9.01 Readings and Lecture Notes
March 8-14 · No new reading
What to do this week is on the Module 9 Overview. Nothing is due.
Readings
Nothing new. If you want to re-read anything from CyBOK, the highest-value sections are §1.4 (the eight principles) and §14.3.1 (access control core concepts). Everything else is better reviewed through your own graded work.
How to spend the week
The single most valuable thing you can do is re-read your own labs and my comments on them. The second half of the course assumes you can do what Labs 1 through 5 and D3 asked for without looking it up.
In rough order of value:
- Redo a threat model from scratch, on something else: your bank's app, the campus print service, a smart speaker. Twenty minutes, timed. The only way to get fast at it is to have done it more than once.
- Redo an access control matrix for three subjects and three objects, then write the ACL and capability list versions. Ten minutes.
- Recite the eight principles until you can list them without looking, with one example of a violation of each.
- Re-run
crypto_demo.pyandsign_demo.pyand explain each section's output out loud to somebody, or to yourself. If you cannot explain the nonce-reuse algebra without looking, that is the thing to work on. - Skim, do not re-read, the CyBOK sections. Know where things are.
What not to do
Do not re-read all 88 pages of assigned CyBOK. Most of what you need is already in your own labs, and re-reading the book is the slowest way to get it back.
After this week
Spring break is March 15-19. Nothing is due and nothing opens. Week 10 materials become available on Monday, March 22.
The second half of the course changes character. The first half was mostly about how things are supposed to work, and the second half is mostly about how they fail (network attacks, malware, memory safety, injection). It ends with what you do once something has already gone wrong.