Skip to main content
Skip header

Advanced Computer Security

Language of instruction angličtina, čeština
Code 460-4165
Abbreviation PB
Course title Advanced Computer Security
Coordinating department Department of Computer Science
Course coordinator prof. Ing. Ivan Zelinka, Ph.D.

Summary

The course Computer Security provides students with a comprehensive understanding of information system and data protection in today’s digital society. It bridges theoretical foundations with practical skills in areas ranging from fundamental cybersecurity principles to malware analysis, penetration testing, incident response, and the application of international standards. Students will not only learn to identify and analyze threats but also to design appropriate countermeasures, preparing them for both professional careers and research activities in the field of cybersecurity.

Knowledge
• Understanding cybersecurity principles – students will grasp the fundamentals of information system and data protection, including the CIA triad (confidentiality, integrity, availability).
• Overview of cyber threats – students will become familiar with major attack vectors, including social engineering, supply chain attacks, DDoS, and malware.
• Knowledge of standards and frameworks – students will acquire knowledge of NIS2, ISO/IEC 27001, OWASP, and other international cybersecurity frameworks.
• Malware and advanced offensive techniques – students will understand the mechanisms of malware, including polymorphic and fileless attacks, and its role in modern cyber threats.
• Forensics and incident response methodologies – students will gain insights into risk analysis, incident management procedures, and digital forensic practices.

Skills
• Conducting penetration tests – students will learn to use essential tools (e.g., Nmap, Metasploit, Wireshark) for identifying and testing vulnerabilities.
• Analyzing attacks and malware – students will be able to perform basic static and dynamic malware analysis in safe environments (sandbox, virtual lab).
• Simulating and responding to incidents – students will practice incident response scenarios, including chain of custody preservation and log analysis.
• Evaluating security measures – students will learn to design and assess the effectiveness of security controls for various systems.
• Applying AI in cybersecurity – students will gain awareness of the use of artificial intelligence for both offensive purposes (deepfakes, autonomous malware) and defensive measures.

Competences
• Analytical thinking – ability to analyze threats, vulnerabilities, and attacks and devise effective countermeasures.
• Critical evaluation – ability to interpret results from penetration tests, forensic investigations, and incident analyses.
• Application of standards and frameworks – ability to implement international standards and methodologies in practice (NIS2, ISO/IEC 27001, OWASP).
• Team collaboration – students will learn to respond to incidents in group exercises, including role allocation and coordination.
• Preparedness for practice and research – the course equips students for professional roles in IT security as well as for further research in malware, AI, and cyber threat analysis.

Literature

Ross J. Anderson. Security Engineering: A Guide to Building Dependable Distributed Systems. 3rd Edition. Wiley, 2020. ISBN 978-1119642787 .
Dostupné z: https://www.wiley.com/en-us/Security+Engineering%3A+A+Guide+to+Building+Dependable+Distributed+Systems%2C+3rd+Edition-p-9781119642787

Bruce Schneier. Applied Cryptography: Protocols, Algorithms, and Source Code in C. 2nd Edition. Wiley, 2015. ISBN 978-1119183471 .
Dostupné z: https://onlinelibrary.wiley.com/doi/book/10.1002/9781119183471

Georgia Weidman. Penetration Testing: A Hands-On Introduction to Hacking. No Starch Press, 2014. ISBN 978-1593275648 .
Dostupné z: https://nostarch.com/pentesting

Michael Sikorski, Andrew Honig. Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software. No Starch Press, 2012. ISBN 978-1593272906 .
Dostupné z: https://nostarch.com/malware

Advised literature

Jean-Philippe Aumasson. Serious Cryptography: A Practical Introduction to Modern Encryption. No Starch Press, 2017. ISBN 978-1593278267 .
Dostupné z: https://nostarch.com/seriouscryptography

Royce Davis. The Art of Network Penetration Testing: Taking over any company in the world. Manning, 2021. ISBN 978-1617296826 .
Dostupné z: https://www.manning.com/books/the-art-of-network-penetration-testing

Jon Erickson. Hacking: The Art of Exploitation. 2nd Edition. No Starch Press, 2008. ISBN 978-1593271442 .
Dostupné z: https://en.wikipedia.org/wiki/Hacking%3A_The_Art_of_Exploitation

Eldad Eilam. Reversing: Secrets of Reverse Engineering. Wiley, 2005. ISBN 978-0764574818 .
Dostupné z: https://en.wikipedia.org/wiki/Reversing%3A_Secrets_of_Reverse_Engineering