About this course
As anybody, familiar with 1970s sitcoms can confirm, Mel, Alice's cook used to say:
“the best defense is a good offense”.
In cybersecurity, a similar saying would be that in order to know how to secure something, one needs first to know how to compromise & break it.
This is exactly what the MODAL offers: to help you understand — and try — how to “break things”. This can include topics such as:
- TCP Connection hijacking & SYN flooding
- SQL Injection attacks on WWW servers
- Heartbleed - that SSL bug that caused the whole Internet to flip out
- DNS Cache Poisoning
- ...
This course consists of a set of instructional videos, some quizzes, tutorials, a set of challenges -- and regular exchanges with your professors and instructors over WebEx.
-
Tutorials serve to help students to acquire a certain set of skills. Each tutorial requires a submission of some code, which will be evaluated, and a grade for each tutorial will be given.
-
Quizzes serve to allow checking that certain theoretical concepts have been acquired. Each quiz can be attempted once. Completing a quiz will give a number of points and will unblock future course activities (tutorials, videos, challenges, and more quizzes...)
-
Challenges each represent "a thing to hack", such as DNS, or TCP, or DHCP, or invoking a buffer overflow, or performing a man-in-the-middle attack. Challenges will each have an explanation, and supporting material, for what is expected - but will require independent thinking. Each challenge requires a demonstration to an instructor, then submission of some code, which will be scrutinised. Based on all this, a grade will be awarded.
-
Each challenge can bring you a maximum number of points, which will be indicated for the challenge.
-
A submission which "does the job, nothing more, nothing less" will be given 50% of the maximum number of points, indicated for the challenge
-
To get maximum points, an additional effort, such as highly modular code, flexible, robust, or supporting different attack approaches, is required.
-
You're encouraged to work in a small group of 1-2 students for each challenge.
You will choose to work on challenges in the order you like, and you will do however many you want - or, need, in order to get enough points to pass the course.
Learning outcomes
Upon successful completion of the course, a student will be able to:
- Describe the basic architecture of the Internet
- Develop simple networked programs (clients) in C, which communicate with computers (servers) across a computer network
- Monitor and analyse Internet traffic using existing traffic dissectors
- Analyse Real-World Internet protocols and Internet-connected systems for vulnerabilities
- Implement viable attacks against identified vulnerabilities
Activities
Video capsules, Asynchronous Learning Flows, Flipped Classrooms
Additional information
- More infoCourse page on website of École Polytechnique
- Contact a coordinator
- About studying within the EuroTeQ alliance
- LevelMaster
- InstructorsKevin Vermeulen, Thomas Clausen
- Mode of deliveryOnline - at a specific time
Starting dates
5 Mar 2027
ends 28 May 2027
Language Enrolment period closed
