ECED4406 - Computer Security
Last updated
For active students, the class primarily uses Brightspace at https://dal.brightspace.com.
Material for my ECED4406 class is available on the ECED4406 GitHub. This includes slides, labs, etc. THIS MATERIAL MAY NOT BE ACCURATE FOR THE CURRENT ACADEMIC YEAR
Lectures from the 2020 edition are on YouTube. The 2020 edition was online-only, so some labs and other items changed in 2022 and later editions of the course.
What the course covers
ECED4406 is about the security of embedded systems: IoT devices, cars, and the small computers inside everything else. It covers both sides:
- How to secure them: what cryptography gives you, authentication, roots of trust and secure boot, threat modelling, and how security is rated.
- How to break them: reverse engineering hardware and software, reading out firmware, fuzzing, and hardware attacks, both non-invasive (side channels) and invasive (fault injection).
It deliberately isn’t about web security (HTTPS, SSL), designing cryptographic algorithms, or desktop application security. You should already be comfortable with RAM and ROM, stack frames, registers, and matrix multiplication.

Lab 1’s target: a Tapo C200 camera. The 8-pin chip at the upper left is the SPI flash that holds its firmware; reading it out is where the lab starts.
Lectures
The slides are PowerPoint files, numbered in hex.
0x100: Foundations
- 0x100 Introduction to the Introduction: what the course is (and isn’t) about, how it’s run, and an example of a recent in-scope attack. PPTX
- 0x101 Security in History, Basic Ciphers: the scytale, Caesar and ROT-13 ciphers, code books, ciphers captured from U-110, and number stations. PPTX
- 0x102 What is Computer Security: learning from failures, from the early hackers of the late 1980s through United States v. Elcom, the Target breach and Stuxnet, to the 2025 Nova Scotia Power breach. PPTX
- 0x103 What is Computer Safety: Therac-25, Toyota’s unintended acceleration and the 737 MAX; an engineer’s duty, functional safety (IEC 61508), MISRA C, and aggressive testing. PPTX
- 0x104 Code Fuzzing: a web form fuzzed into SQL injection, then mutation-based, generation-based and evolutionary fuzzing, and what’s worth fuzzing. PPTX
- 0x105 Engineering Ethics & Computer Security: disclosure and its timelines, what companies worry about, bug bounties, and the law (the DMCA, Canada’s Bill C-11). PPTX
- 0x106 What are Embedded Computers: IoT, automotive and wireless systems, and the attack vectors each one opens up, including software-defined radio. PPTX
- 0x107 Threat Modelling: assets, attackers, attacks and countermeasures; attack trees, scoring attack paths, and CVSS. PPTX
0x200: Hardware reverse engineering
- 0x201 Reverse Engineering: what FCC ID filings and internal photos give away, finding firmware updates, binwalk, and what a typical IoT board looks like. PPTX
- 0x202 Reading Out Firmware: where firmware lives on a board, JTAG and SWD, and reading out SPI flash and eMMC chips. PPTX
- 0x203 Embedded Linux and Android: from a serial console to a root shell through U-Boot (including pin2pwn), and unpacking, modifying and re-signing an Android firmware update. PPTX
- 0x204 Protocols: logic levels, asynchronous serial and RS-232, SPI, I2C, and differential signalling (LVDS), with worked examples. PPTX
- 0x205 Scopes: a tutorial on oscilloscopes: probes and why they’re 10:1, timebase, vertical settings, and triggering (and why not to rely on the Auto button). PPTX
0x300: Cryptography
- 0x301 What Security Gives Us: confidentiality, integrity, availability and non-repudiation, each with real attacks: AES-CBC bit flipping, replay, hash collisions, TOC/TOU, and IoT botnets. PPTX
- 0x302 Authentication: storing passwords (hashes, rainbow tables, salt), shared-key challenges, MACs, and public/private key signing. PPTX
- 0x303 Symmetric Encryption and AES: block vs. stream ciphers, AES, why ECB mode fails on an image, CBC and counter mode, and nonce reuse. PPTX
- 0x304 RSA Introduction: public-key cryptography, why factoring is hard, RSA-CRT and its fault attacks, and what quantum computers change. PPTX
0x400: Software reverse engineering
- 0x401 Reverse Engineering SW: reading compiler output in Compiler Explorer, calling conventions across compilers, and where local variables end up. PPTX
- 0x402 Binary Formats: raw binaries, Intel Hex, and ELF. PPTX
- 0x403 Introducing Ghidra: the decompiler, strings, cross-references and function graphs. PPTX
- 0x404 Identifying Functions: working out what an unknown function does from its callers, its callees and the peripherals it touches. PPTX
- 0x405 Ghidra Embedded Setup: loading raw firmware (a smart lock, the Philips Hue Bridge) with the right processor, base address, memory map, SVD files and interrupt vectors. PPTX
- 0x406 Buffer Overflows and Lab Instructions: smashing the stack on Arm, shellcode vs. return-oriented programming, protections, and the Ozone debugger and ChipWhisperer Jupyter setup for the labs. PPTX
- 0x40A Ghidra Searching: searching program text, scalars and memory, and using memory search to identify cryptographic functions. PPTX
- 0x40B Dynamic Analysis: emulators vs. on-chip debug, J-Link with and without symbols, data breakpoints (breaking on an STM32F3 USART write), and taint analysis. PPTX
0x500: Side-channel attacks
- 0x500 Introduction to Side Channel Attacks: timing, RF (TEMPEST) and power side channels, starting with a timing attack demo. PPTX

The timing attack demo from 0x500, one of four interactive pages written for this module. Demo 2 waits for all four digits, but the scope trace still shows how many were right.
- 0x501 ChipWhisperer Intro for Lab 4: the ChipWhisperer hardware and software, Jupyter, synchronous sampling, and the target boards. PPTX
- 0x502 Cache Timing and T-Tests: using Student’s and Welch’s t-tests to decide whether something leaks, then cache-timing attacks on AES lookups and prime + probe. PPTX

The t-test explorer from 0x502: move the means and the noise, and watch whether the t-statistic calls it a leak.
- 0x503 Power Based Data Dependent Leakage: why driving a bus costs power that depends on the data, demonstrated on an STM32F302. PPTX
- 0x504 Attacking AES with a Single Bit Leakage: how AES works, and how leaking a single bit of its internal state recovers the whole key. PPTX
- 0x505 Attacking AES with Power Analysis: the same attack driven by real power traces, with a difference-of-means attack. PPTX
- 0x506 CPA Examples on Real Targets: correlation power analysis on a smart bulb’s bootloader, a smartphone’s boot loader (by EM), and an AES-NI processor. PPTX

From 0x506: the smart bulb, opened up for the attack. The annotations are not optional reading.
- 0x507 Spectre and Meltdown: cache timing meets branch prediction and speculative execution, and how that leaks memory. PPTX

The speculative execution tutorial for 0x507: how one byte read on a mispredicted path picks which cache line gets touched.
0x600: Fault injection
- 0x600 Fault Injection: what glitches do to code flow, cryptography (RSA-CRT, differential fault analysis) and buffer reads; why they happen (metastability); clock, voltage and electromagnetic glitching; and countermeasures in hardware and software. PPTX

From 0x600: the PicoEMP as a low-cost EMFI tool.
Interactive tools
Four single-page tools written for the side-channel module. Download one and open it in a browser:
- Timing attack demo
- T-test timing leakage explorer
- Cache lookup visualizer
- Speculative execution tutorial
Labs
- Lab 1: reading the SPI flash out of the camera above with flashrom, using a Raspberry Pi Pico as the SPI programmer. The folder has high-resolution photos of the board for answering the lab’s questions.
- Lab 4: power analysis for password bypass, as a ChipWhisperer Jupyter notebook: connect to the ChipWhisperer, find the leak, attack one character, then the whole password.
- Ghidra setup: an easy Windows install that bundles the JRE, a setup video, and an example password-check firmware for the STM32F303 (with an ELF that includes debug symbols, plus the SVD file).
The labs from the 2020 to 2023 editions are also in the repository, as PDF and Word: hash collision timings, AES timings, firmware analysis in Ghidra, and power analysis of a password check.