<?xml version="1.0" encoding="UTF-8"?>
<CourseUnit xmlns="http://www.manchester.ac.uk/CUICourseUnitDetails" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.manchester.ac.uk/CUICourseUnitDetails.xsd">
  <UnitCode Applicant="Y" Label="Unit code" Student="Y">
    <Code>COMP38412</Code>
  </UnitCode>
  <UnitTitle Applicant="Y" Label="Unit title" Student="Y">
    <Title>Cybersecurity: Principles and Secure Software Systems</Title>
  </UnitTitle>
  <MaxUnits Applicant="Y" Label="Credit rating" Student="Y">
    <Units>10</Units>
  </MaxUnits>
  <TeachingPeriods Applicant="Y" Label="Teaching period(s)" Student="Y">
    <Period>Semester 2</Period>
  </TeachingPeriods>
  <AcademicCareer Applicant="Y" Label="Academic career" Student="Y">
    <Value>Undergraduate</Value>
  </AcademicCareer>
  <UnitLevel Applicant="Y" Label="Unit level" Student="Y">
    <Level>Level 3</Level>
  </UnitLevel>
  <StaffList Applicant="Y" Label="Teaching staff" RoleLabel="Course Unit Role" Student="Y">
    <StaffMember>
      <Name>Dominik Winterer</Name>
      <Role>Unit coordinator</Role>
    </StaffMember>
  </StaffList>
  <OfferedBy Applicant="Y" Label="Offered by" Student="Y">
    <OrganisationList>
      <Organisation>
        <OrgName>Department of Computer Science</OrgName>
      </Organisation>
    </OrganisationList>
    <GroupList>
      <Group>
        <GroupName></GroupName>
      </Group>
    </GroupList>
    <FheqLevels>
      <FheqLevel>
        <LevelNumber>1</LevelNumber>
        <LevelName>FHEQ level (Framework for Higher Education Qualifications) ' Last part of a Bachelors ' </LevelName>
      </FheqLevel>
    </FheqLevels>
    <Ects>
      <MaxUnits>European Credit Transfer &amp; Accumulation System Rating :   5.0</MaxUnits>
    </Ects>
  </OfferedBy>
  <MarketingOverview Applicant="Y" Label="Marketing Course unit overview" Student="">
    <Content>&lt;p&gt;This course introduces students to the principles and practice of cybersecurity, with a strong emphasis on software-intensive systems, including AI-enabled and cyber-physical systems (CPS). The course integrates classical security mechanisms with automated and formal verification techniques, enabling students to identify, analyse, and mitigate security threats systematically. Students will learn to reason about security as a "system property", from threat modelling and secure design to vulnerability detection and formal verification. Through lectures and hands-on laboratories, students will gain practical experience in analysing real-world vulnerabilities and applying automated verification tools to security-critical software written in industrial programming languages (e.g., C, C++, Rust, Java, and Python).&amp;nbsp;&lt;/p&gt;</Content>
  </MarketingOverview>
  <UnitOverview Applicant="" Label="Course unit overview" Student="Y">
    <Content>&lt;p&gt;This course introduces students to the principles and practice of cybersecurity, with a strong emphasis on software-intensive systems, including AI-enabled and cyber-physical systems (CPS). The course integrates classical security mechanisms with automated and formal verification techniques, enabling students to identify, analyse, and mitigate security threats systematically. Students will learn to reason about security as a "system property", from threat modelling and secure design to vulnerability detection and formal verification. Through lectures and hands-on laboratories, students will gain practical experience in analysing real-world vulnerabilities and applying automated verification tools to security-critical software written in industrial programming languages (e.g., C, C++, Rust, Java, and Python).&amp;nbsp;&lt;/p&gt;</Content>
  </UnitOverview>
  <Aims Applicant="Y" Label="Aims" Student="Y">
    <Content>&lt;p&gt;This course introduces students to the principles and practice of cybersecurity, with a strong emphasis on software-intensive systems, including AI-enabled and cyber-physical systems (CPS). The course integrates classical security mechanisms with automated and formal verification techniques, enabling students to identify, analyse, and mitigate security threats systematically. Students will learn to reason about security as a "system property", from threat modelling and secure design to vulnerability detection and formal verification. Through lectures and hands-on laboratories, students will gain practical experience in analysing real-world vulnerabilities and applying automated verification tools to security-critical software written in industrial programming languages (e.g., C, C++, Rust, Java, and Python).&amp;nbsp;&lt;/p&gt;</Content>
  </Aims>
  <LearningOutcomes Applicant="Y" Label="Learning outcomes" Student="Y">
    <Content>&lt;p&gt;&lt;span style="font-family:&amp;quot;Cambria&amp;quot;,serif;font-size:11.0pt;tab-stops:86.95pt;"&gt;&lt;strong&gt;ILO1:&lt;/strong&gt; Select and apply cryptographic encryption schemes for confidentiality, and authentication schemes for integrity and non-repudiation&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:&amp;quot;Cambria&amp;quot;,serif;font-size:11.0pt;tab-stops:86.95pt;"&gt;&lt;strong&gt;ILO2: &lt;/strong&gt;Assess the strengths and limitations of automated security analysis tools&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:&amp;quot;Cambria&amp;quot;,serif;font-size:11.0pt;tab-stops:86.95pt;"&gt;&lt;strong&gt;ILO3: &lt;/strong&gt;Identify common software vulnerabilities and apply secure coding practices to mitigate them&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:&amp;quot;Cambria&amp;quot;,serif;font-size:11.0pt;tab-stops:86.95pt;"&gt;&lt;strong&gt;ILO4: &lt;/strong&gt;Evaluate security challenges in modern systems, including AI-enabled and cyber-physical systems&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:&amp;quot;Cambria&amp;quot;,serif;font-size:11.0pt;tab-stops:86.95pt;"&gt;&lt;strong&gt;ILO5: &lt;/strong&gt;Apply automated and formal verification techniques to detect and reason about security vulnerabilities in software&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:&amp;quot;Cambria&amp;quot;,serif;font-size:11.0pt;tab-stops:86.95pt;"&gt;&lt;strong&gt;ILO6:&amp;nbsp;&lt;/strong&gt;Analyse and classify security threats and vulnerabilities in software and systems&amp;nbsp;&lt;/span&gt;&lt;/p&gt;</Content>
  </LearningOutcomes>
  <Knowledge Applicant="Y" Label="Knowledge and understanding" Student="Y">
    <Content></Content>
  </Knowledge>
  <IntellectualSkills Applicant="Y" Label="Intellectual skills" Student="Y">
    <Content></Content>
  </IntellectualSkills>
  <PracticalSkills Applicant="Y" Label="Practical skills" Student="Y">
    <Content></Content>
  </PracticalSkills>
  <TransferableSkills Applicant="Y" Label="Transferable skills and personal qualities" Student="Y">
    <Content></Content>
  </TransferableSkills>
  <EmployabilitySkillsList Applicant="Y" Label="Employability skills" Student="Y">
    <Skill>
      <SkillId>Analytical skills</SkillId>
      <SkillDescription></SkillDescription>
    </Skill>
    <Skill>
      <SkillId>Innovation/creativity</SkillId>
      <SkillDescription></SkillDescription>
    </Skill>
    <Skill>
      <SkillId>Problem solving</SkillId>
      <SkillDescription></SkillDescription>
    </Skill>
    <Skill>
      <SkillId>Research</SkillId>
      <SkillDescription></SkillDescription>
    </Skill>
  </EmployabilitySkillsList>
  <Syllabus Applicant="Y" Label="Syllabus" Student="Y">
    <Content>&lt;p&gt;1. Foundations of Cybersecurity and Threat Modelling&amp;nbsp;&lt;br&gt;- Notion and scope of cybersecurity across software, networked, and cyber-physical systems.&amp;nbsp;&lt;br&gt;- Security goals, services, and adversary models.&amp;nbsp;&lt;br&gt;- Threat classification and attack surfaces.&amp;nbsp;&lt;br&gt;- Systematic threat modelling (assets, trust boundaries, attacker capabilities).&amp;nbsp;&lt;br&gt;- Overview of formal methods in security assurance.&lt;/p&gt;&lt;p&gt;2. Cryptography: Symmetric and Asymmetric Encryption&amp;nbsp;&lt;br&gt;- Classical encryption techniques.&amp;nbsp;&lt;br&gt;- Block ciphers.&amp;nbsp;&lt;br&gt;- Symmetric encryption modes of operation.&amp;nbsp;&lt;br&gt;- Number theory: Prime numbers, Fermat’s and Euler’s Theorems, Primality Testing (Miller-Rabin), and Discrete Logarithms.&amp;nbsp;&lt;br&gt;- Asymmetric encryption: Principles of Public-Key Cryptosystems and the RSA scheme.&lt;/p&gt;&lt;p&gt;3. Cryptographic Authentication and Access Control&amp;nbsp;&lt;br&gt;- Cryptographic hash functions.&amp;nbsp;&lt;br&gt;- Message authentication codes (MACs).&amp;nbsp;&lt;br&gt;- Authenticated encryption.&amp;nbsp;&lt;br&gt;- Digital signatures.&amp;nbsp;&lt;br&gt;- Identification Schemes.&lt;/p&gt;&lt;p&gt;4. Software and System Security&amp;nbsp;&lt;br&gt;- Threat modelling for software systems.&amp;nbsp;&lt;br&gt;- Malicious software and attack vectors.&amp;nbsp;&lt;br&gt;- Software vulnerabilities: memory safety, injections, race conditions, and logic errors.&amp;nbsp;&lt;br&gt;- Secure coding principles and defensive design.&amp;nbsp;&lt;br&gt;- Software supply-chain security and dependency risks.&amp;nbsp;&lt;br&gt;- Security challenges in AI-enabled and embedded software systems.&lt;/p&gt;&lt;p&gt;5. Automated and Formal Security Analysis&amp;nbsp;&lt;br&gt;- Static and dynamic analysis techniques for vulnerability detection.&amp;nbsp;&lt;br&gt;- Security properties vs safety properties.&amp;nbsp;&lt;br&gt;- Model checking and unbounded verification.&amp;nbsp;&lt;br&gt;- Formal specification of security requirements.&amp;nbsp;&lt;br&gt;- Practical verification of security properties in C, C++, Rust, Java, and Python programs.&amp;nbsp;&lt;br&gt;- Verification challenges in cyber-physical and AI-enabled systems.&amp;nbsp;&lt;/p&gt;</Content>
  </Syllabus>
  <TeachingMethods Applicant="Y" Label="Teaching and learning methods" Student="Y">
    <Content>&lt;p style="margin-left:48px;"&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;Lecture: 20 hours&lt;/span&gt;&lt;br&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;Assessment - Coursework: 20 hours&lt;/span&gt;&lt;br&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;Independent Study: 60 hours&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-left:48px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin-left:48px;"&gt;&amp;nbsp;&lt;/p&gt;</Content>
  </TeachingMethods>
  <AssessmentMethods Applicant="Y" Label="Assessment methods" Student="Y">
    <IntroText> </IntroText>
    <Method>
      <MethodId>1</MethodId>
      <MethodName>Written exam</MethodName>
      <MethodWeight>70%</MethodWeight>
    </Method>
    <Method>
      <MethodId>2</MethodId>
      <MethodName>Written assignment (inc essay)</MethodName>
      <MethodWeight>30%</MethodWeight>
    </Method>
  </AssessmentMethods>
  <FeedbackMethods Applicant="Y" Label="Feedback methods" Student="Y">
    <Content>&lt;p&gt;&lt;span style="font-size:12pt"&gt;&lt;span style="font-family:Calibri,sans-serif"&gt;&lt;span style="font-size:11.0pt"&gt;Exercises and in-class feedback&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;</Content>
  </FeedbackMethods>
  <RequirementsList Applicant="Y" Label="Pre/co-requisites" Student="Y">
    <Requirement>
      <UnitCode>COMP15111</UnitCode>
      <UnitTitle>Fundamentals of Computer Architecture</UnitTitle>
      <RequirementType>Pre-Requisite</RequirementType>
      <Description>Compulsory</Description>
    </Requirement>
    <Requirement>
      <UnitCode>COMP11212</UnitCode>
      <UnitTitle>Fundamentals of Computation</UnitTitle>
      <RequirementType>Pre-Requisite</RequirementType>
      <Description>Compulsory</Description>
    </Requirement>
    <AdditionalRequirement>COMP15111 and COMP11212 are pre-requisites. CM students will be missing the COMP15111 pre-requisite so will need to get permission from their Year Tutor and the Unit Coordinator for COMP38412 before they can enrol.&lt;p&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;COMP15111 and COMP11212 are pre-requisites. CM students will be missing the COMP15111 pre-requisite so will need to get permission from their Year Tutor and the Unit Coordinator for COMP38412 before they can enrol.&lt;/span&gt;&lt;/p&gt;</AdditionalRequirement>
  </RequirementsList>
  <AcademicPrograms Applicant="Y" Label="Academic programmes" Student="Y">
    <AcademicProgram>
      <Program></Program>
      <Plan></Plan>
      <Level></Level>
      <Requirement></Requirement>
    </AcademicProgram>
  </AcademicPrograms>
  <FreeChoice Applicant="Y" Label="Available as a free choice unit?" Student="Y">
    <Content>N</Content>
  </FreeChoice>
  <Accreditation Applicant="Y" Label="Accreditation" Student="Y">
    <Content></Content>
  </Accreditation>
  <RecommendedReading Applicant="Y" Label="Recommended reading" Student="Y">
    <Content>&lt;ol&gt;&lt;li&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt;William Stallings, Lawrie Brown. (2024). &lt;/span&gt;&lt;i&gt;&lt;span style="font-size:12pt;"&gt;Computer Security Principles and Practice&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:12pt;"&gt;. Pearson Education, Inc. ISBN:&lt;/span&gt;&lt;/span&gt;&lt;a href="https://www.librarysearch.manchester.ac.uk/discovery/search?query=isbn,contains,9780138091675&amp;amp;search_scope=MyInst_and_CI&amp;amp;sortby=rank&amp;amp;vid=44MAN_INST:MU_NUI&amp;amp;lang=en&amp;amp;mode=advanced&amp;amp;offset=0" target="_blank"&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt; 9780138091675&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt;Clarke, Edmund M; Henzinger, Thomas A; Veith, Helmut; Bloem, Roderick. (2018). &lt;/span&gt;&lt;i&gt;&lt;span style="font-size:12pt;"&gt;Handbook of Model Checking&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:12pt;"&gt;. Springer International Publishing. ISBN:&lt;/span&gt;&lt;/span&gt;&lt;a href="https://www.librarysearch.manchester.ac.uk/discovery/search?query=isbn,contains,9783319105758&amp;amp;search_scope=MyInst_and_CI&amp;amp;sortby=rank&amp;amp;vid=44MAN_INST:MU_NUI&amp;amp;lang=en&amp;amp;mode=advanced&amp;amp;offset=0" target="_blank"&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt; 9783319105758&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt;Stallings, William. (2014). &lt;/span&gt;&lt;i&gt;&lt;span style="font-size:12pt;"&gt;Cryptography and Network Security: Principles and Practice.&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:12pt;"&gt; Pearson Education UK. ISBN:&lt;/span&gt;&lt;/span&gt;&lt;a href="https://www.librarysearch.manchester.ac.uk/discovery/search?query=isbn,contains,9780273793762&amp;amp;search_scope=MyInst_and_CI&amp;amp;sortby=rank&amp;amp;vid=44MAN_INST:MU_NUI&amp;amp;lang=en&amp;amp;mode=advanced&amp;amp;offset=0" target="_blank"&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt; 9780273793762&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt;Anderson, Ross. (2020). &lt;/span&gt;&lt;i&gt;&lt;span style="font-size:12pt;"&gt;Security engineering: a guide to building dependable distributed systems&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:12pt;"&gt;. John Wiley &amp;amp; Sons Inc. ISBN:&lt;/span&gt;&lt;/span&gt;&lt;a href="https://www.librarysearch.manchester.ac.uk/discovery/search?query=isbn,contains,9781119644682&amp;amp;search_scope=MyInst_and_CI&amp;amp;sortby=rank&amp;amp;vid=44MAN_INST:MU_NUI&amp;amp;lang=en&amp;amp;mode=advanced&amp;amp;offset=0" target="_blank"&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt; 9781119644682&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt;William Stallings. (2018).&lt;/span&gt;&lt;i&gt;&lt;span style="font-size:12pt;"&gt; Effective Cybersecurity: A Guide to Using Best Practices and Standards&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:12pt;"&gt;. Addison-Wesley. ISBN: &lt;/span&gt;&lt;/span&gt;&lt;a href="https://www.librarysearch.manchester.ac.uk/discovery/search?query=isbn,contains,978&amp;amp;search_scope=MyInst_and_CI&amp;amp;sortby=rank&amp;amp;vid=44MAN_INST:MU_NUI&amp;amp;lang=en&amp;amp;mode=advanced&amp;amp;offset=0" target="_blank"&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size:12pt;"&gt;978&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;&lt;span style="font-size:12pt;"&gt;Computer Security: Art and Science &lt;/span&gt;&lt;/i&gt;&lt;span style="font-size:12pt;"&gt;| 2nd edition | Pearson. &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;</Content>
  </RecommendedReading>
  <StudyHours Applicant="Y" Label="Study hours" Student="Y">
    <IntroText> </IntroText>
    <ScheduledHours Applicant="Y" Label="Scheduled activity hours" Student="Y">
      <ActivityHours>
        <ActivityType>Lectures</ActivityType>
        <Hours>20</Hours>
      </ActivityHours>
      <ActivityHours>
        <ActivityType>Practical classes &amp; workshops</ActivityType>
        <Hours>20</Hours>
      </ActivityHours>
    </ScheduledHours>
    <PlacementHours Applicant="Y" Label="Placement hours" Student="Y">
      <ActivityHours>
        <ActivityType></ActivityType>
        <Hours>0</Hours>
      </ActivityHours>
    </PlacementHours>
    <TotalHours Applicant="Y" Label="Independent study hours" Student="Y">
      <Hours>60</Hours>
    </TotalHours>
  </StudyHours>
  <Notes Applicant="Y" Label="Additional notes" Student="Y">
    <Content></Content>
  </Notes>
</CourseUnit>
