Georgia Tech Creates Cybersecurity Master’s Degree Online for Less Than $10k
news.gatech.edu
news.gatech.edu
I'd love if there were a CS masters that either let you apply directly or complete a specification to get automatic admission. Perhaps after completing foundational courses with a B average. That would greatly increase access and should be sufficient to weed out unprepared candidates.
Why shouldn't it be? I don't see why 3 years worth of miscellaneous classes and 1 year worth of classes toward a major (not even necessarily in computer science) should be a prerequisite for a cybersecurity program, or for any masters program for that matter. It just seems like another part of the false mythology of undergraduate education. And I'm sure the people running these credential rackets realize that allowing students to cut to the point would put an end to their gravy train.
Those years for the bachelor don't just prove you learned some random subjects. They also show that you deliver - you have a topic, you study it, you pass the exam.
The reason you say "I don't need that" is because you have to pay a crapload of money for those 3 years with a dubious ROI. It's a credential racket because they charge you through your nose. And it's cheaper now because online is cheaper. But it's unrealistic to assume you get the same quality for less money, it would sink their normal masters business right? Lots of things are debatable here especially if you dig into the exceptions but generally it might be the difference between takeout/fast food and a good restaurant.
When I see people skipping some degrees and going for the online ones they have to show some damn good practical achievements to convince me that was time worth saving.
I'm pretty sure most of you would refuse to go to a doctor who studied online. Cyber-security can easily turn out to be life or death.
Plenty of people have been admitted to MS programs without a BS/BA when they prove why they're the exception. Serious private sector work fills in the gaps easily. MBA programs are no different.
That's an oddly specific case. But as I said, digging into the exceptions will always find something to support any point of view. I'm looking at the overall situation. In most cases the degree can be compensated with work experience.
> Plenty of people have been admitted to MS programs without a BS/BA [...]
This of course is entirely up to the program. Most PhD programs require both, some require only one. What I said is that I (personally) see this as a natural progression. Skipping one will have to come with a damn good reason attached. Like exceptional performance otherwise.
> MBA programs are no different.
Again, personal opinion, I trust the MBA program the least of all. I have seen so many people (including a lot of colleagues) dish out several (tens of) thousands of Euros to get an MBA while still in their 20s, with only some mediocre team-leader over 4-5 people for 2 years experience behind them that I simply cannot put any kind of weight in that achievement.
There's a lot of reasons why you wouldn't finish a degree that are valid. Have you considered asking rather than assuming? What if someone had serious depression or social anxiety? You're making a lot of assumptions on being "serious" and it's honestly pretty naive and silly, borderline offensive, and very common in academia.
Pretty sure that's asking, and if you find that _borderline offensive_ then you probably need a little bit thicker skin. If you're applying for a top-tier institution, they are going to look for red flags in your transcript, and not finishing your education, no matter the reason, is a red flag that needs to at least be explored. They aren't going to simply _assume_ you had some legitimate excuse for not finishing because many people don't.
I don't think it's fair for you to call it naive and silly for someone to understand your background. No one is saying that your serious depression or social anxiety isn't a legitimate reason, but it's also something that has to be considered. Academic institutions have a graduation rate to protect, and they aren't keen on letting someone in that is a risk to drop out after a couple of semesters -- no matter the reason.
If depression or social anxiety are holding you back in your life that much, it's time to seek help, by the way. As someone who has experienced the same, that is a really good indication that it has gone past a simple mood thing into a serious medical condition.
Best of luck.
How does that logically follow? Different people have different learning styles and are at different points in their lives and careers. The rigour of the material is orthogonal to the channel of delivery
You're saying that there's no clear benefit for the first option other than personal "learning style"? How does that fare when going head to head with the extremely obvious and objective advantages of the online option? There's always a compromise and if you gain flexibility and money something's gotta give elsewhere.
You're making a huge confusion if you think an online masters is just a channel of delivery for some material. A (good) classic masters is more than the professor handing out the material personally instead of emailing it to you (which they do anyway).
Exactly as you said, online is the option you choose when you no longer afford (time/money) the other one. It's for when you need to tick a box on an application. Otherwise you can easily skip it and substitute with your experience.
As a person with a bachelor, 2 masters, almost a PhD (:D), and a whole host of online courses and degrees I can tell you there's a world of difference between the two types of experience. So I treat those degrees with the corresponding level of respect. And please mind you, I said the degrees, not the degree holders.
I'm not saying that online=bad. But a good classic masters program will invariably be better than a good online masters program. Of course if something's already not up to par (classic or online) it becomes irrelevant by how much it fails.
But if you believe that masters degrees have value beyond signaling, then the thinking is that a formal multi-year undergraduate course of study that ensures a minimum knowledge core on a topic will better prepare you for a formal multi-year graduate course of study on that topic than simply working in the field and acquiring a random assortment of specific skills based on what you needed on the jobs that you took.
* Even to the extent that degrees are just signaling devices, they are still useful because many people with power over your career care a lot about those signals.
* If you choose a useful major, that one-years-worth of your undergraduate education certainly has utilitarian value in preparing you for a related career or for further instruction.
* The other three-years-worth of courses may make you more worldly and well-rounded, but their instructional value is nowhere near the $150,000 you'll pay for them at a private university.
>the thinking is that a formal multi-year undergraduate course of study that ensures a minimum knowledge core on a topic will better prepare you for a formal multi-year graduate course of study on that topic than simply working in the field and acquiring a random assortment of specific skills based on what you needed on the jobs that you took.
* Yes, of course, but this only applies to the quarter of the undergraduate courses that are actually relevant. It doesn’t explain why should you need three years worth of courses in underwater basketweaving or gender studies as a prerequisite to a masters in cybersecurity.
If you're saying that you think people should be able to attend a graduate degree program without an undergraduate degree, then that doesn't really make a whole lot of sense to me. There is a long established precedent that (formal, possibly legal requirements, too?) you must have an undergraduate degree to take the next step in your education.
You either want the formal education or don't -- if you do, then you have to meet the pretty standard requirements.
There are always ways around, and candidates that should be considered based on potential. But some kind of a qualifier, even a certificate, that would allow candidates like myself that would love to be engaged through some kind of qualifier or conditional acceptance would allow more people to get engaged and show their ability and commitment to being successful.
There is a requirement to complete a few foundational courses after you enroll but you still need to be accepted first.
My career is software dev adjacent and I haven't seen college being a limiting factor.
University of Oxford Master’s in Software Engineering
... However, more extensive experience may compensate for a lack of formal qualifications, and a strong, immediately-relevant qualification may compensate for a lack of professional experience.
There are BS/MS, BA/MA, BBA/MBA, and BSL/JD programs (asking others) that do not require a prior undergraduate degree but instead incorporate a same-field undergrad degree into the graduate out professional program, with typically less total coursework and tone in residence than separate programs would require because of right integration.
> Possession of a masters degree indicates you have completed a prescribed course of study.
Yes, but there's no reason that a bachelor's degree needs to be an admission requirements for that to work; it may be a completion requirement, but that doesn't mean it needs to be an admission requirement.
The comment I was replying to was saying, in effect, "I want to be able to earn a graduate degree without having to earn an undergraduate degree".
Those programs sound great. They would allow a person to EARN both the graduate degree and the underlying undergrad.
That comment specifically complained about entrance requirements, so, no, I don't think that is a fair characterization.
I highly doubt that the motivation behind that comment is a desire to audit a masters program.
I suspect that will be stigmatic, or is already.
If that is the case, then why waste $10K on a degree that is no more valuable than "self taught"?
Is an OMS from Georgia Tech more convincing than "I read some books and here's a good portfolio of personal projects" ? It's a hard sell.
The problem I've seen with "I don't need a degree!" people is gaping holes in their self-taught education, missing things that every degreed person learns.
Yes, I'd trust an OMS from Georgia Tech over "I read some books and here's a good portfolio of personal projects". I'd be seriously concerned that the latter missed stuff any MS in the subject should know.
I know people with degrees who have gaping holes in their knowledge.
Remember the old adage "C's get degrees"? You only need to understand 50% of the material (C- grade point average in my country) to get your degree. That's not to mention people cheating or bullshitting their way though their degree. I knew plenty of people at university who were lacking basic skills, but managed to get pulled through by group assignments.
A degree certifies that you've been taught a body of knowledge, not that you've learned a body of knowledge.
Asking self-taught people questions from one domain is exactly the way you won‘t find out if they have skills missing that are necessary.
GT's collective response was always that that wasn't their job. They expected you to pick up {new-js-library} while you were studying.
Their job was to "train you for the last job you'll ever have."
And there's a certain wisdom to that. I can learn a new library -- I'd be unlikely to learn the full networking stack, RDBS internals, the history of hardware / software development, or OS & processor memory handling.
I understand that you are saying any accreditation is better than none. I am just playing devil's advocate with an accreditation alternative to formal education.
Here are the 3 possible curricula for the GT program:
Core: Introduction to Information Security (CS 6035) Information Security Policies and Strategies (PUBP 6725)
Info Security Track: Applied Cryptography (CS 6260) Secure Computer Systems (CS 6238) Network Security (CS 6262) Information Security Lab (CS 6265)
Energy Systems Track: Smart Grids (ECE 8803) Introduction to Cyber-Physical Electric Energy Systems (ECE 8803) Introduction to Cyber-Physical Systems Security (ECE 8803) Computational Aspects of Cyber-Physical Systems (ECE 8803)
Policy Track: Introduction to Information Security (CS 6035) Information Security Policies and Strategies (PUBP 6725) Information and Communications Policy (PUBP 6502) Privacy, Technology, Policy and Law (CS/MGT 6726) Internet and Public Policy (PUBP 6111) Scenario and Path Gaming (INTA 6014) Data Analytics and Security (INTA 8803) Information Policy and Management (PUBP 6501) Challenge of Terrorism in Democratic Societies (INTA 8803 G)
Maybe some people can go really deep into topics when learning by themselves, for me the fact that i need to pass an exam and want a good grade helps a lot to go the extra mile on some of the harder stuff.
So when someone says an Online degree equals "I read some books and here's a good portfolio of personal projects" i honestly get mildly offended.
I speak okayish german. Can definitely understand and work with it, but I think that writing a essay in German for me might be too much. So I've been delaying my MsC until I learn better German, but this will take forever.
Otherwise you'd need to try something like Internationale Medieninformatik at TU Berlin which is in english, but not remote unfortunately. Otherwise maybe the Open University Masters is something for you, or of course the GTech MSc which is quite a bit more expensive though.
https://www.fernuni-hagen.de/mi/studium/msc_informatik/ (German only)
Around 1000€ for the Computer Science Master.
How will this degree appear on my diploma and/or transcript? The name "Online Master of Science" is an informal designation to help both Georgia Tech and prospective students distinguish the delivery method of the OMS program from our on-campus degree. The degree name in both cases is Master of Science in Computer Science.
The point stands that it would be relatively easy to know which version someone completed (you worked in New York but got a masters at Georgia Tech?). I personally believe the value to be roughly equal to a "real" degree.
Compared to the average cost for an online degree from a decent university, I can see a lot of people compromising over only 10K - even if some parts of the program aren't perfect.
Part of the price is GT's credibility. Someone not familiar with security may not be impressed with a portfolio of personal projects.
It’s also a place where marginal people can burrow in or even thrive - either doing policy work (in the form of monk-like transcription of NIST documents), being a gatekeeper for exceptions and reviews, or doing threat intelligence. Figuring out how to measure and hire people is hard, and banks and Federal contracts need to fill thousands of chairs.
The racket of expensive certifications was restricting the talent pool, so these cyber security programs are sort of like a substitution for that. This isn’t going to ever produce real technical leadership — the smart people are ultimately engineers who do interesting security things. IMO it’s a waste of potential — smart kids are bypassing Computer Science or Engineering for a much less rigorous education.
There are some opposing forces at play that students and new grads may not quite understand: Computer Science and Software Engineering (boot camps by extension) are basically branching paths to the same entry entry level job, but where you go beyond that can have a stark difference.
I always ask our interns a few questions about their education when they start. One of the chief complaints for CS students is that they don't learn enough practical knowledge to enter the work force. They talk about people who went to a boot camp or were self-taught, and they always express that those people are much more prepared for a given position. Thus we have students who are looking for SWE courses but are taking a CS curriculum. In my experience, no one bothers to make the distinction until it's too late.
True story that drives this home: Our client hired an intern who didn't think a CS degree was practical. He clearly had gaps in his skill set, but I chalked it up to him being a college junior. He was given a small task to parse some text, and I suggested regular expressions (the programming construct) - something he said he had experience with. He came back to me a hour or so later utterly confused on how people could catch all of the edge cases and branching paths that a small regex can generate. Turns out he hadn't taken formal languages yet. I sat him down to build a DFA and talk regular expressions (the formal language concept) with JFLAP[0], and it blew his mind. That conversation changed his entire outlook on CS degrees.
[0]: http://jflap.org
I took a master's course in cryptography at a university as part of a job perk. The IRL aspect was lectures and office hours sometimes. The professor did not have a great grasp of the English language so I had to work with other students and do extensive internet research to understand things.
I also did one of Udacity's FEND program. It had a Slack channel and pretty cool feedback mechanisms for homework and tests. If the grad school class had that I think I would have enjoyed it more and had greater mastery of the subject.
I think it's past time for us to consider OMS legit instead of automatically second-guessing them.
The FAQ on EdX says the certificate is identical to the on-campus one, it doesn’t mention “online”.
In the UK we have had “distance learning” for a long time (Open University) and there is no stigma attached, OU is probably actually more prestigious than most ex-polys.
[*]Introduction to Graph Design and Theory
[*]Secure Network Design, Theory and Implementation
Introduction to Analog and Digital Signal Processing
[*]Assembly for IA-32 and x86_64
Assembly for PowerPC, MIPS and ARM
[*]C/C++ Programming for Windows, Linux and MacOS
C/C++ Programming for Android, iOS and Embedded Systems
[*]Python Programming
[*]Advanced Python Programming
[*]Automated Testing Theory and Implementation
Advanced Graph Theory
Introduction to Game Theory
Advanced Game Theory
Building Secure Scaleable Systems and Networks
Building Big Data Analytics Systems
[*]Automated Defense and Offensive Systems Theory and Implementation
[*]Information Assurance Policy
[*]Reverse Engineering Windows, Linux and MacOS
Reverse Engineering Mobile Devices and Embedded Devices
Reverse Engineering SCADA Systems
Advanced Analog and Digital Signals Processing
Cryptography for Engineers
[*]Vulnerability Research Theory and Methods
Updated - [*] Core courses.If the individual could make it through the above, they would be very knowledgable, experienced and ready for many of the hard problems in the realm of cyber that employers are wanting in extremely high demand.
Then kernel development, in depth work with creating custom applications that deal with TCP and UDP security and analysis, deep dives into the inner working on how various IoT devices work, building autonomous cyber reasoning systems, automated cyber ranges, and or automated policy client/server enforcement systems.
That's the USA philosophy of advanced degrees; it does not reflect the practice of every country.
And given standard scholarly impact statistics for completed theses, it arguably doesn't reflect reality either. Maybe we should start admitting that most PhD candidates haven't made a significant contribution to the state-of-the-art, most future candidates aren't going to, and the nominal requirement to do so isn't helpful?
If you come in the door with these credentials you will be highly qualified to be at least a principal cyber engineer. Your in depth research would makes serious waves in the industry and with real world experience it would be an amazing win-win situation for you and the company that hires you, or even better your own business doing cyber research.
Edit: from elsewhere in the thread, I understand that a degree is more usually more expensive than 10k in the USA? I guess a lot more, since this is making headlines? Is that also the typical case for online degrees?
1) The degree earned is the same exact as what the on-campus students earn. Exact same diploma - no mention of 'online'
2) It is a top ranked program (the MS in CS is ranked #8 - not sure about this Cybersecurity one)
3) It is (relatively) cheap at under $10k
Well it objectively isn't, and 'relatively' doesn't help me in understanding how expensive a degree normally is in the USA.
(Not that I've ever had any experience on the receiving end of this... /s)
Worldwide it holds less prestige but in the USA for the major companies, GT is very highly regarded and the students are heavily recruited.
When I interned at Deloitte (here in the Netherlands), there were a lot of employees from two particular IT security studies. There was teasing and slight rivalry back and forth of course, but it definitely wasn't that one camp got paid more or was hired more easily than the other.
In fact, if you were to ask, most people would tell you that any vaguely relevant master's would do (and get paid similarly) since the company has to teach you the specifics anyway. Now I've noticed that's not entirely true, they will definitely frown upon a network engineering graduate applying for a security job, but you'll still get the job if you can convey your interest in the field.
Job market for GT BSCS grads is the same bollocks as most anywhere else. I say, save your money and go someplace else (or self-teach) and then use a recruiter that knows wtf they're doing; that's what will make the difference.
The job market for GT grads is the same as everyone else, yes, because it's unlikely a job is going to magically open just for a GT grad. However, I guarantee saying you hold a GT BSCS catches the eye of recruiters more than a certificate from Udemy or no education but some experience.
I do in fact hold rigorous formal education in high regard. But I doubt that more than about 70% of GA Tech BSCS holders have actually received such a thing; and a result from a 70/30 binary distribution is not a very informative piece of evidence.
I don't doubt that a Udemy cert alone is as close to bubkes as you claim. I do doubt that an Anytown State University degree is in the same bucket as Udemy certs, rather than the same bucket as a BSCS from GA Tech. I have also seen recruiters that can very easily convert autodidacts' and Udemy grads' raw experience and competence into employer signals.
University of Oxford Master’s in Software Engineering
https://mba.london.ac.uk/overview/programme-structure/
University of London (Queen Mary’s) MBA
https://london.ac.uk/courses/finance-major-banking#entry-req...
SOAS University of London Master’s in Finance
All of these Master’s will admit students with enough relevant work experience without a Bachelor’s degree. If your work experience is tangential to what you want to study they might tell you to go do a MOOC and apply again with proof you did well in it.
Unless I misread the below they prefer a Math, CS or Engineering Bachelor’s and a Bachelor’s of some kind is an absolute requirement.
> Preferred qualifications for admitted OMS CS students are an undergraduate degree in computer science or related field (typically mathematics, computer engineering or electrical engineering) from an accredited institution with a cumulative GPA of 3.0 or higher. Applicants who do not meet these criteria will be evaluated on a case-by-case basis; significant professional or other work experience with supporting recommendations may qualify as an adequate substitute for the appropriate academic credentials, however work experience will not take the place of an undergraduate degree
A working person might be able to space out classes so that they can continue their full-time job, but I'm not sure.
So on the surface the GATech offering looks superior. However, I can't help but wonder how the "at-scale" model changes that. At IA State I'm "in" rather small classes and have very ready access to the instructor by email and phone. My work is also almost all graded by the instructor directly, most courses aren't big enough for a TA to have been hired. So I feel like it's a fairly personal experience, despite my physically being several states away and watching lectures recorded. I'm working on forming a committee for my thesis this semester so I'll be conversing directly with the faculty even more.
I wonder how an "at-scale" program like this, which seems to get built more on a MOOC model, will compare. Will it feel nearly as much like receiving direct instruction from an expert, which is what I would want a graduate program to be, or will it feel more like an off-the-shelf mass produced training package? That's a big concern to me.
Edit: I also feel like it's worth noting that my program confers an MS, with either thesis or creative component at student choice. I suspect this will be viewed more favorably by employers and others than an "OMS," even with a big name on it.
Some places seem to charge an enormous amount of money (>40k$) and some other a fairly small amount of money (<5k$).
Unrelated to the price, some are simply a glorified version of a Coursera MOOC with a non personalized experience while some other seem to offer a lot of 1:1 and side project opportunities directly with the TAs and teachers.
This field is in full revolution, but it feels like a lot of universities see this as an easy way to get a couple thousands extra dollar for only posting the lecture videos online.
https://techcrunch.com/2018/08/12/hacking-the-websites-respo...
Yes, there's a HUGE range of quality in on-line degrees these days. Many of the degrees are sold by degree mills calling themselves universities and cheating the hell out of their students. Almost all MOOCs are watered down subset of an on-campus course.
But the on-line degrees from these top tier schools do not suffer from that.
I am curious as to your basis for this statement. Have you done many? Why would a prestigious institution be willing to dilute its brand in that way?
You will at least have a rich gitHub repository if you go through it. If you try your best you will also learn a lot and make connections.
The advantage of a part time masters is that the connections are of a much higher value. During your undergrad you and all your connections will go on the job hunt. In a part time masters some of your connections will be hiring.
Master's degrees are cool, but what about Bachelors' degrees ?
https://www.coursera.org/degrees/bachelor-of-science-compute...
https://webcache.googleusercontent.com/search?q=cache:2ygsHH...
"OMS Cybersecurity is Georgia Tech’s third at-scale online degree program. It will follow the same model as the groundbreaking online Master of Science in Computer Science (OMSCS) program, which launched in 2014 on Udacity with support from AT&T and has enrolled approximately 10,000 students overall for the $6,800 degree."
[0]: https://www.reddit.com/r/OMSCS/comments/2ydahe/how_long_time...
The curriculum is as follows (tech specialization, the others are worse):
1 intro to security
1 intro to policy
1 hands on lab
1 crypto
1 netsec
2 it security
choice of (2):
basic CS courses (i.e. mobile apps, operating systems)
None of that will help you get a job at any company with a serious security org. All of those courses from what I could find are the same introductory level electives you can get in your BS degree in CS.
It is not a specialized program, it is more of an introduction to security and CS at the MS level.
Things that would help:
Client XSS, Authentication / Session Management, Secure client/server architecture, defining access boundaries, phishing / social engineering, red team / blue team setup, automated vulnerability regression tests, SSDL, threat modeling, etc.
What did OP mean by "secure client/server architecture" though? What are the basic/fundamental principles behind it, that are NOT covered in cybersec education?
^ I am in no way trying to be offensive here. But if you are already a programmer, with the exception of "threat modeling" and "regression tests", it seems all those topics combined would take a week to learn?
I know cybersec is extremely broad, but I think software engineering plays an extremely important role.
Speaking practically, the vast majority of companies that experience one of the vulnerabilities you are referencing are not going to be patching the code themselves - they're going to be updating their infrastructure with code that was written by someone else. And before they even get to that point, they are going to have to have policies/procedures that alert them of that vulnerability, that assess how important patching that vulnerability is, that determine cost of patching/not patching, that determine how to receive that patch, and that determine how to apply that patch. And all of those things involve much more than programming.
One of the other largest parts of defending a company from being hacked is training and protecting employees from social engineering/phishing attacks, and that's something that doesn't involve writing any code (or even knowledge of code) at all.
I didn't say there weren't?
> In my experience, the companies with the worst security are ones that primarily employ current or former software engineers as leaders of their security teams with a misguided mentality that security is just a subset of software engineering.
Wasn't what I was advocating for.
I'm advocating for learning security after you have a base of software development. Not leading a security team with no experience learning or practicing security. Also, this is a huge and growing field, so I'm speaking generally, but I'm sure there are sub-areas where there are counter examples.
I could keep going. All of these things could have some software engineering component, such as with identity management: there is a component there that deals with (for example) writing code to integrate your web app with multi-factor authentication, but identity management also encompasses things like writing good access control policies, managing the legal requirements for access, training people on how to use that multi-factor auth, etc.
Engineering skills are of course of great use if you are talking about the security of a specific codebase or doing penetration testing or doing the nitty-gritty customization of a security application, but "cybersecurity" is much more than that.
Can you elaborate? I know a lot of security teams will have large amounts of machine data thrown into ELK or Splunk, but that seems like qualitative data and so there's not a lot of number-crunching to do.
Graph Analysis => Saw some guys turn the Android codebase into a graph and use that to turn a dozen minor exploits into a chain that gave them root. Pwn2own IIRC.
Statistics => Great for detecting anomalies / understanding how to evaluate manipulation of cyber adjacent systems. For example, understanding the beta distribution lets you figure out how someone will game ratings in your app store to beat out legitimate apps with similar sounding ones. And of course all of these things cut both ways: if you're on red team it helps you masquerade more effectively.
Recommenders => Obviously useful to understand from attack detection, spam filter evasion, etc.
Linguistic analysis => De-anon attackers by the language they use. Figure out automatically which email accounts have been owned by sudden changes in speech usage.
Anecdotally, at my (one of the largest in the world) security consulting firms that hires from similar degree programs, a very small minority of people have any experience as a programmer, and a similarly small minority of our work involves writing/reading any code.
I'm not sure why you are just reposting what someone else wrote, the course and curriculum are linked to in the second sentence of the article.
It's far more solid than your incredibly spartan summary:
https://pe.gatech.edu/degrees/cybersecurity
Your list of "things that would help" are likely found in:
"Introduction to Information Security (CS 6035) A full spectrum of information security: threats, software vulnerabilities, programming for malice, basic cryptography, operating systems protections, network security, privacy, data mining, computer crime."
A course on documentation would also be prudent. Knowing the difference between policies, standards, and procedures will help you in any interview for positions above entry level. Knowing qualitative from quantitative, and being able to talk about abstract security theory, would be good too.
And some law. Some basic course so you can talk about negligence and liability without sounding like a wikipedia page.
Potential gems on the list might be the OS or networking course if they are run something like MIT's 6.828 with lots of lab coding and perhaps a bit of hand-holding, but if you can just clone last semester's 6.828 repo and get osdev'ing, why drop 10k to spend most of your time on courses that look like yawn central?
I think what I really wanted to see was a lab-focused curriculum for aspiring vulnerability researchers, so perhaps I was bound to be disappointed.
A MS is an academic degree so of course it will be heavy on the theory, and you will mainly be expected to do practical work independently on top. Same as an undergraduate degree actually, at least a good one. That stuff you call “yawn central” is the principles that will last your entire career, the stuff you learn in the lab will be obsolete in a few years.
1. Exploit a buffer overflow in a C program
2. Use Cuckoo to understand a malware attack
3. Implement CBC encryption algorithm and a brute-force algorithm to crack it
4. Demonstrate an XSRF, XSS and SQL injection attack
Remember this is an intro course and there are about 2-3 weeks per project so you won't be an expert but I'd say it makes you aware of some of the basic security attacks and how to prevent them.
Most of the jobs are with non-serious orgs. But yeah, paying $10k to get a basic bootcamp on security probably isn't going to inspire tons of confidence by employers.
Core:
CS 6035 Intro To Info Security
PUBP/CS/MGT 6725 Info Security Policies
CS/ECE/PUBP 6727 Cyber Sec Practicum
Elective (CS/PUBP/ECE 6000-level)
Tech Specialization:
CS 6260 Applied Cryptography
CS 6238 Secure Computer Systems
CS 6262 Network Security
CS 6265 Information Security Lab
Any 2:
CS 6210 Adv Operating Systems
CS 6250 Computer Networks
CS 6255 Network Management
CS 6300 Software Dev Process
CS 6310 Software Arch & Design
CS 6340 Software Analysis & Test
CS 6365 Intro Enterprise Comput.
CS 6390 Programming Languages
CS 6400 DB Sys Concepts& Design
CS 6675 Advance Internet Comput
CS 7210 Distributed Computing
CS 7230 Software Dsgn,Impl& Eval
CS 7260 Internet Arch& Protocols
CS 7270 Networked Apps&Services
CS 7292 Reliable Secure Comparch
CS 8803 Mobile Applications and Services
Energy Systems Specialization:
ECE 8813 Smart Grids
ECE 8813 Introduction to Cyber-Physical Electric Energy Systems
ECE 8813 Introduction to Cyber-Physical Systems Security
ECE 8803 Computational Aspects of Cyber-Physical Systems
And any 2:
ECE 6550 Linear Sys and Controls
ECE 6607 Computer Comm Networks
ECE 6615 Sensor Networks
ECE 6102 Dependable Distribut Sys
ECE 6320 Power Sys Ctrl&Operation
ECE 6323 Power System Protection
ECE 8813 Advanced Computer Security
ECE 8813 Network Forensics
Policy Specialization:
Select 4 courses:
PUBP 6502 IT/Comm/Telecom Policy
MGT 6726 Privacy Tech Policy Law
PUBP 6111 Internet & Public Policy
INTA 6014 Scenario and Path Gaming
INTA 8803 Data Analytics and Security
PUBP 6501 Information Policy & Mgt
INTA 8803 Challenge of Terrorism in Democratic Societies
And any 2:
PUBP 6701 Energy Technol & Policy
PUBP 6014 Organization Theory
PUBP 6401 Sci,Tech & Public Policy
INTA 6103 International Security
INTA 6015 Technology& Military Org
I'm pretty meh about this. In particular: when we think about the "cybersecurity talent shortage" (I don't believe that one exists, but whatever), we're thinking about what this degree program considers "technical specialization" roles. I don't look at that course list and think of a consistent cohort of people it produces that are especially ready to take on jobs in my field.I'm also: why do they make Cybersecurity MS candidates take that pointless Applied Cryptography class? I read the lecture slides for it, and, like most university crypto classes, it's "just enough cryptography to make you dangerous, with just enough math notation to make you think you learned something really hard that you didn't really learn".
The MS core classes are an intro to computer security that might be workable as a 100-level class in a serious CS program, a "policies" class that looks just absolutely deadly (1 week on "HIPAA, GLBA, FISMA", then a week on the "NIST cybersecurity framework", then a week on "cybercrime and cyberwar"), and a capstone independent study program.
My advice: get an internship and skip the MS. They'll pay you to learn this stuff.
(I graduated from GT but didn't take the undergrad version of intro infosec, which is 400 level and is likely crosslisted with the on campus 6035. I also don't think infosec was the most rigorous of courses from what I heard, but still)
I agree that Georgia Tech is a top CS program. I don't think this is a top CS degree.
I agree that the credentialism is the real issue here. I wanted to go into security after graduating and couldn't find anywhere offering jobs with less than 3 years of work experience or a graduate degree, lucky if it was only a MsC requirement.
That vs having to interrogate a candidate on 22 subjects, identifying what constitutes sufficient coverage. I've seen enough self-taught developers who clearly haven't covered the basics to be concerned.
I wonder which schools will be offering the CS, EE, and Accounting Master's. Hopefully MIT, MIT, and UT-Austin, respectively. Does anyone know anything beyond what's already posted?
edit: Profit as institution, not just on this program, devaluing their in-person MS programs by charging very little for the online version would be a net negative in profit for example.
If you really want to learn invaluable cybersecurity skills, start playing wargames. I suggest (1) which is one of the best. If you manage to reach level 25 on your own, then you are elite and the knowledge you gained doing so is not only extremely valuable but something you can be proud of.
(Sidenote: I would hire anyone who reached vortex level 25 on the spot and pay him a six figure salary, without looking at any of his other qualifications/degrees/past experience)
Additionally, read every single phrack (2) magazine from the past 20 years and try to understand most of the material within.
This is a strong statement. I remember reading somewhere that Bill Gates said he would hire anyone who has read The Art of Computer Programming by Knuth.
I think these challenges should be collated and put up in a website where motivated individuals can grab the opportunity to prove themselves.
I take the same approach. Have been around many well qualified people who lack critical thinking and thus suffer poor output. There is no amount of education that can correct for this.
There are a lot of jobs and they are a lot more stable for people who have studied the fields academically. There's some high pay for those who haven't, but a lot of it ends up being temporary.
[1] https://news.ycombinator.com/item?id=17772970
[2] https://news.ycombinator.com/item?id=17773218
[3] https://news.ycombinator.com/item?id=17770602
[4] https://news.ycombinator.com/item?id=17770724
[5] https://news.ycombinator.com/item?id=17770883
[6] https://news.ycombinator.com/item?id=17770722
etc.
Stage 16 is one of my favorite challenges all time. It took me weeks to solve and the solution is very impressive.
I've been stuck for the last few years on stage 23. Unlike the rest of the challenges it is a stenography level, and I'm not convinced that it is still solvable today.
This sounds fascinating since progress does not tend to work that way. What is it about this problem that leads you to think it was solvable in the past but no longer?
The name of the level is "the properties of a mirror" which hints that you need to find a mirror of the original site in order to solve the level, and I think that the mirrors are no longer online.
Note for anyone unfamiliar that this level is not at all representative of vortex - all the other levels are all hard core exploit implementation and not stego challenges. In general I don't like stego because I feel that it is more of "try to guess what I'm thinking" than solving interesting challenges.
I would assume that if this were the case someone who has already completed that level could check if where they found it was still up? Perhaps this is not the interpretation of the level name that the writers had in mind?
It may be obvious but I'm currently drawing a blank. What are other possible non-programming examples of reaching a certain level in a game and that being worthy of an immediate hire (not including the video game industry)? Complete courses via gamified education is a cool concept.
> I would hire anyone who reached vortex level 25
What would be the position/role?
Doing these and other similar challenges and reading and understanding phrack articles would give you a solid foundation to start doing reverse engineering and vulnerability research and reap the rewards that come from successfully doing so.
Anyone reaching 25+ would either:
1) Command significantly more than just (low) 6-figure salary
2) Won't be willing to be hired as an employee
However, for developing compliance and architectural plans for a large enterprise, it's quite a bit more complex problem.
Reverse engineering & vulnerability research.
I do wish more CTFs kept their challenges online after the competition: good ones and these wargames form what are essentially the problem sets for a top-tier exploit engineering program.
I cut my teeth on these wargames, as well as pwnable.kr/tw and, of course, microcorruption. While working through some of these challenges and finally popping a shell was definitely satisfying, I'm not sure I'll feel "elite" until perhaps I take home master of pwn at cansecwest.
It's a known fact that MS-holder salaries grow faster than BS (and PhD faster yet). So seems like financially it's a no-brainer.
If you leave the workforce to study full-time, then it's often free (with the caveat that you must have a research assistantship or teaching assistantship), but then you lose out on multiple years' worth of salary.
So it's not a "no-brainer," financially speaking.
Security academics, self-taught pentesters, and people who simply gained hard security experience in their day to day jobs each bring something unique to the table. I'm far more likely to pick up the principal engineer with a security MS for a security architect role than I am someone who can prove to me they passed an OSCE.
That said, for the person who can prove to me they passed an OSCE, I'll knock two years off the pentest experience requirement for any such role.
So my comment was mostly trying to illustrate that the skills one learns by going through these kind of challenges are extremely useful in practice and the skills one learns by doing an Msc of the sort advertised here pretty much completely useless, assuming one wants to do reverse engineering and vulnerability research and not just push paper, point at his Master's and call himself a "security expert".
This is why in Bulgaria, Cz and other countries you see locals paying low rates while other Europeans paying private college fees.
That's incorrect. In EU you can't price-discriminate, based on nationality, regardless of the product or service you're offering. Of course, that applies to EU citizens only. Non-EU citizens do indeed pay higher university fees than locals.
Quick Google search: https://www.medicalstudyguide.com/bulgarian-university-tuiti...
Come to think of it, they probably discriminate on the basis of the program language: If you take the English course you have to pay high tuition fees, while if you take the local language program, you don't.
If you're foreigner, haggling at a local flea market, of course it can happen. But in "official" places, this is simply not possible. And yes, that program discriminates based on language. If you take the version in Bulgarian, you'll pay same fees as locals, though you're usually forced to undergo a paid language course before enrolling.
The US$15/hr TA pay rate is absolute garbage - when I TAed as a 3rd year undergrad in Australia, I was paid double that.
Working as a TA pays $15 per hour, distributed twice monthly based on submitted timesheets (alumni are salaried, however).
Also “move to Germany” isn’t really something you can just...do.
The quality of education you'll get there is questionable, though
I mean I studied Physics at a good UK Uni but it isn't like one of the best in the world or anything.
Then I did Neuroinformatics at Edinburgh which is really competitive due to their reputation in AI etc.
It was fine, ultimately linear algebra etc. are the same wherever you learn it. I think in less objective and more qualitative fields the reputation of the University etc. counts a lot more.
Why would you think this? From my experience technical universities in Europe do a lot less hand holding and a lot more practical courses than American ones do.
France too, and I suppose most(?) European countries. Many universities have international masters where classes are taught in English. Students come from everywhere, including the US. It's easy to get a student visa.
Technically, there is supposed to be some fairly brutal bandwidth sharing and the speed is not guaranteed in any way but I never had my speedtest drop under 90Mb/s
I theorised that over the course of 4 years (5 as it turned out) would give me 20 minutes of talking time.
It worked. Even with average scores (and a handful of fails) I got a well paying job at a top company. Even back in the late 90’s many hiring managers valued experience and personality equally to academic transcripts.
The extracurricular activities were: * organised LAN gaming days for 100 people to teach myself networking, event management, marketing etc. Quake was the game by the way :) * half a day a week work experience for a year at a relevant employer * involvement in a paid capacity at the student association, taking on leadership roles * something else I cannot remember now!
Best wishes for your studies!
It's also good to look for any sort of volunteer position that'll help development of leadership skills. With a master's degree expectations will be that you can develop into a leadership role which doesn't necessarily mean management.
Set up a small network at home. Go crazy with nmap. Set up a few VMs. Go crazy with gdb or windbg. The best way to learn is to break things.
If you have an old application or game with serial #. Try to crack it.
Set up an webserver + sql backend, try injections or other exploits. Profile/audit it to see what is happening.
There are websites that document OS, Database, Webserver, etc vulnerabilities. Install older versions and try these vulnerabilities.
Then you can look into worms, trojans, etc. See their code and how they work. And see if you can come up with ways to stop it. Then see how you would bypass your fix.
You can also look at security ( white hate/black hat ) software that audit, pentest, etc. If it is open source, read the source.
The only reason to shell out the $10K is if you are looking for a job.
That's a pretty big "if". If you're considering a cyber security Masters degree, you're probably interested in doing it for a career.