📧 hipravat@gmail.com Support

Computer Science and Information Technology

Course: CS818 — Doctoral Program in Computer Science (Cybersecurity & Information Assurance) Focus Area: Foundational CS Theory, Systems, Security, AI/ML, and Cloud Computing


Overview

This course provides a doctoral-level survey of core computer science and information technology domains — from the theoretical foundations of algorithms and computability, through operating systems, networking, databases, software engineering, computer graphics, artificial intelligence, and cloud security. All topics are examined through the lens of applied research in cybersecurity.


Computability and Algorithm Complexity

Functions and Computation

Computer science at its core asks: what can and cannot be computed?

  • Computable functions can be expressed as a well-defined, step-by-step algorithm
  • Noncomputable functions — no algorithm exists to determine outputs for all inputs; the halting problem is the canonical example

Turing Machines

Turing machines define the theoretical boundary of computation:

  • A Turing machine reads symbols on a tape, transitions between states, and writes new symbols
  • Any function computable by a modern computer can be computed by a Turing machine
  • The halting problem — predicting whether any given program will terminate — is undecidable and cannot be solved by any algorithmic system

The Bare Bones Language

A minimal imperative programming language that can express all Turing-computable functions using only: - Variables (non-negative integers as bit patterns) - Three assignment statements - One loop control structure (while)

This illustrates that computational power does not require complexity — minimalism can be Turing-complete.

Algorithm Complexity

Complexity measures how resource requirements (time, space) scale with input size.

Notation Meaning
Big-O (O) Upper bound — worst-case growth rate
Big-Theta (Θ) Tight bound — exact growth rate

Time complexity counts execution steps, not lines of code.

Algorithm Complexity Example
Binary Search O(log n) Finding a value in a sorted list
Merge Sort O(n log n) Efficient sorting
Bubble Sort O(n²) Naive sorting
Brute-force TSP O(n!) Traveling Salesperson Problem

P vs. NP

Class Description
P (Polynomial) Tractable — solvable in polynomial time
NP (Nondeterministic Polynomial) Verifiable in polynomial time; may not be solvable quickly
NP-Complete Hardest problems in NP; if one is solved in P, all NP problems are
Intractable Cannot be solved in reasonable time for large inputs

Open question: Does P = NP? The most important unsolved problem in theoretical computer science.

Heuristic approaches — for intractable problems, approximation algorithms find "good enough" solutions (e.g., greedy algorithms for TSP).

Advanced Persistent Threats as a High-Complexity Problem

APTs exemplify computational complexity in cybersecurity: - Multiple attack stages with branching decision paths - Customized exploits targeting specific vulnerabilities - Prolonged undetected presence (months to years) - Countermeasures: SIEM platforms, behavioral analytics, AI-based anomaly detection


Operating Systems

History and Evolution

Era Technology Key Development
1940s–1950s Mainframes Manual program setup; no OS
1960s Batch processing Job queues (FIFO); job control language (JCL)
1970s Time-sharing Multiple users; interactive processing via terminals
1980s–1990s Personal computing Single-user multitasking; GUI interfaces
2000s–present Cloud & mobile Multiprocessor, distributed, networked OS

Core OS Functions

  • Process management — Scheduling, dispatching, preventing interference between processes
  • Memory management — Allocation, virtual memory, paging
  • File management — Storage organization, access control, persistence
  • Device drivers — Hardware abstraction layer
  • User interface — CLI and GUI interaction
  • Security — Authentication, privilege levels, access control

Multitasking and Time-Sharing

Multiprogramming creates the illusion of concurrent execution: - Multitasking (single user) — OS switches rapidly between processes - Time-sharing (multi-user) — CPU time is divided across users to ensure responsiveness

OS Comparison

OS Strengths Weaknesses
Windows Familiar UI; broad software compatibility; enterprise support Licensing cost; more vulnerable to malware; resource-heavy
macOS Seamless Apple integration; strong security; optimized hardware Expensive hardware; limited customization; restricted compatibility
Linux Free, open-source; highly secure; highly customizable Steeper learning curve; less centralized support; some compatibility gaps

Server OS Effectiveness

Windows Server: Integrates with Active Directory; familiar to Windows admins; strong enterprise support Linux Server: Preferred for web servers, databases, and cloud infrastructure due to low cost, stability, and security

OS Security Vulnerabilities

Malware and Ransomware - Viruses, worms, trojans, spyware encrypt or destroy files - Ransomware locks access and demands payment — disrupts operations and causes reputational damage

Zero-Day Vulnerabilities - Flaws unknown to the vendor — no patch exists at time of discovery - High-risk targets: Windows 10/11, Android (11–13), Windows Server 2012, Debian Linux

Most Vulnerable OS Versions (CVSS 7–10): Windows 10, Windows 11, Android 11–13, Windows Server 2012, Debian Linux 10/11, Fedora 37, HarmonyOS 2

Mitigation Strategies: - Enforce least-privilege access - Multi-factor authentication (MFA) - Patch management cadence - Endpoint detection and response (EDR) tools - Built-in CPU security features (hardware-enforced isolation)


Communication Protocols

Web Protocols and Their Security Roles

Protocol Purpose Security Mechanism
HTTP Data exchange between browser and server None — plaintext
HTTPS Secure HTTP TLS/SSL encryption; Certificate Authority validation
DNS Translates domain names to IP addresses None inherently
DNSSEC Authenticates DNS responses Digital signatures prevent spoofing/cache poisoning
FTP File transfer None — plaintext
SFTP Secure file transfer SSH encryption
SMTP + STARTTLS Secure email transmission TLS upgrade for email channels

HTTPS in Depth

  1. Browser sends HTTPS request to server
  2. Server presents TLS certificate (issued by a Certificate Authority)
  3. Browser verifies certificate authenticity
  4. TLS handshake establishes encrypted session parameters
  5. All subsequent data is encrypted — protected against eavesdropping, tampering, and man-in-the-middle attacks

CDN Security Role

Content Delivery Networks (CDNs) distribute assets globally, improving performance and providing DDoS protection by absorbing volumetric attack traffic before it reaches origin servers.

Impact of Network Loss

The COVID-19 pandemic demonstrated network dependency across every sector:

  • Business — Remote work, video conferencing, e-commerce, cloud services would have been impossible without connectivity
  • Education — Online platforms (Zoom, Google Classroom) sustained learning continuity
  • Healthcare — Telemedicine replaced in-person consultations; vaccination data shared in real-time
  • Government — E-governance services maintained during lockdowns
  • Mental health — Social connectivity via online platforms reduced isolation impact

Algorithms and App Development

Algorithm Design Lifecycle (App Development)

  1. Ideation & Research — Define the problem; market analysis; set measurable goals
  2. Planning — Feature list; technology stack; timeline and budget
  3. Design — Wireframes → UI/UX design → interactive prototype
  4. Development — UI layer → backend/API → database integration → testing (unit, integration, UAT)
  5. Deployment — Containerize with Docker; push image to artifact registry; deploy to target platform
  6. Operations — Monitor performance; collect user feedback; release patches

Cybersecurity Algorithm Complexity

APTs require multi-step detection algorithms with high branching complexity: - Threat vector identification (branching per attack type) - Anomaly scoring across behavioral baselines - Correlation across SIEM event streams - Automated escalation or remediation decisions

Modern solutions: ML-powered SIEM, behavioral analytics, automated threat intelligence feeds


Security Issues and Prevention

Principal Software Vulnerabilities

SQL Injection - Attacker inserts SQL code into user input fields to manipulate database queries - Can read, alter, or delete data; execute OS commands - Detection: Static code analysis; penetration testing; ML classifiers (Naïve Bayes, decision trees, deep neural networks) - Mitigation: Parameterized queries / prepared statements; input validation; ORM frameworks

Cross-Site Scripting (XSS) - Malicious scripts injected into web pages viewed by other users - Mitigation: Output encoding; Content Security Policy (CSP) headers; input sanitization

Insecure Data Storage - Sensitive data stored without encryption or proper access controls - Mitigation: Encrypt data at rest (AES-256); enforce access control; audit storage configurations

Security-First Development Principles

  • Embed vulnerability assessment into the SDLC — not as an afterthought
  • Use static analysis tools (SAST) and dynamic analysis tools (DAST) at every build stage
  • Conduct regular penetration testing with both automated tools and manual consultants
  • Apply least-privilege access at the application, database, and OS layers

Software Development Frameworks

Framework Comparison

Framework Approach Best For Key Strength
Agile Iterative (sprints ~2 weeks) Evolving requirements; customer-driven Flexibility; fast delivery; continuous feedback
Waterfall Sequential (phase-gated) Stable, well-defined requirements Predictability; documentation; regulatory compliance
Kanban Continuous flow Ongoing maintenance and support Visual workflow management; limit WIP
Lean Waste elimination Efficiency-focused teams Maximize value; minimize non-essential work

Choosing the Right Framework

  • Agile — Use when requirements will change; customer collaboration is possible; fast time-to-market is critical
  • Waterfall — Use when requirements are fixed; documentation is mandatory (healthcare, government, defense)
  • Cybersecurity projects often benefit from Agile for threat response tools, Waterfall for compliance-driven security audits

Open-Source Software

Open Source vs. Licensed Software

Dimension Open Source Licensed/Proprietary
Cost Free (hidden costs: customization, support) License fee (includes support, updates)
Customization Fully customizable (source code access) Limited; may cost extra
Support Community-driven; paid options available Vendor-backed; reliable professional support
Security Rapid community patching; vulnerabilities publicly visible Closed source; vendor-controlled patch timing
Compliance License terms require legal review (GPL, MIT, Apache) Clear vendor licensing terms

Open Source in Cybersecurity and AI

  • Cybersecurity: Open-source tools (Snort, OSSEC, OpenVAS) enable rapid vulnerability identification through global community peer review
  • AI/ML: Open frameworks (TensorFlow, PyTorch, Hugging Face) accelerate research and deployment — enabling organizations to build, share, and improve models without vendor lock-in
  • Tension: Transparency that enables rapid security improvement also exposes vulnerabilities to malicious actors — balance between openness and security protocols is essential

Data Storage and Manipulation

Data Compression

Lossless Compression — All data preserved; exact reconstruction guaranteed - Examples: ZIP, PNG, GIF - Used for: Code, documents, archives

Lossy Compression — Some data discarded for higher compression ratio - Examples: JPEG, MP3, MPEG - Used for: Images, audio, video where perceptual accuracy is sufficient

Compression Algorithm Comparison

Algorithm Compression Ratio Speed Best For
Brotli Excellent Moderate Web assets (HTML, CSS, JS)
7-Zip Highest Slow Long-term archiving
LZ4 Moderate Fastest Real-time, in-memory compression
WinZip Good Fast General purpose; balanced

Size Reduction Formula: Size Reduction = 1 - (1 / Compression Ratio)

WAN Optimization via Reference Indexing

A novel approach for optimal data transfer across Wide Area Networks:

  1. Analyze source data at the byte level
  2. Compare chunks to a reference database — generate metadata pointers instead of transmitting raw data
  3. Compress metadata using lossless techniques
  4. Transmit compressed metadata (significantly smaller than original)
  5. At destination, decompress and reconstruct using the reference table

Key advantage: Particularly effective in bandwidth-constrained environments; more flexible than traditional deduplication

Dissertation Topics in Data

  1. WAN Optimization — Reference indexing for efficient data center-to-data center transfer
  2. Real-Time Data Manipulation and Cybersecurity — AI-driven detection of data tampering in live streams
  3. Blockchain for Secure Data Storage — Immutable, distributed ledger for data integrity assurance

Databases

Relational Databases (RDBMS)

  • Data organized in tables with predefined schemas
  • Relationships enforced through foreign keys
  • Query language: SQL
  • ACID properties: Atomicity, Consistency, Isolation, Durability
Database Strengths Common Use Cases
MySQL Open-source; fast; widely supported Web apps (WordPress, e-commerce, YouTube)
PostgreSQL Advanced SQL; extensible; ACID-compliant Complex analytics, financial systems
Oracle Enterprise-grade; high availability Banking, ERP, government
MS SQL Server Windows integration; BI tools Enterprise applications, .NET stacks

NoSQL Databases

Designed for unstructured data, horizontal scalability, and high availability in distributed environments.

Type Example Best For
Document MongoDB JSON data, content management, catalogues
Key-Value Redis, DynamoDB Sessions, caching, real-time leaderboards
Column-Family Cassandra Time-series, IoT, write-heavy workloads
Graph Neo4j Social networks, fraud detection, knowledge graphs

Data Abstraction Levels

Level Description
Physical How data is stored on disk (files, indexes, pages)
Logical How data is structured (tables, relationships, schema)
View How data is presented to specific users (filtered, role-based)

Abstracting Dissertation Data for Cybersecurity

For AI cybersecurity research, raw data should be abstracted into: - Performance metrics table: Accuracy, false positives/negatives, response time, resource utilization - Threat landscape summary: Attack types, frequency, severity (Critical/High/Medium/Low) - Human-AI interaction themes: Trust levels, expert feedback, adoption barriers

Presentation tools: Bar charts (model accuracy comparison), line graphs (response time trends), thematic tables (qualitative interview themes)


Computer Graphics

Core Areas

  • 2D Graphics — Raster (pixel-based: PNG, JPEG) and Vector (math-based: SVG, PDF)
  • 3D Graphics — Modeling, rendering, lighting, texture mapping
  • Animation — Keyframing, motion capture, procedural animation
  • Simulation — Physics engines, particle systems, fluid dynamics

Industry Impact

Film and Entertainment - CGI enables photorealistic environments — Avatar, Jurassic Park, Toy Story - Real-time 3D rendering powers gaming (Unity, Unreal Engine) - Independent filmmakers empowered by accessible digital creation tools

Healthcare - 3D medical imaging (MRI, CT, ultrasound) provides detailed anatomical visualization - Surgical simulation training reduces risk in high-stakes procedures - Digital twins of organs enable personalized treatment planning

Graphics Processing Units (GPUs)

GPUs were designed for rendering but have become the dominant compute platform for AI, science, and data:

Application Why GPU Excels
Deep Learning / AI Massive parallelism for matrix operations and backpropagation
Scientific Computing Fluid dynamics, molecular modeling, particle physics simulations
Data Mining Parallel processing of large datasets
Cryptocurrency Mining High-throughput hash computations

CPU vs. GPU Architecture: - CPU: Few powerful cores (4–64); optimized for sequential, low-latency tasks - GPU: Thousands of smaller cores; optimized for massively parallel workloads

Impact on AI: Training that takes days on a CPU completes in hours on a GPU. NVIDIA's Tensor Core (Volta architecture) specifically accelerates deep learning workloads.


Artificial Intelligence and Machine Learning

AI vs. ML Distinction

Dimension Artificial Intelligence (AI) Machine Learning (ML)
Scope Broad — all intelligent machine behavior Subset of AI — learning from data
Dependency Can exist without ML (rule-based systems) Cannot exist without AI
Goal Emulate human intelligence broadly Learn patterns; improve predictions over time
Approach Rules, reasoning, symbolic logic, ML Data-driven; statistical models
Examples Expert systems, robotics, NLP, computer vision Classification, regression, clustering, deep learning

ML Techniques

Type Description Example
Supervised Learning Trains on labeled input-output pairs Spam detection, fraud classification
Unsupervised Learning Finds patterns in unlabeled data Clustering anomalies in network traffic
Reinforcement Learning Learns by reward/penalty feedback Adaptive intrusion response systems
Deep Learning Multi-layer neural networks for complex patterns Malware detection, image recognition

AI Strengths and Weaknesses

Strengths: - Handles diverse tasks across domains - Excels at decision-making with incomplete information - Versatile — combines NLP, vision, reasoning, and learning

Weaknesses: - Requires significant compute, data, and tuning investment - Most AI is "narrow" — struggles to generalize across unrelated domains - AI trained on biased data produces biased outputs — critical concern in security profiling

AI in Cybersecurity — Dissertation Focus

Identified Gap: Ethical frameworks for AI in cybersecurity are underdeveloped; AI bias leads to unfair security outcomes (over-targeting specific user groups or attack types); zero-day threats remain a persistent challenge.

Proposed Research Topics: 1. Mitigating Bias and Enhancing Ethical Considerations in AI-Driven Cybersecurity Systems 2. Explainable AI (XAI) in Cybersecurity for Enhanced Threat Detection and Response

Research Methodology: - Review literature on AI threat detection, focusing on zero-day attacks - Develop a GAN-based cybersecurity framework — one network generates attack strategies, another detects them - Test against real-world cybersecurity datasets; compare to existing AI-based intrusion detection systems

Expected Contributions: - New methodology for integrating explainability into AI threat detection - Framework for human-AI collaboration in SOC environments - Adaptive security architecture that evolves with emerging threats


Cloud Computing and Security

Cloud Computing Fundamentals

Cloud computing delivers on-demand compute, storage, and networking resources over the internet — adaptable, durable, and cost-efficient.

Service Models: | Model | Description | Examples | |---|---|---| | IaaS | Infrastructure — VMs, networking, storage | AWS EC2, Azure VMs | | PaaS | Platform — runtime, middleware, databases | AWS RDS, Google App Engine | | SaaS | Software — complete applications | Salesforce, Google Workspace |

Deployment Models: Public, Private, Hybrid, Multi-Cloud

Cloud Security Challenges

The shared responsibility model — cloud provider secures infrastructure; customer secures their data, applications, and access — creates potential gaps when responsibilities are unclear.

Top Cloud Security Issues:

1. Data Breaches - Unauthorized access to sensitive information (PII, financial data, IP) stored in distributed cloud infrastructure - Causes: Misconfigured storage buckets, weak IAM policies, unpatched vulnerabilities - Dissertation research angle: AI-powered detection and prevention methods for cloud data breaches - Methodology: Quantitative analysis of breach incident data + AI/ML detection models

2. Insecure APIs - APIs are the primary interface for cloud-to-cloud and application-to-cloud communication - Vulnerable APIs expose backend systems to unauthorized access, data exfiltration, and injection attacks - Mitigation: OAuth 2.0 authentication, API key validation, rate limiting, Apigee API gateway security policies, mutual TLS

Cloud Security Research Potential

Each issue can be developed into a dissertation:

  • Data Breach Research: Develop AI-powered intrusion detection for cloud environments; evaluate detection accuracy, false positive rates, and response times
  • API Security Research: Propose ontological framework for cataloging and mitigating cloud API vulnerabilities dynamically

Course Summary and Key Takeaways

  1. Computability defines limits — Understanding what computers cannot do is as important as what they can; the halting problem remains unsolvable

  2. Operating systems are the security foundation — Patch management, privilege enforcement, and multi-factor authentication must be built into OS strategy, not bolted on

  3. Protocols enable and protect communication — HTTPS, DNSSEC, SFTP, and TLS are not optional for any production system handling sensitive data

  4. Algorithm complexity drives architectural decisions — Choosing the right data structure and algorithm class (P vs. NP-hard) determines whether a system scales

  5. Open source accelerates innovation but requires governance — Transparency is a double-edged sword; security policies must accompany open adoption

  6. Databases are not one-size-fits-all — RDBMS for transactional integrity; NoSQL for scale and flexibility; choose based on data structure and access patterns

  7. GPUs transformed AI — The shift from CPU to GPU computing made modern deep learning possible; hardware architecture is inseparable from AI capability

  8. AI in cybersecurity requires ethics and explainability — Biased models produce unjust outcomes; XAI is not optional when AI drives security decisions

  9. Cloud security is shared — Understanding the boundary between provider and customer responsibility is the first step in building a secure cloud architecture

  10. Every topic connects to the dissertation — Each CS domain informs the research on AI-driven cybersecurity — from algorithms that detect APTs, to databases that store threat intelligence, to cloud platforms that host AI models


References

  • Brookshear, J. G., & Brylow, D. (2018). Computer Science: An Overview (13th ed.). Pearson.
  • Russell, S., & Norvig, P. (2021). Artificial Intelligence: A Modern Approach (4th ed.). Pearson.
  • Silberschatz, A., & Galvin, P. (1998). Operating System Concepts. Wiley.
  • Patterson, D., & Hennessy, J. (2016). Computer Organization and Design. Morgan Kaufmann.
  • Stallings, W. (2003). Data and Computer Communications. Prentice Hall.
  • Fuggetta, A. (2003). Open source software — An evaluation. Journal of Systems and Software, 66(1).
  • Ali, M., Khan, S. U., et al. (2015). Security in cloud computing: Opportunities and challenges. Information Sciences, 305.
  • Zhang, W., Li, Y., et al. (2022). Deep learning for SQL injection detection. Computers & Security.