Lectures
Invited speakers give talks on cybersecurity topics every Tuesday. Everyone is welcome: you don't need to be registered for the lab's courses to attend.
- Time
- Tuesday, 15:30 – 17:00
- Location
- Kiberlab / Teams
-
Next
Information security as a management system I
Legal requirements relating to information security. Information security of state and local government bodies (Act XXIII of 2023; Regulation (EU) 2016/679 of the European Parliament and of the Council – GDPR). ISO Management System Standards.
Speaker: István Giesz Location: Teams
-
Next
Foundations of information security
Introduction to information security. Interpreting IT security. IT security as a business requirement.
Speaker: Attila Kovács Location: KiberlabTeams
-
Next
Perimeter defence technologies
Perimeter defence technologies and their operating principles: packet filters and their types. Bastion hosts, SOCKS, proxies, transparent and modular proxies. Related technologies: VPN, authentication, content filtering.
Speaker: Bálint Kovács Location: KiberlabTeams
-
Next
Information security management system II
Standards and recommendations: RfC, IETF, IEEE, ISO, NIST, MSZT. The ISO/IEC 27000 family of standards (27001, 27002, 27003):2022. The NIST Special Publication 800 Series Security Guidelines – NIST SP 800-53r4 – and a few other useful SPs. Management systems: COBIT5 – CC / ISO/IEC 15408 – ITIL / ISO/IEC 20000.
Speaker: István Giesz Location: Teams
-
Next
Intrusion detection and prevention
Network security events and their detection. Intrusion Detection and Intrusion Prevention systems (IDS, IPS, nIDS, etc.). Other detection options (honeypot / honeynet, darknet, etc.). Case study.
Speaker: Tamás Horváth Location: KiberlabTeams
-
Next
Document security
Access control and digital signatures. Security rules applying to employees. Electronic signatures and signature verification. Fundamentals of public key infrastructure, main components (CA, RA, directory). Building a PKI hierarchy, registration methods and procedures. The contents of a certificate, its main fields, the analysis of a concrete certificate. Revocation checking: OCSP, CRL. Timestamps. Key storage devices, key management (HSM and CMS systems). PKI-related policies (CPS, CP, subscriber agreement). A few practical examples and applications (email encryption, electronic company procedures, e-invoicing).
Speaker: Tamás Kovács Location: KiberlabTeams
-
Next
Operational security
Log processing and analysis. The purpose of logging. Logging protocols. Standard log formats. Log analysis (on-the-fly / periodic, correlation analysis). Incident management. Definition, types and risks of network security incidents. The incident handling process (from gathering information through blocking to restoring the systems). Business continuity.
Speaker: István Giesz Location: Teams
-
Next
The topic will be announced later
-
Next
Anti-virus protection
Why computer viruses are written and distributed, and how they spread. What should we defend against? Viruses, trojans, worms and their relatives. How should we defend ourselves? The structure of defence systems, defence points, the architecture of anti-virus systems.
Speaker: Gábor Szappanos Location: KiberlabTeams