COMP 4/6420 Network and Mobile Security - Fall2026
Teaching Team
Lecturer: Kan Yang. Email: kan.yang@memphis.edu
Office: 305 Dunn Hall
Department Office: 375 Dunn Hall (Phone: 901-678-5465)
TA: Ilham Dinle (yhssein1@memphis.edu)
Course Description
Cyber security is one of the most critical concerns in network and mobile systems today. This course discusses security vulnerabilities, threats, and solutions in modern networks and mobile devices. The curriculum is organized into five core modules: Web Security (web security model, application-level exploits), Cryptography (symmetric and public-key cryptography, SSL/TLS), Network Security (security in network protocols, defense tools, and DDoS), Mobile Security (Android and iOS security architectures), and a newly integrated module on AI Security.
The newly added AI Security module bridges fundamental network defense concepts with state-of-the-art research conducted in Dr. Kan Yang's CryptoSec Lab. Students will learn the robustness, privacy, and trustworthiness of machine learning systems, exploring adversarial evasion attacks (such as FGSM), data poisoning, privacy-preserving machine learning, and secure federated learning.
Lecture
Tuesday/Thursday, 11:20 am - 12:45 pm, J.M. Smith 220
Office Hours
With TA: TBD
With Lecturer: By appointment via email
Textbook & Learning Resources
Required Textbook: Internet Security: A Hands-on Approach, 3rd Edition (ISBN: 978-17330039-6-4) by Dr. Wenliang Du. Purchase on Amazon
Additionally, we will utilize lab exercises and reading materials from the open-source SEED Labs project and research publications covering privacy-preserving machine learning and federated learning robustness.
Evaluation
Final Grades = Lab Assignments & Reports (90%) + In-class Random Quizzes / Attendance (10%).
Grading Scale: A: 85 - 100, B: 75 - 84, C: 65 - 74, D: 55 - 64, F: 54 and below. Plus/minus grading will be applied. The instructor reserves the right to lower the thresholds to make the grading scale more favorable, but will never raise them.
Course Schedule
By eliminating standard examinations, homework, and review sessions, the course evaluation is focused entirely on hands-on practical skills (Labs accounting for 90% of the grade and In-class Quizzes / Attendance for 10%). This restructuring frees up multiple lecture slots, allowing Network Security and Mobile Platform Security topics to be explored in full depth, and expanding the newly integrated AI Security module to five comprehensive sessions (encompassing Threat Modeling, Adversarial ML, LLM/RAG Security, Agentic Systems, and Privacy-Preserving ML/Federated Learning), interspersed with three dedicated, independent lab working sessions to support students in completing their advanced practical deliverables.
Part I: Introduction
- Aug 25 - Lecture 1: Course Overview and Introduction
- Aug 27 - Lecture 2: Security Foundations, Ethics, and Threat Modeling
Part II: Web Security
- Sep 01 - Lecture 3: Web Security Architecture and SQL Injection [SQL Injection Attack Lab]
- Sep 03 - Lecture 4: Cross-Site Scripting [XSS Attack Lab]
- Sep 08 - Lecture 5: CSRF, Authentication, and Session Management [CSRF Attack Lab]
Part III: Cryptography
- Sep 10 - Lecture 6: Symmetric Cryptography I: Definitions and AES [Secret Key Encryption Lab]
- Sep 15 - Lecture 7: Symmetric Cryptography II: Modes and AEAD [Secret Key Encryption Lab continued]
- Sep 17 - Lecture 8: Symmetric Cryptography III: Integrity and Hashing
- Sep 22 - Lecture 9: Public-Key Cryptography I: RSA and Signatures [Public-Key Cryptography and PKI Lab]
- Sep 24 - Lecture 10: Public-Key Cryptography II: Key Exchange and PQC
- Sep 29 - Lecture 11: HTTPS, TLS, and Public-Key Infrastructure [TLS and PKI Labs]
- Oct 01 - [NO CLASS] Lab Working
Part IV: Network Security
- Oct 06 - Lecture 12: Network Security: Architecture and Zero Trust
- Oct 08 - Lecture 13: Network Protocol Threats and Security Issues [Sniffing/Spoofing, IP/ICMP, TCP, BGP Labs]
- Oct 13 - [NO CLASS] Fall Break
- Oct 15 - Lecture 14: Firewalls, VPNs, and Intrusion Detection [Firewall Setup & VPN Tunneling Labs]
- Oct 20 - Lecture 15: DNS Security [Local and Remote DNS Attack Labs]
- Oct 22 - Lecture 16: DDoS and Resource-Exhaustion Security
- Oct 27 - Lecture 17: Wireless and Mobile Network Security
Part V: Mobile Security
- Oct 29 - Lecture 18: Mobile Platform and Application Security [Android Repackaging & Device Rooting Labs]
- Nov 03 - Lecture 19: Mobile Malware, Supply Chains, and AI-Enabled Threats
Part VI: AI Security
- Nov 05 - Lecture 20: AI Security I: Systems, Assets, and Threat Modeling
- Nov 10 - Lecture 21: AI Security II: Adversarial ML and Supply Chains [AI Lab 16: Adversarial Machine Learning]
- Nov 12 - Lecture 22: AI Security III: LLM and RAG Security
- Nov 17 - Lecture 23: AI Security IV: Agentic Systems and Red Teaming
- Nov 19 - Lecture 24: AI Security V: Privacy-Preserving ML & Secure Federated Learning [AI Lab 17: Federated Learning]
- Nov 24 - [NO CLASS] Lab Working
- Nov 26 - [NO CLASS] Thanksgiving Holiday
- Dec 01 - [NO CLASS] Lab Working
Hands-On Lab Requirements
Labs are a cornerstone of this course. Students will complete hands-on activities to experience real-world attacks and implement defense systems in a virtual environment. Out of the available labs, students are required to submit comprehensive reports based on their enrollment level:
- Undergraduate Students (COMP 4420): 6 Lab Reports
- Undergraduate Students with Honors Project: 7 Lab Reports (including web, network, or mobile honors task)
- Graduate Students (COMP 6420): 8 Lab Reports
Available Lab List
Web Security Labs (3 labs)
- Cross-Site Scripting (XSS) Attack Lab
- Cross-Site Request Forgery (CSRF) Attack Lab
- SQL Injection Attack Lab
Cryptography Labs (3 labs)
Network Security Labs (7 labs)
- IP Layer and Attacks / ICMP Redirect Lab
- Packet Sniffing & Spoofing Lab
- TCP Attacks and Mitigation Lab
- Firewall Setup and Evading Lab
- Virtual Private Network (VPN) Tunneling Lab
- Local and Remote DNS Attack Labs
- BGP Security Lab
Mobile Security Labs (2 labs)
AI Security Labs (2 labs)
- AI Lab 1: Adversarial Machine Learning - Evasion Attacks & Robust ML Classifiers: Implement FGSM evasion attacks against PyTorch image classifiers and construct defensive adversarial training loops.
- AI Lab 2: Federated Learning - Privacy-Preserving Collaborative Training & Poisoning Robustness: Build a secure, local federated learning environment and model defensive aggregation strategies against weight-poisoning attacks.