WORLD GATEWAY EDUCATION AGENCY WORLD GATEWAY EDUCATION AGENCY
Universidad de Tecnologías de la Información y Gestión

Ingeniería informática (“Diseño de sistemas informáticos”, “Diseño de herramientas de software prácticas”, “Tecnologías de la información y multimedia”)

Bachiller Jornada completa 4 años

Sobre el programa

I. The content of science

The goal of teaching science is to help students become more professional. The goal is to develop knowledge, skills, and competencies in solving issues related to ensuring the cybersecurity of information systems and information resources.

The task of the subject is to familiarize students with the basic concepts of cybersecurity, the basics of cryptography, access control, effective methods and tools for ensuring network and computer security, as well as threats to information security and combating them.

II. Main theoretical part (lectures)

II.I. The subject includes the following topics:

Section 1 Cybersecurity

Lecture 1. Basic concepts of cybersecurity i.

Examples of information security in real life, cybersecurity, information security, confidentiality, integrity, usability, risk, thinking like an attacker, systems thinking, asset, threat, vulnerability, control tool, knowledge areas of cybersecurity.

Lecture 2 Cybercrime, cyberlaws and cyberethics.

Domestic cybercrimes. external cybercrimes, cyberlaws, national laws, international cyberlaws, cyberethics.

Lecture 3. Safety of human activities.

Human factor in cybersecurity, social engineering , phishing, social engineering protection measures .

Section 2. Cybersecurity architecture, strategy, and policy

Lecture 4. Cybersecurity architecture, strategy, and policy.

Cybersecurity architecture, strategy. Cybersecurity policy and its implementation: information security policy, necessity of security policy, benefits of security policy, hierarchy of security policy, features of security policy , types of information security policy.

Section 3. Cryptographic Protection of Information.

Lecture 5. Basic concepts of cryptography.

Basic terms, sections of cryptography, cryptosystems, Kerckhoff's principles, history of cryptography, cryptographic reflection.

Lecture 6. Symmetric cryptographic algorithms and public-key cryptosystems.

Stream symmetric encryption algorithms, A5/1 Stream encryption algorithms, block symmetric encryption algorithms, problems in symmetric cryptosystems,

One-way function, Factorization problem, modular arithmetic, RSA algorithms, Use of public-key cryptosystems, Key length in public-key cryptosystems.

7. Methods for ensuring data integrity.

Hash function, message authentication code, data integrity verification based on hash functions, data integrity verification and anti-repudiation protection based on public-key encryption algorithms, EDS formation process, EDS verification process, public key infrastructure

Lecture 8. Disk and file encryption. Methods for secure data deletion.

Hardware-software encryption, hardware encryption, software encryption, disk and file system level encryption. Methods for destroying paper documents, destruction of electronic documents.

Section 4 Usage Control

Lecture 9. Identification and authentication tools.

Identification, authentication and authorization, one-way and two-way authentication, multi-factor authentication, password systems, electronic devices, biometric systems.

Topic 10. Logical management of data usage.

Access control, Discretionary access control (DAC), Mandatory access control (MAC), Role-based access control (RBAC), Attribute-based access control (ABAC), access control matrix, ACL or S-list.

Topic 11. Multi-layered security models.

Bell-LaPadula model, Biba model, logical and physical access control.

Topic 12. Physical protection of data.

Physical security, its necessity, factors affecting physical security, natural threats, man-made threats, physical security control, other physical security measures, awareness/training.

Section 5. Network Security.

Topic 13. Computer networks and network security issues.

Network types, network topologies, OSI model, network requirements, TCP/IP model, network tools. Vulnerability, threat, attack, internal threat, external threat, reconnaissance attacks, intrusion attacks, malicious attacks, Denial of service (DOS) attacks.

Topic 14. Tools for ensuring network security.

Network firewalls, virtual private networks, intrusion detection systems (IDS), data leakage prevention systems (DLP), honeypots.

Topic 15. Wireless network security.

Types of wireless networks, vulnerabilities in wireless networks, uncontrolled area, unauthorized intrusion, eavesdropping, denial of service, man-in-the-middle attack, rogue network access points (malicious twin attack), Roaming problem, encryption of data transmitted over the network.

Topic 16. Risk management.

Risk, risk level, risk frequency, risk matrix, risk management, key risk indicators, risk management stages, risk management framework in an organization, risk management information systems (Risk Management Information Systems, RMIS).

Section 6. Methods for ensuring usability.

Topic 17. Usability concept: backup, data recovery, and event logging.

Usability, backup, backup tools. RAID technology, advantages and disadvantages, backup methods, types of backup. Data recovery, causes of data loss, data recovery tools, event logging, types of events in Windows OS.

Section 7. Security in software tools

Topic 18. Security issues in software tools.

Security issues related to websites, common web vulnerabilities, secure and insecure programming languages, concepts of vulnerabilities in software tools, defects, bugs, memory overflows.

Topic 19. Computer viruses and virus protection issues.

Types of malicious programs, viruses and their classification, functions performed by viruses, methods and tools for detecting malicious software.

Section 8 Special Section

Topic 20. Record protection.

Protecting information related to the record, protecting information with the party you are communicating with, protecting information with parties you are not communicating with. Passwords, password generation, password management, password storage, password transfer, identifying alternative methods to passwords.

Topic 21. Protection against social engineering.

Types of social engineering, principles used by social engineering professionals, not sharing information on social networks, identifying fake social media connections, using secure software tools.

III. Practical training instructions and recommendations

The following topics are recommended for practical training .

  1. Learning about risk assessment in cybersecurity .
  2. Studying the working procedure of classical encryption algorithms.
  3. Studying the working procedure of classical encryption algorithms.
  4. Learn how to encrypt data using TrueCrypt.
  5. Learn how to install and configure a password-based authentication mechanism in the operating system (Windows OS).
  6. Learning to carry out a reconnaissance attack.
  7. Learning to carry out a reconnaissance attack.
  8. Building network protection using a network firewall tool.
  9. Building network protection using a network firewall tool .
  10. Building a secure Wi-Fi wireless network.
  11. Learn how to recover data using special software tools.
  12. Installing virus protection on personal computers.
  13. Learn to manage the use of passwords.
  14. Learning to collect data from social networks.
  15. Learning to collect data from social media.

Practical training should be conducted in an auditorium equipped with multimedia devices by one professor-teacher per academic year. It is appropriate to conduct training using active and interactive methods, and to use appropriate pedagogical and information technologies, respectively.

IV. Independent learning and independent work

The main goal of independent work assigned to a student is to form and develop knowledge and skills to independently complete specific educational tasks under the guidance and supervision of a teacher.

Recommended topics for independent study :

  1. Analysis of national and foreign regulatory and legal documents related to cybersecurity.
  2. Cryptographic methods of information protection.
  3. The Enigma cipher machine and its durability.
  4. The role of antivirus, IDS, IPS, and TE tools in ensuring the usability of information.
  5. Classification of malicious software and protection methods.
  6. Threats to the security of information and communication technologies.
  7. Types of malware.
  8. Computer viruses and methods of protection against viruses.
  9. Analysis of electronic digital signature algorithms of foreign countries.
  10. The concept and functions of identification and authentication.
  11. Methodology for detecting unauthorized use of information systems and resources.
  12. Protection of information resources in wireless communication systems.
  13. Protecting information from unauthorized access.
  14. Analysis of attacks in social engineering.
  15. Modern antivirus software tools and their capabilities.
  16. Cybercrime and cyberlaw.
  17. The role of cryptography in protecting information transmitted over the network.
  18.  Malware and protection against them (for example, in the case of Malwarebytes).

19. Cybercrime and the reasons for its prevalence.

20. Facial image-based authentication method and its features.

21 Fingerprint-based authentication method and its features.

22. Electronic digital signature and the status of its implementation in our republic.

23. Categories of specialists in the field of cybersecurity.

24. Explore career paths in cybersecurity.

25. Starting a career in information security.

26. Popular certifications in cybersecurity.

27. Password management systems (e.g. LastPass) and their use.

28. Virtual private network and its practical use (for example, CyberGhost or ExpressVPN) .

29. What is social engineering and its modern methods?

30. Using the ESET NOD32 antivirus tool.

31. Kaspersky antivirus tool and its use.

32. Install and configure a network security tool (e.g. ZoneAlarm).

33. Virtual private network and its practical use (for example, CyberGhost or ExpressVPN).

34. Configuring user accounts (in particular, password usage policies) in Windows OS .

35. Performing Backup and Restore in Windows OS .

36. Types of privileges in Windows OS, access control procedure for files and directories.

37. Types of privileges in Linux OS, access control procedure for files and directories.

38. Data recovery tools (such as Recuva or EaseUS Data Recovery Wizard Pro) and how to recover data using them.

39. Protect data using the VeraCrypt software tool.

It is recommended that students prepare independent work on topics that are to be mastered independently, present it, and perform it in practice.

V. Learning outcomes (Developed competencies)

As a result of mastering the subject, the student will:

  • legal, organizational and technical aspects of ensuring cybersecurity;
  • have an idea of cybersecurity principles;
  • definitions of key cybersecurity concepts;
  • the legal and regulatory framework for cybersecurity;
  • international, national and departmental regulatory framework in the field of cybersecurity;
  • know and be able to use the concepts of confidentiality, integrity, and usability of information;
  • explain the main types of cybersecurity threats and methods and techniques for combating them;
  • analysis of methods of violating the confidentiality, integrity and usability of information;
  • analysis of the causes, types, and channels of information loss and corruption;
  • use of information protection methods and tools;
  • Must have skills in cryptography, access control, network and computer security.

VI. Educational technologies and methods

      • lectures;
      • interactive case studies;
      • seminars (logical thinking, quick questions and answers);
      • working in groups;
      • making presentations;

VII. Requirements for obtaining loans:

Fully master the theoretical and practical concepts of the subject, be able to fully reflect the results of the analysis, conduct independent observations of the processes being studied, complete the tasks and assignments given in the forms of current and intermediate control, and submit the final control work (regardless of its type).

Main literature

  1. D.Y.Akbarov, P.F.Xasanov, X.P.Xasanov, O.P.Axmedova, I.U.Xolimtayeva. Kriptografiyaning matematik asoslari. O‘quv qo‘llanma. T.: «Aloqachi», 2018, 192 bet.
  2. M.M.Aripov, B.F.Abdurahimov, A.S.Matyakubov. Kriptografik usullari – Toshkent, 2020 – 213-bet.

Additional literature

  1. James S. Kraft, Lawrence C. Washington. An Introduction to Number Theory with Cryptography, Second Edition, 2018, International Standard Book Number-13: 978-1-1380-6347-1 (Hardback).
  2. Jeffrey Hoffstein, Jill Pipher Joseph, H. Silverman. An Introduction to Mathematical Cryptography, Second Edition, 2014, Springer New York Heidelberg Dordrecht London.
  3. Lawrence C. Washington. Elliptic Curves Number Theory and Cryptography, Second Edition, 2008, International Standard Book Number-13: 978-1-4200-7146-7 (Hardcover).

                                      Internet resource bee

1. https://cryptomuseum.com/crypto/index.htm

2. https://www.futurelearn.com/courses/cryptography

3. https://www.edx.org/learn/cryptography

4. https://classcentral.com/course/crypto-616

5.https://medium.com/privacy-preserving-natural-language-processing/homomorphic-encryption-for-beginners-a-practical-guide-part-1-b8f26d03a98a.

Programas similares