15-316: Software Foundations of Security & Privacy
(Spring 2026)
Overview
Security and privacy issues in computer systems continue to be a
pervasive issue in technology and society. Understanding the security
and privacy needs of software, and being able to rigorously demonstrate
that those needs are met, is key to eliminating vulnerabilities that
cause these issues. Students who take this course will learn the
principles needed to make these assurances about software, and some of
the key strategies used to make sure that they are correctly implemented
in practice. Topics include:
-
Policy models: safety & liveness, information flow, capabilities
- Reference monitors
- Security type systems
-
Isolation principles & techniques: software fault isolation,
control-flow integrity, hardware protection
-
Trusted computing: authorization logic, public key infrastructure,
hardware & software support
- Side channel vulnerability & defense
- Techniques for ensuring rigorous data privacy
Students will also gain experience applying many of these techniques to
write code that is secure by construction. However, the goal of the course
is to teach students the principles and algorithms behind good security
and privacy solutions, so they they can adapt and extend them in the
future. In order to achieve this level of understanding, the course will
cover a number of key ideas from logic and languages when developing the
security topics above. These include:
- Formal proof
- Soundness and completeness of deductive systems
- Program semantics
- Specification and verification of program behavior
- Software model checking
Pre-requisites
15-213 (Introduction to Computer Systems) with a C or better.
Credits
This is a 9 unit elective course.
Place and time
| Day |
Time |
Location |
| Sundays and Tuesdays |
2:30 to 3:45 |
CMB 1190 |
Assignments
Homeworks
Homeworks are written assignments designed to help you master the
theoretical concepts in this course. They will include things like logic
proofs and describing vulnerabilities in formally described security
systems.
Unless otherwise stated, all homeworks are due at 8:00pm on the date
marked on the handout. Written homework should be submitted through
Gradescope, please notify the course staff if you have not already
received an email to enroll in the relevant Gradescope instance.
You are required to typeset your homework using
LaTeX. Typically you will
edit a .tex file which is compiled into a pdf. This file
uses specific tags and commands for typesetting. If you only know Word
(or similar) for creating documents, LaTeX takes a little getting used
to, but it is worth it. After you become familiar with the syntax, some
advantages are:
- Typing math is much (much, much) faster
-
You do not have to worry about margins or consistent style of headers
or alignment
-
Changing the order of sections involves no renumbering on your part
-
References are formatted and numbered for you (APA? What is that?)
There are various tools for editing and compiling LaTeX. If you do not
want to install anything locally, you can use one of the web-based ones,
such as Overleaf.
We recognize that certain types of answers, such as those that involve
graphical figures, can be difficult or tedious to typeset. In those
cases, it is fine to scan a handwritten solution to include in your
latex code as a graphic.
Written homeworks must be done individually. Collaboration is regulated
by the whiteboard policy: you can bounce ideas about a homework with
other students, but when it comes to typing it down for submission, you
are on your own. You are not allowed to use notes, files, pictures,
etc., from any previous discussion nor previous versions of this course.
If you use unrelated web resources, you must explicitly cite them.
Labs
Labs are programming assignments designed to give you hands on
experience applying the concepts learned in this course. You will be
writing and testing code and security policies.
As with homeworks, all labs are due at 8:00pm on the date marked on the
handout. Labs should also be submitted on Gradescope.
Labs may be done in pairs (strongly encouraged) or individually. If you
choose to work with a partner, you should submit only one solution as a
group on Gradescope. You should not collaborate with others outside your
group---the whiteboard policy only applies to the written homework
assignments. You are not allowed to use any materials from labs in
previous versions of this course. If you use unrelated web resources,
you must explicitly cite them.
Policies
Grading
Your final grade will be calculated using the following weightings:
| Component |
Description |
| Labs (30%) |
The lab assignments are designed to give you hands-on experience
writing secure software that serves a practical purpose. In
general, the lab assignments will ask you to implement some
functionality (generally in C) related to a network server that
receives HTTP requests, while ensuring that it is not vulnerable
to a particular class of security threats. Some of the labs will
give you hands-on experience using tools to help achieve this
goal, whereas others will have you implementing a technique
discussed in lecture.
The most important criterion with respect to grading the labs is
correctness, and your justification for believing that your
solution is correct. An ideal lab attempt contains a concise,
correct security policy, and a correct implementation of an
apparatus that enforces that policy or sufficient documentation
of the steps you took to ensure compliance. However, it may be
the case that your policy is incorrect, or too complicated for
the grader to fully understand. Verification of policy to code
cannot be fully automated, so it is possible that the grader is
not able to certify that your solution is guaranteed to be
correct. In these cases, you will receive partial credit, so it
is also important that the code you hand in be clean and
well-commented, as course staff cannot assign points to
solutions that they do not understand.
|
| Homework (30%) |
Written homework will be assigned more frequently, and should
not require as much time to complete as the labs. The goal of
the written homework is to help you refine the fundamental
skills, and better understand the theoretical underpinnings,
that you will need in order to do well on the labs and exams.
Grading for these assignments is based on the correctness of
your answer, and the presentation of your reasoning. You should
strive for clarity and conciseness, while making sure to show
each step of your reasoning. Categorical answers with no
explanation will not even receive partial credit, but lucid
explanations of your attempt to find the answer will.
|
Exams (40%) |
We will have two exams. The content of these exams will more
closely resemble the written homework than the labs, but some
questions may rely on, or make reference to, key parts of the
labs. The midterm will take place during the normal class
meeting time, in the same room used for lectures. Both exams are
"closed book" (i.e., you may not reference our lecture notes),
but you are allowed to bring a single double-sided sheet of
hand-written (by you) notes. Typed or photocopied notes
will not be allowed.
Your highest scoring exam will be weighted at 25%, and your
lowest scoring exam weighted at 15%.
|
Regardless of the weightings above, your overall course average cannot
be more than 10 percentage points higher than your exam average. This
means, for example, that if your exam average is a 75%, then your
overall course average is capped at 85%.
Regrades
We occasionally make mistakes while grading (we're only human!). If you
find a mistake which you would like us to correct, then submit a regrade
request using the Gradescope regrade request feature. Regrades must be
requested within two weeks of the time when the contested grade was
released. The two week limit may be shortened at the end of the semester
in order to meet grade submission deadlines.
Late Days
For homeworks, you have a total of 5 late days to use throughout the semester on the
five written homeworks, where you may not use more than 2 days on any
given homework.
For labs, no late days are available.
Academic Integrity
You are expected to comply with the
university policy on academic integrity
(see also
The Word
and
Understanding Academic Integrity).
Collaboration is regulated by the whiteboard policy: you can bounce
ideas about a homework with other students, but when it comes to
typing it down for submission, you are on your own. You are not
allowed to use notes, files, pictures, etc, from any previous
discussion nor previous versions of this course.
And remember not to ignore your inner voice when it says "That's
probably not the best decision...".
Artificial Intelligence Tools
Preliminary research indicates that the use of AI when solving tasks
results in a
measurable decrease in learning. It also seems to
decrease engagement with, and enjoyment of, tasks when it is used. Given that the purpose of taking this course
is to engage with, and learn, new material, that makes AI tools
counter-productive.
For the homeworks, the use of AI tools is not permitted.
For the labs, AI tools may be used to learn syntax or library questions
about programming (i.e., "Hey ChatGPT, how do I case/switch over a
variable's type in Python?") but should not be used to write code
or brainstorm solutions techniques. This means that you will likely need
to disable AI autocomplete and refrain from using tools like Github
CoPilot.
If you are asking an AI tool a question about the homework or a lab,
then you are in violation of this policy. If you are asking it general
questions about programming or logic, then you are fine.
An Invitation to Students with Learning Disabilities
Carnegie Mellon University is committed to providing reasonable
accommodations for all persons with disabilities. To access
accommodation services you are expected to initiate the request and
submit a Voluntary Disclosure of Disability Form to the office of Health
& Wellness or CaPS-Q. In order to receive services/accommodations,
verification of a disability is required as recommended in writing by a
doctor, licensed psychologist or psycho-educational specialist. The
office of Health & Wellness, CaPS-Q and Office of Disability
Resources in Pittsburgh will review the information you provide. All
information will be considered confidential and only released to
appropriate persons on a need to know basis.
Once the accommodations have been approved, you will be issued a Summary
of Accommodations Memorandum documenting the disability and describing
the accommodation. You are responsible for providing the Memorandum to
your professors at the beginning of each semester.
For more information on policies and procedures, please visit
Assistance for Individuals with Disabilities on Scotty.
Take Care of Yourself
We all feel stress at different times and for different reasons, and
when we do, it is good to reach out for support. Do your best to
maintain a healthy lifestyle by eating well, exercising, getting enough
sleep and taking some time to relax. Please know that you are not alone.
There are many helpful resources available on campus and an important
part of your university experience is learning how to ask for help.
Asking for support sooner rather than later can often help your
situation from getting more complicated.
If you or any of your CMUQ peers are experiencing academic stress,
difficult life events, or feelings like anxiety or depression, we strongly
encourage you to seek support. Our Student Affairs staff are here to help.
Please reach out to:
Consider also reaching out to a friend, faculty, staff or family member
you trust for help. If you would like to speak to a trained professional
for mental health support, day or night, call our ProtoCall hotline at
5554 7913, which is staffed by trained mental health care providers. If
the situation is life threatening, please call 4454 0999 for an on
campus emergency or 999 for an off campus emergency.
Diversity Statement
It is my hope that students from a diversity of backgrounds and
perspectives be well served by this course, that students' learning
needs be addressed both in and out of class, and that the diversity
students bring to this class be viewed as a resource, strength and
benefit. It is my intent to present materials and activities that are
respectful of diversity: gender, sexuality, disability, age,
socioeconomic status, ethnicity, race, nationality, religion, and
culture. Your suggestions are encouraged and appreciated. Please let me
know ways to improve the effectiveness of the course for you personally
or for other students or student groups.
This statement is adapted from
The University of Iowa Department of Education.