN: 0-387-02620-7. [BF]

Learning Objectives

There are three main learning objectives for this course – computer systems architecture and security. We will demonstrate that both objectives need to be integrated for effective enterprise systems design.

  1. We will survey and explore enterprise information systems architectures including software systems, hardware, operating systems, databases, component technologies, networking, and architecture patterns. We will introduce systems architecture into the Systems Development Lifecycle Process: analysis, design, development, implementation and post implementation-phases.
  2. Security of IT systems is too important to be separated from IT architecture and systems analysis. We will seek a fundamental understanding of network security principles and implementation. We will study technologies and principles involved in creating a secure computer networking environment. Topics include: authentication, types of attacks and malicious code that may be used against your network, threats and countermeasures for e-mail, Web applications, remote access, and file and print services.
  3. Security topologies, technologies and concepts used to provide secure communications channels, secure internetworking devices, and network mediums will be integrated into the system architecture discussion.

Course Skills / Outcomes

Upon completion of this course, students should be able to:

  • Describe and understand the significance of different levels ( viewpoints) of enterprise system architectures
  • Understand the dynamic nature of middleware and the difficulties associated with its design
  • Explain the architecture components (software, hardware and networks) that comprise an enterprise system
  • Identify the security trade-offs involved in the design, development, and maintenance of enterprise systems
  • Understand the interrelationships between enterprise architecture, security requirements and the SDLC process

Web Site

A wealth of supplementary information for our course is available at www.infosec-technologies.com. Material downloaded must be appropriately attributed to contributors in all team / individual papers.

E-Mail

All students are requested to obtain an e-mail account that can receive a lot of weekly E-Mail, PPTs, notes, etc). G-Mail, Comcast, seem to do the job. Towson, Hotmail addresses do not. If you have any questions about the course or need assistance, please contact me in person or by telephone during office hours or by e-mail at any time. About mid-semester, I will send out a confidential “1 to 1” email to check on the progress of each student. Response is optional.

COURSE DELIVERABLES

The course deliverables are as follows:

Exams. There will be no formal midterm or final exam.

In-Class / Take- Home Assignments. There are three In-Class Team / Individual assignments scheduled.

Asymmetric Project Presentation. A team produced Asymmetric Project PowerPoint presentation will be due at mid-term. Consider it a warm-up for the collaborative team paper/presentation without the required paper due at the same time.

Collaborative Team Research Paper / PowerPoint Presentation. A semester-long team research paper and PowerPoint presentation is required. Be advised, this is not a project to wait for the last moment to prepare. It is very competitive and teams should organize on first class meeting, pick a team leader and assess strengths and weaknesses of its membership. Everyone on the team receives the same grade (subject to the P-2-P process, if invoked). Sink or swim.

Participation. Students are expected to prepare for each class meeting and participate in the homework discussion conferences. Questions based on the weekly lecturette and assigned text readings require students to contribute regularly. A rubric for participation is available as a benchmark.

Bullets. Students will prepare short Bullets on current items pertaining to this course (URLS, 30 - 60 second summaries of current security events, interesting IT/ INFOSEC finds, etc. or webliography items REGULARLY. Virus bullets (and AV product news) do not count. Duplicate bullets do not count. Bullet participation is generally a grade differentiator on participation.

There are quality bullets and there are not so quality ones. There are A-bullets which go right to the gradebook in your favor. There are 2 conditions I look for in addition to the quality of Bullets: 1) currency [bullets should be not more than 7-days old or if older, need to be updated with a current reference on the same subject]and 2) bullets about viruses or malicious software in any form, including spyware, bots, web bugs, Trojans, worms, computer programs to stop them, script kiddies, AV company information, new marketing program signatures or even legal stuff about them are boring information and should be avoided, like poison. There are literally hundreds of security events happening around the world; INFOSEC newsletters, newspapers, formal /informal initiatives, CT resources that provide raw high-grade material for bullets. Information about new approaches to IT architecture Open or supported software, NIST standards or best practices are all fuel for good quality bullets.

The instructor reserves the right to make changes to this syllabus at any time.

GRADING:

The final grade will be determined as follows:

Asymmetric Team Project Presentation-- 25%
Team Research Paper and PowerPoint Presentation-- 45%
Weekly Discussion Participation / In-Class Team / Individual Assignments-- 15%
Bullets -- regular submissions of "Bullets" or webliography are required -- 15%

Teams may elect to use a peer-to-peer evaluation process in which team members evaluate (or mirror) the performance and participation of their teammates but not their own. Multiple negative “P-2-P’s” may negatively affect an individual’s grade by up to 20%. P-2-P's are held confidential and recorded. A special XLS formatted sheet will be given to team leaders.

GRADUATE SCHOOL GRADING GUIDELINES:

According to Graduate School grading policy, the following symbols are used: A = excellent; B = good; C = passing; and F = failure.

The grade of B represents the benchmark for the Graduate School. It indicates that the student has demonstrated competency in the subject matter of the course, e.g., has fulfilled all course requirements on time, has a clear grasp of the full range of course materials and concepts, and is able to present and apply these materials and concepts in clear, well-reasoned, well-organized, and grammatically correct responses, whether written or oral.

Only students who fully meet this standard and, in addition, demonstrate exceptional comprehension and application of the course subject matter earn a grade of A.

Students who do not meet the benchmark standard of competency fall within the C range or lower. They, in effect, have not met graduate level standards. Where this failure is substantial, they can earn an F.

WRITING STANDARDS:

Effective managers, leaders, and teachers are also effective communicators. Written communication is an important element of the total communication process. The Graduate School recognizes and expects exemplary writing to be the norm for course work. To this end, all papers, individual and group, must demonstrate graduate level writing and comply with the format requirements of the Publication Manual of the American Psychological Association, (5th Edition). Careful attention should be given to spelling, punctuation, source citations, references, and the presentation of tables and figures. It is expected that all course work will be presented on time and error free. Work submitted online should follow standard procedures for formatting and citations.

Timeliness It is expected that all course work will be presented on time and error free. Work submitted online should follow standard procedures for formatting and citations

POLICY ON ACADEMIC INTEGRITY AND PLAGIARISM:

Academic integrity is central to the learning and teaching process. Students are expected to conduct themselves in a manner that will contribute to the maintenance of academic integrity by making all reasonable efforts to prevent the occurrence of academic dishonesty. Academic dishonesty includes, but is not limited to, obtaining or giving aid on an examination, having unauthorized prior knowledge of an examination, doing work for another student, and plagiarism of all types.

Plagiarism is the intentional or unintentional presentation of another person’s idea or product as ones own. Plagiarism includes, but is not limited to, the following: copying verbatim all or part of another’s written work; using phrases, charts, figures, illustrations, or mathematical or scientific solutions without citing the source; paraphrasing ideas, conclusions, or research without citing the source; and using all or part of a literary plot, poem, film, musical score, or other artistic product without attributing the work to its creator. Students can avoid unintentional plagiarism by following carefully accepted scholarly practices. Notes taken for papers and research projects should accurately record sources to material to be cited, quoted, paraphrased, or summarized, and papers should acknowledge these sources. The penalties for plagiarism include a zero or a grade of F on the work in question, a grade of F in the course, suspension with a file letter, suspension with a transcript notation, or expulsion. Students may learn more about Towson University’s formal policies at: https://inside.towson.edu/generalcampus/tupolicies/index.cfm.

DISABILITIES

Any student who needs an accommodation due to a disability should make an appointment to discuss the accommodation. A memo from Disability Support Services authorizing the accommodation is required.

COURSE EVALUATIONS:

Feedback on each graduate course and instructor is important to the university, your professor, and to all students. Towson has the responsibility to assess the effectiveness of classroom instruction, and each student has the responsibility to provide accurate and timely feedback through completion of the course evaluation form. This is a shared obligation for us all. It is therefore important that you complete the evaluation form for each course. This should be viewed as an additional course and program requirement.

Course Schedule

Week
Topics
Chapter Readings
(week after class)
Hands-On
Projects / Class
Exercises
Due Date
Week 1

Syllabus
Administrative
Class Expectations

TEAMS FORMATION
& Topic Selections
-------------------
Middleware Summary
Overview

Security Overview
Authentication

IT Ch5: Middleware

IT Ch 1: Architecture problem

NS Ch 1: Security Overview

NS Ch 2: Authentication

In class exercise
Authentication

Bullets


Week 2

Objects
Components

Attacks and Malicious Code
Security Tradeoffs

IT Ch 1 & 2: Emergence and Objects

NS Ch. 3: Attacks and Malicious Code

BF Ch. 1,2&3: Security Tradeoffs

In class exercise- Asymmetric Thinking

Bullets


Week 3

Web Services
Remote Access
Failure of systems

IT Ch 4: Web Services

NS Ch 4: Remote Access

BF Ch. 4: Systems failure

Ryan 30 Elements
For SE

Bullets

Week 4

Distributed Apps
E-Mail


IT Ch. 6: Distributed Apps

NS Ch. 5: E-Mail

½ TEAM Day

Bullets

Week 5

Web security
Security attacks



NS Ch. 6: Web Security

BF Ch. 5 & 6: Attackers


Bullets  
Week 6

IT Ch. 7: Resiliency

NS Ch. 7: Directory and File Transfer Services

BF Ch. 7: Attackers & Technology

Bullets Field trip to Gettysburg

Week 7

Resiliency
Directory
File Transfer

Brittleness

NS Ch. 8 : Wireless and Instant Messaging

BF Ch. 8 & 9: Weak link & Brittleness

In class Exercise
Security Technologies & Matrix

Bullets

Asymmetric Project Team Presentations

Gettysburg Battle. Designing a real-time battlefield intelligence computer architecture
Week 8

Performance
Scalability

Wireless and Instant Messaging

IT Ch. 8 Performance and Scalability

BF Ch. 10: People

Bullets  
Week 9

Application Design
Business Processes
Network Security Topologies

IT Ch. 11 & 12: Application Design & Processes

NS Ch. 11: Network Security Topologies

Bullets  
Week 10

Systems Management
Detection

IT Ch. 9 Systems Management

BF Ch. 11& 12 Detection

In Class: Asymmetric exercise

Bullets

 
Week 11

Identification Authentication authorization

IT Ch. 10: Security

BF Ch 13: IAA

Bullets


Week 12

Integration
Accuracy
Building IT Architectures

Cryptography
Countermeasures

IT Ch 13,14, 16: Integration
Accuracy Architecture

NS Ch. 14 : Cryptography

BF Ch. 14: Countermeasures

Bullets


 
Week 13 Counter Terrorism BF Ch.15: Terrorism Bullets  
Week 14 Wrap-Up
TEAM DAY Bullets  
Week 15 FINAL TEAM Paper
FINAL TEAM Presentations

Good Luck!
    Team A/D Counter -Terrorism Scenarios

Computers at there best! Putting it all together.

References

Adelman, G.E. (2003) The Myth of Little Round Top, Gettysburg PA. Gettysburg, PA: Thomas.

Afyouni, H.A. (2006) Database Security and Auditing: Protecting Data Integrity and Accessibility. Boston: Thomson Course Technology.

Britton, C. & Bye, P. (2004) IT Architecture and Middleware: Strategies for Building Large Integrated Systems, 2nd Ed. New York: Addison Wesley.

Campbell, P., Calvert, B., & Boswell, S. (2003) Cisco Learning Institute, Security+ Guide to Network Security Fundamentals. Boston: Thomson Course Technology.

Canavan, J. E. (2001) Fundamentals of Network Security. Boston: Artech House.

Ciampa, M. (2004) Security Awareness: Applying Practical Security in your World. Boston: Thomson Course Technology.

Harman, T.D. (2003) Lee’s Real Plan at Gettysburg. Mechanicsburg, PA: Stackpole Books.

Holden, G. (2004) Guide to Firewalls and Network Security. Boston: Thomson Course Technology.

Holden, G. (2003) Guide to Network Defense and Countermeasures. Boston: Thomson Course Technology.

Erbschloe, M. (2003) Disaster Recovery. Boston: Thomson Course Technology.

Northcutt, S., Zeltser, L, Winters, S., Frederick, K.K., & Ritchey, R.W. (2003) Network Perimeter Security. Boston: New Riders. [See chapters 14-16]

Palmer, M. (2004) Guide to Operating Systems. Boston: Thomson Course Technology.

Schneier, B. (2003) Beyond Fear: Thinking Sensibly About Security in an Uncertain World, New York: Copernicus.

Whitman, M.E. & Mattord, H.J. (2004) Management of Information Security. Boston: Thomson Course Technology.