courses

CS 410/510: System Administration and DevOps

Location: FAB 47 (MW 09:15-11:35)

Instructor: D. Kevin McGrath


Recordings

While not all lectures will be recorded, some will be. You will likely have to login to your PDX MediaSpace account to view these.

Weekly Schedule

The course is a single continuous build: each week hardens, scans, or instruments the lab environment so that the next week has something to defend, detect, or attack. Every week is two sessions; click a week for the full walkthrough, and use the linked reference pages for the background theory.

Week 1 — Infrastructure as Code and Threat Modeling

Establish the two foundations the rest of the course builds on: a reproducible, version-controlled environment, and a threat model that explains why every later control matters. You cannot harden what you haven’t defined.

Session Focus Reference reading
1 · Infrastructure as Code Terraform, declarative/idempotent provisioning, the Proxmox lab, baseline snapshots Infrastructure as Code
2 · Threat Modeling with STRIDE STRIDE, data flow diagrams, threat scoring, the DVWA target system Threat Modeling · DevSecOps Fundamentals

Week 2 — OS Hardening and Secrets Management

Reduce the attack surface of the freshly provisioned Ubuntu server — removing what isn’t needed, locking down what remains — then replace plaintext credentials with a proper secrets manager.

Session Focus Reference reading
3 · Linux OS Hardening Attack-surface mindset, SSH lockdown, service minimization, SUID auditing, sudo-rs, fail2ban OS Hardening
4 · Secrets Management with OpenBao Why env vars aren’t enough, OpenBao’s security model, policies, dynamic vs. static credentials OpenBao · CI/CD, Secrets, and GitOps

Week 3 — Container Security I: Threat Model and Image Hardening

Understand what containers actually isolate (and what they don’t), harden the DVWA and nginx images, and apply runtime constraints that limit what a compromised container can do.

Session Focus Reference reading
5 · Container Threat Model & Image Hardening Isolation boundaries, the DVWA threat surface, Dockerfile hardening, non-root execution, layer inspection for secrets Containerization · Container Security
6 · Container Runtime Hardening Defense in depth, Linux capabilities, seccomp syscall filtering, the Compose file as security policy, network segmentation Container Security

Week 4 — Container Security II: Scanning, Supply Chain, and Monitoring

Look inside the containers — scanning for known CVEs in OS packages and dependencies — and bring the Wazuh agent online so everything from here on is observed.

Session Focus Reference reading
7 · Image Scanning & Supply Chain The software supply chain, CVSS scoring, Trivy scanning and triage, the SBOM Vulnerability Management · Container Security
8 · Networking, Secrets Integration & Wazuh Agent Secrets in containers done right, verifying network isolation, registering the Wazuh agent Wazuh SIEM

Week 5 — Shift-Left Security Tooling

Move detection earlier in the lifecycle: static analysis and secrets scanning at commit time, plus a structured vulnerability-management and host-audit workflow.

Session Focus Reference reading
9 · SAST and Secrets Detection What static analysis is and isn’t, Bandit, Semgrep with custom rules, triage, gitleaks SAST and Secrets Detection · Vulnerability Management · DevSecOps Fundamentals
10 · Vulnerability Management & OS Audit The VM lifecycle, Lynis host-hardening audit, connecting findings to the threat model, patch strategy Vulnerability Management

Week 6 — Policy, Access Control, and Host Firewall

Add the final layer of host-side controls: policy-as-code, least-privilege access, and a host firewall with automated response.

Session Focus Reference reading
11 · Policy-as-Code with auditd & AppArmor What policy-as-code means, auditd framework, Wazuh integration, AppArmor MAC, host-level zero trust OS Hardening
12 · IAM, Firewall, and Automated Response Least privilege end to end, nftables host firewall, fail2ban active response, IAM concepts applied locally Identity and Access Management · Firewalls and IPS

Week 7 — Detection and Monitoring

Build the detection layer on top of the preventive controls: knowing when an attack is happening, what it’s doing, and how to respond.

Session Focus Reference reading
13 · Wazuh Rules, Tuning & Active Response The detection problem, writing and calibrating Wazuh rules, active-response architecture, closing the detection gap Monitoring and Observability · SIEM, SOC, and Threat Detection
14 · Suricata Integration & File Integrity Monitoring Network vs. host detection, Suricata IDS rules, FIM as the last line, correlating detection layers Suricata IDS/IPS · Wazuh SIEM

Week 8 — Incident Response and Capstone

Close the loop: respond to an incident when prevention fails, then prove the whole stack with a red/blue capstone against your own system.

Session Focus Reference reading
15 · Incident Response IR as more than a technical problem, NIST SP 800-61r2 lifecycle, triage, snapshot-before-touching containment, writing a runbook Incident Response · SIEM, SOC, and Threat Detection
16 · Red/Blue Capstone Structured offense, structured analysis, an honest post-mortem, and revisiting the Week 1 threat model Threat Modeling

Pages

Course-specific reference pages

These are not specific to any one lecture, but offer significant reference material that we will use as we move through the course.

Lab environment

Reference pages (background reading by week)

Configuration and Tooling

Other stuff

Homework

Each homework will build on the previous assignment. These aren’t your typical “write answers to questions” type assignments, but rather are intended to be more hands-on. We will be adding to, modifying, or otherwise doing something to the VM environment to enable us to do something else. The first assignment will be to get the VM environment set up and configured. Subsequent assignments will build on this.

Submission

All work will be submitted via MarkDown documents within an internal gitlab repo. You will be using this repo for the rest of the term. This repo exists on the CECS intranet. You will need to add the TA and me to this repo as Developers. Grades and feedback will be done via a merge request from the TA.

Assignments

Evaluation of Student Performance

This course uses a weighted average of assignments. All assignments will be graded out of 100 points, with the following weights towards the final grade:

Letter Grade

Letter grades will be assigned based on standard ranges with (optionally) +/- steps.

Grade Percent Range
A 90-100
B 80-90
C 70-80
D 60-70
F <60

Course Policies

Late Work Policy

No late work will be accepted without prior discussion. I understand that life happens, but request for late hand-in must be submitted prior to the due date. Permission will be granted dependent upon reasons, current state of completion, etc.

Incompletes

Incomplete (I) grades will be granted only in emergency cases (usually only for a death in the family, major illness or injury, or birth/adoption of a child), and if the student has turned in 90% of the points possible AT THE TIME OF REQUEST. In other words, if you have been keeping up, but a major life event occurs, let me know as soon as possible. If you are having any difficulty that might prevent you completing the coursework, please don’t wait until the end of the term; let me know right away.

Academic or Student Support Services

Accommodations

Accommodations for students with disabilities are determined and approved by Disability Resource Center (DRC). If you, as a student, believe you are eligible for accommodations but have not obtained approval please contact DRC immediately at 503-725-4150, drc@pdx.edu, or https://www.pdx.edu/disability-resource-center. DRC notifies students and faculty members of approved academic accommodations and coordinates implementation of those accommodations. If you have accommodations through DRC and wish to take the Midterm or Final Exam in the testing center, I strongly recommend that you schedule it before the end of week 1. If you are not registered with the DRC, you cannot register to take an exam in the testing center.

I want to make this class an open and welcoming environment for all. Your success is my goal.

Religious Observance

Portland State University strives to respect all religious practices. If you have religious holidays that conflict with any of the requirements of this class, please see me immediately so that we can make alternative arrangements.

Reach Out for Success

The PSU Center for Student Health and Counseling (SHAC) is staffed with folks who care and can help with a wide range of personal challenges. Here at PSU, there is never a need to tough things out alone.

As a student you may experience a range of issues that can cause barriers to learning, such as strained relationships, increased anxiety, alcohol/drug problems, feeling down, difficulty concentrating and/or lack of motivation. These mental health concerns or stressful events may lead to diminished academic performance or reduce a student’s ability to participate in daily activities. PSU is committed to advancing the mental health and well-being of its students. If you or someone you know is feeling overwhelmed, depressed, and/or in need of support, services are available. You can learn more about the broad range of confidential mental health services available on campus via SHAC https://www.pdx.edu/health-counseling/.

SHAC also has resources for physical health, including flu shots. You can check out their COVID-19 resources page here: https://www.pdx.edu/health-counseling/covid-19-resources (including testing).

Get Food Now Here at PSU, there is never a need to tough things out alone. Those who can, give, so those who need, have.

Housing / financial crisis help Here at PSU, there is never a need to tough things out alone. Emergency Housing, etc.

Title IX

As an instructor, students frequently come to me for assistance in matters that are not related to the course material. Please be aware that PSU’s policies require instructors to report any instance of sexual harassment, sexual and relationship violence and/or other forms of prohibited discrimination to University Officials, who keep the information private. If you would rather share information about these experiences with a PSU staff member who does not have these reporting responsibilities and can keep the information confidential, please contact one of the following campus resources.

PSU Sexual Misconduct Response website gives you comprehensive information about how to support and/or report an incident.

Please complete the required student module Understanding Sexual Misconduct and Resources in Canvas, which provides information about PSU policy and resources.

You may also report sexual and relationship violence to law enforcement on campus with Campus Public Safety Office (CPSO)

Or you may file an anonymous report with Campus Public Safety Office or a Bias Incident report with the Bias Review Team (BRT). PSU does not typically investigate the reports that are made through these two avenues. These reports help PSU understand what students and employees are experiencing on and around campus and provide support where needed.