Topics in Computer and Network Security

Stanford CS 356, Fall 2026

CS 356 is graduate course that covers foundational work and current topics in computer and network security. The course consists of reading and discussing published research papers, presenting recent security work, and completing an original research project.

📌 Course Information

Discussion: M/W 10:30–11:50 AM. Littlefield 103.
⚠️ This course is based on in-person discussion of research. On time, in-person attendance and participation is required.

Instructor: Zakir Durumeric. Office Hours: Monday 12:00–1:00 PM, after class. Or, by appointment.

Course Assistant: Rumaisa Habib. Office hours by appointment.

Prerequisites: CS 356 is open to all graduate students as well as advanced undergraduate students. While the course has no official prerequisites, it requires a mature understanding of software systems and networks. Students are expected to have taken CS 155: Computer and Network Security or equivalent.

Communication: We use Ed Discussion for announcements and discussion. Students can submit anonymous feedback at any time.

Submissions: All course assignments are to be submitted through Gradescope. Enrollment code: YGR33Y.

🗓️ Topics and Schedule

The tentative schedule and required readings for the class are below:

9/21  

No class.

9/23  Introduction

Against Security Nihilism

Blog Post. 2016. Chris Palmer.

Mining Your Ps and Qs: Detection of Widespread Weak Keys in Network Devices

SEC '12. Nadia Heninger, Zakir Durumeric, Eric Wustrow, and J. Alex Halderman.

How to Read a Paper

Srinivasan Keshav.

9/28  Web Privacy and Security

Online Tracking: A 1-million-site Measurement and Analysis

CCS '16. Steven Englehardt and Arvind Narayanan.

Bridges to Self: Silent Web-to-App Tracking on Mobile via Localhost

SEC '26. Tim Vlummens, Aniketh Girish, Nipuna Weerasekara, Frederik Zuiderveen Borgesius, Gunes Acar, and Narseo Vallina-Rodriguez.

9/30  Usability

Alice in Warningland: A Large-Scale Field Study of Browser Security

SEC '13. Devdatta Akhawe and Adrienne Porter Felt.

Do Users Write More Insecure Code with AI Assistants?

CCS '23. Neil Perry, Megha Srivastava, Deepak Kumar, and Dan Boneh.

10/5  Authentication and Phishing

The science of guessing: analyzing an anonymized corpus of 70 million passwords

S&P '12. Joseph Bonneau.

Understanding the Efficacy of Phishing Training in Practice

S&P '25. Grant Ho, Ariana Mirian, Elisa Luo, Khang Tong, Euyhyun Lee, Lin Liu, Christopher A. Longhurst, Christian Dameff, Stefan Savage, and Geoffrey Voelker.

10/7  Spam and eCrime

Spamalytics: An Empirical Analysis of Spam Marketing Conversion

CCS '08. Chris Kanich, Christian Kreibich, Kirill Levchenko, Brandon Enright, Geoffrey Voelker, Vern Paxson, and Stefan Savage.

Framing Dependencies Introduced by Underground Commoditization

WEIS '15. Kurt Thomas, Danny Huang, David Wang, Elie Bursztein, Chris Grier, Thomas Holt, Christopher Kruegel, Damon McCoy, Stefan Savage, and Giovanni Vigna.

10/12  System Attacks [SP]

Hacking Blind

S&P '14. Andrea Bittau, Adam Belay, Ali Mashtizadeh, David Mazieres, and Dan Boneh.

Practical Data-Only Attack Generation

SEC '24. Brian Johannesmeyer, Asia Slowinska, Herbert Bos, and Cristiano Giuffrida.

10/14  System Defenses [SP]

Bringing the Web up to Speed with WebAssembly

PLDI '17. Andreas Haas, Andreas Rossberg, Derek Schuff, Ben Titzer, Michael Holman, Dan Gohman, Luke Wagner, Alon Zakai, and JF Bastien.

The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against LLM Jailbreaks and Prompt Injections

SEC '26. Milad Nasr, Nicholas Carlini, Chawin Sitawarin, Sander V. Schulhoff, Jamie Hayes, Michael Ilie, Juliette Pluto, Shuang Song, Harsh Chaudhari, Ilia Shumailov, Abhradeep Guha Thakurta, Kai Yuanqing Xiao, Andreas Terzis, and Florian Tramèr.

10/19  Network Security

Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice

CCS '15. David Adrian, Karthikeyan Bhargavan, Zakir Durumeric, Pierrick Gaudry, Matthew Green, J. Alex Halderman, Nadia Heninger, Drew Springall, Emmanuel Thomé, Luke Valenta, Benjamin VanderSloot, Eric Wustrow, Santiago Zanella-Béguelin, and Paul Zimmermann.

Don’t Look Up: There Are Sensitive Internal Links in the Clear on GEO Satellites

CCS '25. Wenyi Morty Zhang, Annie Dai, Keegan Ryan, Dave Levin, Nadia Heninger, and Aaron Schulman.

10/21  Internet Censorship [JC]

Exposing and Circumventing SNI-based QUIC Censorship of the Great Firewall of China

SEC '25. Ali Zohaib, Qiang Zao, Jackson Sippe, Abdulrahman Alaraj, Amir Houmansadr, Zakir Durumeric, Eric Wustrow.

Characterizing the Implementation of Censorship Policies in Chinese LLM Services

NDSS '26. Anna Ablove, Shreyas Chandrashekara, Xiao Qiang, and Roya Ensafi.

10/26  Cyber Physical Systems

Comprehensive Experimental Analyses of Automotive Attack Surfaces

SEC '11. Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, and Tadayoshi Kohno.

A Tale of Two Industroyers: It was the Season of Darkness

S&P '24. Luis Salazar, Sebastian Castro, Juan Lozano, Keerthi Koneru, Emmanuele Zambon, Bing Huang, Ross Baldick, Marina Krotofil, Alonso Rojas, and Alvaro Cardenas.

10/28  Hardware

Flipping Bits in Memory Without Accessing Them: An Experimental Study of DRAM Disturbance Errors

ISCA '14. Yoongu Kim, Ross Daly, Jeremie Kim, Chris Fallin, Ji-Hye Lee, Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu.

Spectre Attacks: Exploiting Speculative Execution

S&P '19. Paul Kocher, Jann Horn, Anders Fogh, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom.

11/2  At-Risk Populations

The Spyware Used in Intimate Partner Violence

S&P '18. Rahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron, Jackeline Palmer, Diana Freed, Karen Levy, Nicola Dell, Damon McCoy, and Thomas Ristenpart.

When Governments Hack Opponents: A Look at Actors and Technology

SEC '14. Bill Marczak, John Scott-Railton, Morgan Marquis-Boire, and Vern Paxson.

11/4  IoT Security and Botnets

Understanding the Mirai Botnet

SEC '17. Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J. Alex Halderman, Luca Invernizzi, Michalis Kallitsis, Deepak Kumar, Chaz Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas, and Yi Zhou.

Derailing the Raptor Train

Technical Report. Lumen Black Lotus Labs.

11/11  AI-Enabled Abuse

Characterizing the MrDeepFakes Sexual Deepfake Marketplace

SEC '25. Catherine Han, Anne Li, Deepak Kumar, and Zakir Durumeric.

Glaze: Protecting Artists From Style Mimicry by Text-to-Image Models

SEC '23. Shawn Shan, Jenna Cryan, Emily Wenger, Haitao Zheng, Rana Hanocka, and Ben Zhao.

11/16  Data Leakage [RH]

Robust De-anonymization of Large Sparse Datasets

S&P '08. Arvind Narayanan and Vitaly Shmatikov.

Extracting Training Data from Large Language Models

SEC '21. Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, Alina Oprea, and Colin Raffel.

11/18  Problem Selection [RH]

The Moral Character of Cryptographic Work

Phillip Rogaway.

Science, Security, and the Elusive Goal of Security as a Scientific Pursuit

S&P '17. Cormac Herley and Paul C. van Oorschot.

11/23  Thanksgiving Break

No class.

11/25  Thanksgiving Break

No class.

11/30  Final Presentations

No required reading. Attendance mandatory.

12/2  Final Presentations

No required reading. Attendance mandatory.

🚩 Course Structure

This course is composed of three parts: reading and discussing foundational papers in every class, reading and presenting recent work for one class, and completing a group research project. Grading will be based on:

📚 Readings and Discussion (30%)

We will read and discuss 1–2 papers for each class. Typically, these are formative works in an area of security. Students should come prepared to actively discuss assigned papers and to make substantive intellectual contributions. This means that you need to thoroughly read each paper ahead of time. Before each section, students will submit a short (400 word) summary and reaction for each each paper, as well as a proposal of one discussion question for class.

📨 Students should submit the reading assignments through Gradescope by 10:30 am on the day of each class. Paper responses should be completed individually without the assistance of LLMs (e.g., ChatGPT).

Grading will be based 20% on these written responses and 10% on in-class participation. We do not allow any late days for paper reactions, but students may skip two paper summaries and two lectures without penalty. We will take class attendance. However, participation grades are based on not only attendence, but active participation during class discussion.

📣 Do not underestimate the amount of time required to properly read and process a research paper. Expect to spend several hours preparing for each section.

🧑‍🏫 Topic Presentation (15%)

While reading formative papers helps to demonstrate how a subfield started, it oftentimes leaves us wondering how the area has evolved. To fill this gap, each student in the class will present one recent paper during the quarter topically relevant to that day's class. At the start of the quarter, students will have the opportunity to sign up for the topic/date that they want to present their paper.

Students are expected to perform a literature search and to select a paper that was published in the last three years from a top-tier venue in security (e.g., IEEE Security and Privacy, USENIX Security, ACM Computer or Communication Security) or adjacent field (e.g., CHI, NSDI, ASPLOS, PLDI, SIGCOMM, etc.). Be wary of other publications from IEEE, most are not top-tier venues and papers will not be accepted for presentation.

⚠️ Student presentations must be 10-12 minutes and allow for 2-5 minutes of questions. We will cut presentations off at 12 minutes, which will impact your presentation grade. Be prepared to answer questions about the paper you present.

⚠️ Students must submit their papers to approval to the teaching staff a minimum three days prior to their presentation.

🔬 Course Project (55%)

Students will complete a quarter-long original research project in small groups (1–3 students) on a topic of their own choosing. Groups will present their work during the last two sections as well as submit a 6–10 page report, similar to the papers we read in the course.

Projects have four graded components:

  • Project Proposal (5%). Project groups will meet with course staff to discuss their project during the third week of class and submit a one page project proposal. Reports must include a complete Introduction, and Related Work section. Due 10/14.
  • Mid-Quarter Progress Report (5%). Submit a short (1–2 pages) progress report part way through the quarter. The report should indicate what has been accomplished, what work is remaining, obstacles the team has encountered, and any preliminary data or insights. Reports must include a complete Abstract, Introduction, Methodology, and Related Works section. Due 11/20 (11:59 PM PT).
  • Class Presentation (10%). Each group will give a 15 minute class presentation during the last week of the course.
  • Final Paper (35%). Groups will submit a final project report similar to the papers we read in the course. Papers should be 6–10 pages. Papers must include Abstract, Introduction, Related Work, Methodology, Results and Discussion/Conclusion. Due 12/11 (11:59 PM PT).

All written submissions related to the course project are to be written in paragraph form, in English, using LaTeX, and submitted in PDF form, inline with the examples provided at the start of the quarter. Submissions must use the USENIX LaTeX template. We strongly encourage you to read Writing Technical Articles if you haven't previously published academic research work in computer science.

⚙️ Administrivia

Students should submit all reports through Gradescope by classtime at 10:30 am on the day of each deadline.

In past offerings, well-executed projects have led to publications at top-tier security conferences and workshops. The teaching team is happy to work with groups to publish their work.

All submitted work for this course must by directly written by the submitting student(s). Using generative AI tools to read papers or generate reading responses is prohibited. Using AI tools to assist with research project implementation, proofread paper submissions, or battle-test ideas is acceptable. Students must describe their usage of AI in any submission where it is utilized and are responsible for the accuracy of the results in their submissions.

Attendance on 11/30 and 12/2 is required for all students. This class has no final exam.

Stanford as an institution is committed to the highest quality education, and as your teaching team, our first priority is to uphold your educational experience. To that end we are committed to following the syllabus as written here, including through short- or long-term disruptions, such as public health emergencies, natural disasters, or protests and demonstrations. However, there may be extenuating circumstances that necessitate some changes. Should adjustments be necessary, we will communicate clearly and promptly to ensure you understand the expectations and are positioned for successful learning.