21 / 21

Chapter 13: Security Engineering

نموذج إِمام التعليمي: إنطلاقة راسخة على خطى الأولين
إِنَّ اللَّهَ يَأْمُرُكُمْ أَن تُؤَدُّوا الْأَمَانَاتِ إِلَىٰ أَهْلِهَا

"Indeed, Allah commands you to render trusts to whom they are due" - Qur'an 4:58

(Transliteration: Inna Allaha ya'murukum an tu'addū l-amānāti ilā ahlihā)

Foundation: أمانة (Trust) and حماية (Protection)

⚡ Your Mission: Master security engineering to protect Saudi Arabia's digital sovereignty
افهم
Understand

Why security matters
Core principles
Section: Foundations

مارس
Practice

Risk assessment
Security tools
Section: Requirements

اتقن
Master

Design patterns
Secure coding
Section: Design

ميز
Excel

Testing & Innovation
Vision 2030
Section: Innovation

🚀 Framework Evolution: Shaping Security Engineering

افهم

Two Lenses for Mastering Security

🏭 Industrial Revolution 6.0 (IR 6.0)

Human-Centric Security (2020s)

  • Section 13.1 - CIA Triad: Enhances confidentiality while respecting privacy (e.g., Absher's biometric auth).
  • Section 13.2 - Organizational Security: Designs policies that don't burn out security teams (e.g., automated SOC at STC).
  • Section 13.3 - Requirements Engineering: Balances security with user experience (e.g., Nafath's seamless auth).
  • Section 13.4 - Secure Design: Creates sustainable incident response (e.g., SAMA's 24/7 ops with rotation).
Market Impact: IR 6.0 reduces security analyst burnout by 40%, increasing threat detection by 2x.

📖 Islamization of Knowledge

أسلمة المعرفة (Proactive)

  • Section 13.1 - CIA Triad: Derives from أمانة (trustworthiness) not Western models.
  • Section 13.2 - Organizational Security: Models from Shura (consultation) for security governance.
  • Section 13.3 - Requirements Engineering: Misuse cases prevent خيانة (betrayal of trust).
  • Section 13.4 - Secure Design: Defense-in-depth from حصن (fortress) concept.
Principle: Start with Islamic ethics, then evaluate global security standards.
University Tool: Theoretical Security Models
Market Test: Preventing Real Breaches

🎯 Your Learning Approach (Mapped to Objectives)

  • ✅ Understand security dimensions & terminology (Objective 1, Section 13.1).
  • ✅ Master risk assessment & requirements (Objective 2, Section 13.3).
  • ✅ Apply secure design patterns (Objective 3, Section 13.4).
  • ✅ Execute security testing strategies (Objective 4, Section 13.5).
🤔 Quick Quiz: Which IR 6.0 principle helps prevent SOC burnout? (2 mins)
⏱️ Timer: 2:00
A. More monitoring tools
B. Human-centric automation
C. Stricter policies
D. Longer shifts

🌍 Mission Context: The Shamoon Reality

افهم
University Tool: Case Study Analysis
Market Test: Understanding Attack Impact
August 15, 2012: 35,000 Aramco computers destroyed in hours

🎯 Experience the Attack Timeline (3 mins)

⏱️ Timer: 3:00

(Adapt for online/in-person; use simulation)

Live Simulation: Watch the attack spread:

  • 11:08 AM: First infection (1 computer)
  • 11:15 AM: 100 computers infected
  • 11:30 AM: 1,000 computers down
  • 12:00 PM: 10,000 computers destroyed
  • 2:00 PM: 35,000 computers - total destruction

Your Task: At what point would you pull the network cable?

💔 The Human Cost

  • • 35,000 employees couldn't work for weeks
  • • IT staff worked 24/7 for 2 weeks straight
  • • $15 million in immediate damages
  • • Global oil supply at risk
🤔 What made Shamoon so devastating?
A. It stole data
B. It destroyed data permanently
C. It was undetectable
D. It spread slowly

📚 CIA Triad: The Foundation

افهم
University Tool: Theoretical Models
Market Test: Protecting Real Assets

🔍 Discover CIA Yourself (4 mins)

⏱️ Timer: 4:00

(Adapt for online/in-person)

With your neighbor, identify CIA violations:

Scenario C, I, or A? Why?
WhatsApp message leaked ? Your answer...
Bank balance changed ? Your answer...
Absher down for hours ? Your answer...
Fake COVID certificate ? Your answer...

WhatsApp: Confidentiality - Private info exposed
Bank: Integrity - Data corrupted
Absher: Availability - Service denied
COVID: Integrity - False data created

Definition: "Security engineering is about building systems to remain dependable in the face of malice, error, or mischance" (Anderson, 2008)
Market Reality: One CIA violation in SAMA systems could cost billions and destroy public trust.

⚖️ Security ≠ Safety: Critical Differences

افهم
University Tool: Comparative Analysis
Market Test: Choosing Right Approach

🎮 Role Play: Safety vs Security Engineer (5 mins)

⏱️ Timer: 5:00

(Split class into two teams)

Scenario: System failure at Riyadh Metro

  • Safety Team: Find root cause, fix, document
  • Security Team: Assume attack, contain, investigate

Which approach if: (a) Train stops suddenly? (b) All screens show "HACKED"?

Aspect Safety Focus Security Focus Saudi Example
Threat Source Accidents, nature Malicious actors Hajj crowd vs cyber attack
Response Can shutdown safely Must stay operational SAMA can't go offline
Failure Analysis Open investigation Attacker hides traces Shamoon wiped logs
Environment Predictable Adversarial, adaptive APT groups target Saudi
Market Reality: Treating security as safety led to Shamoon's success - no adversarial thinking.

🎯 Risk Assessment: STRIDE Model

مارس
University Tool: STRIDE Framework
Market Test: Identifying Real Threats

🔍 Apply STRIDE to Tawakkalna (5 mins)

⏱️ Timer: 5:00

(Work in pairs; use worksheet)

Your Task: Find one threat for each STRIDE category

STRIDE Threat Type Tawakkalna Example Islamic Violation Control
Spoofing Fake identity Fake vaccine status انتحال الشخصية Biometric + Nafath
Tampering Modify data Change health status تحريف البيانات Blockchain logs
Repudiation Deny actions Deny permit request إنكار الفعل Digital signatures
Info Disclosure Data leak Medical records exposed إفشاء السر End-to-end encryption
Denial of Service Block access App crash during Hajj منع العبادة CDN + scaling
Elevation Gain privileges Access admin panel تجاوز الصلاحيات Zero trust + RBAC
Industry Tool: Microsoft Threat Modeling Tool for automated STRIDE analysis.

😈 Misuse Cases: Think Like an Attacker

مارس
University Tool: Misuse Case Diagrams
Market Test: Preventing Real Attacks

🎭 Evil Twin Exercise (4 mins)

⏱️ Timer: 4:00

(Ethical hacking mindset)

Your Mission: Break into Absher (theoretically!)

  1. Partner A: Describe normal use case
  2. Partner B: Describe how to abuse it
  3. Together: Design a defense

✅ Use Case

Login to Absher

  • Enter national ID
  • Enter password
  • Verify with Nafath
  • Access services

😈 Misuse Case

Hijack Account

  • Phishing for credentials
  • SIM swap for SMS
  • Man-in-the-middle
  • Session hijacking

🛡️ Security Use Case

Prevent Hijacking

  • Anti-phishing training
  • Device fingerprinting
  • Certificate pinning
  • Session timeout
# Example: Detecting account hijacking attempt
def detect_suspicious_login(user_id, ip, device):
  # Check for unusual patterns
  if ip_location(ip) != user_usual_location(user_id):
    send_alert("Login from unusual location")
    require_additional_verification()
  
  if device not in trusted_devices(user_id):
    send_notification_to_registered_phone()
    require_nafath_verification()
  
  # Islamic principle: Trust but verify (الثقة مع التحقق)
  log_access_attempt(user_id, ip, device, timestamp())

📋 10 Essential Security Requirements

مارس
University Tool: Firesmith's Framework
Market Test: Complete Coverage

🎯 Requirement Mapping Game (3 mins)

⏱️ Timer: 3:00

Match each Saudi service to its PRIMARY requirement:

1. Identification

Who are you?
Absher ID

2. Authentication

Prove it!
Nafath

3. Authorization

What can you do?
SAMA roles

4. Immunity

Resist attacks
Aramco post-Shamoon

5. Integrity

Accurate data
Hajj permits

6. Intrusion Detection

Spot attacks
NCA SOC

7. Non-repudiation

Can't deny
Sarie payments

8. Privacy

Protect personal
Sehhaty records

9. Auditing

Track actions
Government ops

10. Maintenance

Stay secure
Regular updates

Market Reality: Missing even one requirement led to 70% of Saudi breaches in 2023.

🏗️ Secure Architecture: Two Approaches

اتقن
University Tool: Architecture Patterns
Market Test: Building Resilient Systems

🛡️ Protection Architecture

🏰

Fortress Model (حصن)

Layers of defense:

  • Platform security (OS hardening)
  • Application security (Input validation)
  • Record security (Encryption)

Saudi Example: SAMA's banking platform

📊 Distribution Architecture

🌐

Spread Model (توزيع)

Minimize single points:

  • Replicated databases
  • Geographic distribution
  • Load balancing

Saudi Example: Hajj systems across regions

User Request
WAF Filter
Load Balancer
App Server
Database

📐 10 Security Design Guidelines

اتقن

🏗️ Design Challenge: Secure Madrasati (5 mins)

⏱️ Timer: 5:00

Apply 5 guidelines to fix Madrasati vulnerabilities:

# Guideline Madrasati Application Fix
1 Base on explicit policy No clear data retention Define 5-year policy
2 Defense in depth Only password auth Add MFA + biometric
3 Fail securely Shows error details Generic error messages
4 Balance security/usability 15-char passwords Passphrase option
5 Log user actions No audit trail Log all grade changes
6 Redundancy & diversity Single server Multi-region deployment
7 Validate inputs SQL injection possible Parameterized queries
8 Compartmentalize All data accessible School-level isolation
9 Design for deployment Manual configuration Infrastructure as Code
10 Design for recovery No backup plan Automated daily backups

💻 Secure Programming Practices

اتقن

🐛 Bug Hunt Challenge (4 mins)

⏱️ Timer: 4:00

Find 5 vulnerabilities in this code:

# Vulnerable Sarie payment system
def process_payment(amount, account_from, account_to):
  # BUG 1: No input validation
  query = f"SELECT balance FROM accounts WHERE id = {account_from}"
  # BUG 2: SQL injection vulnerability
  
  balance = execute_query(query)
  # BUG 3: No error handling
  
  if balance > amount:
    # BUG 4: Race condition - no locking
    execute_query(f"UPDATE accounts SET balance = balance - {amount} WHERE id = {account_from}")
    execute_query(f"UPDATE accounts SET balance = balance + {amount} WHERE id = {account_to}")
    # BUG 5: No logging of transaction
    return "Success"
  else:
    # BUG 6: Information disclosure
    return f"Insufficient funds. Current balance: {balance}"
# Secure version with Islamic principles
def process_payment_secure(amount, account_from, account_to):
  # حفظ الأمانة - Protect the trust
  try:
    # Input validation
    if not validate_amount(amount) or not validate_accounts(account_from, account_to):
      return {"status": "error", "message": "Invalid request"}
    
    # Use parameterized queries
    with transaction_lock():
      balance = db.query("SELECT balance FROM accounts WHERE id = ?", [account_from])
      
      if balance >= amount:
        db.execute("UPDATE accounts SET balance = balance - ? WHERE id = ?", [amount, account_from])
        db.execute("UPDATE accounts SET balance = balance + ? WHERE id = ?", [amount, account_to])
        
        # Complete audit trail
        log_transaction(account_from, account_to, amount, "SUCCESS")
        return {"status": "success", "transaction_id": generate_id()}
      else:
        log_transaction(account_from, account_to, amount, "INSUFFICIENT_FUNDS")
        return {"status": "error", "message": "Transaction cannot be completed"}
  
  except Exception as e:
    log_error(e)
    return {"status": "error", "message": "Service temporarily unavailable"}

🧪 Security Testing Strategies

اتقن
University Tool: Testing Methodologies
Market Test: Finding Real Vulnerabilities

🔍 Testing Tournament (5 mins)

⏱️ Timer: 5:00

Each team picks a testing approach for Tawakkalna:

📋 Checklist Testing

OWASP Top 10

  • ✓ Injection flaws?
  • ✓ Broken authentication?
  • ✓ Sensitive data exposure?
  • ✓ XXE attacks?
  • ✓ Broken access control?

Tool: OWASP ZAP

🎯 Penetration Testing

Ethical Hacking

  • Reconnaissance
  • Scanning
  • Gaining access
  • Maintaining access
  • Covering tracks

Tool: Metasploit

🔬 Static Analysis

Code Review

  • Buffer overflows
  • SQL injection points
  • Hardcoded secrets
  • Unsafe functions
  • Race conditions

Tool: SonarQube

🤖 Dynamic Testing

Runtime Analysis

  • Fuzzing inputs
  • Memory analysis
  • API testing
  • Session management
  • Error handling

Tool: Burp Suite

⚠️ Why Security Testing is Hard

  • "Shall Not" Requirements: Can't prove absence of all vulnerabilities
  • Intelligent Adversaries: Attackers adapt and share techniques
  • Unknown Unknowns: Zero-day vulnerabilities

🇸🇦 Saudi's Security Revolution

ميز
Vision 2030: Transform Saudi Arabia into a global cybersecurity hub
Target: Top 20 globally by 2030

🛡️ National Cybersecurity Authority

500+
Security experts
  • 24/7 SOC monitoring
  • National threat intelligence
  • Incident response teams

🏆 Saudi CTF

10,000+
Participants
  • Annual competition
  • $1M+ prizes
  • International recognition

🎓 SAFCSP

50,000
Certified professionals
  • Security certifications
  • Training programs
  • Career development

🏙️ NEOM Security

100%
Smart city coverage
  • Zero-trust architecture
  • Quantum-safe crypto
  • AI-powered defense

🚀 Innovation Opportunities

Saudi is investing $20B in cybersecurity by 2030 - your chance to lead!

🕌 Islamic Security Framework: Leading Global Innovation

ميز
وَلَا تَجَسَّسُوا

"And do not spy" - Qur'an 49:12

Privacy-preserving security is an Islamic mandate, not Western import

حفظ الدين

Protect Religion

Secure Hajj systems
Protect Islamic apps
Guard prayer times

حفظ النفس

Protect Life

Healthcare security
Emergency systems
Critical infrastructure

حفظ العقل

Protect Intellect

Educational platforms
Research data
Knowledge systems

حفظ النسل

Protect Lineage

Family records
Marriage systems
Child protection

حفظ المال

Protect Wealth

Banking security
Zakat systems
Trade platforms

حفظ العرض

Protect Honor

Privacy rights
Reputation systems
Data protection

Your Innovation: Create security frameworks that start from Maqasid, not patch Western models with Islamic justifications.

💼 Your Security Engineering Career Path

ميز

12-Month Roadmap to Excellence

Months 1-3: Foundation
  • Master Chapter 13 concepts
  • CompTIA Security+
  • OWASP Top 10 mastery
Months 4-6: Specialization
  • Choose: AppSec/NetSec/CloudSec
  • Bug bounty participation
  • Saudi CTF preparation
Months 7-9: Experience
  • NCA internship
  • Contribute to OWASP
  • Security research paper
Months 10-12: Leadership
  • Lead security project
  • Mentor juniors
  • Speak at conferences

Saudi Security Career Opportunities

Company Role Salary (SAR) Growth
NCA Security Analyst 300,000+ Extreme
Aramco CISO Track 400,000+ Very High
SAMA Security Architect 350,000 High
NEOM Zero-Trust Engineer 380,000 Extreme

🎓 Bridging University to Market

ميز

الجامعة تعلمك (University Teaches You)

  • نظريات الأمن (Security theories)
  • التفكير النقدي (Critical thinking)
  • البحث العلمي (Research methods)
  • الأخلاقيات (Ethics)
  • الأساسيات (Fundamentals)
  • حل المشاكل (Problem solving)
  • العمل الجماعي (Teamwork)
  • التواصل (Communication)
  • إدارة الوقت (Time management)

السوق يعلمك (Market Teaches You)

  • منع الاختراقات الحقيقية (Stop real breaches)
  • الاستجابة تحت الضغط (Respond under pressure)
  • التكلفة مقابل الأمان (Cost vs security)
  • السياسات والامتثال (Compliance)
  • أحدث التهديدات (Latest threats)
  • أدوات الصناعة (Industry tools)
  • العملاء الصعبون (Difficult stakeholders)
  • الحلول العملية (Practical solutions)
  • التعلم المستمر (Continuous learning)

University gives the foundation: How to think about security systematically.

Market tests execution: Can you stop a real attack at 3 AM?

Bridge: University is your training ground; market is your battlefield.

📝 Assignment: Comprehensive Security Assessment

ميز
Design a complete security framework for a Saudi national service

Choose ONE National System:

  1. 🕋 Nusuk (3M Hajj pilgrims)
  2. 🏥 Sehhaty (30M health records)
  3. 📱 Tawakkalna (25M users)
  4. 🎓 Madrasati (6M students)
  5. 💰 Sarie (National payments)

Deliverables (EMAM Framework)

Phase Weight Requirements Rubric
افهم 20% CIA analysis, threat landscape Clear understanding – 10/20; Islamic integration – 10/20
مارس 30% STRIDE analysis, misuse cases Complete coverage – 15/30; Practical controls – 15/30
اتقن 30% Apply 10 guidelines, secure code Design excellence – 15/30; Code quality – 15/30
ميز 20% Testing plan, Vision 2030 Innovation – 10/20; Saudi context – 10/20

Submission Requirements

  • Due: Next week
  • Format: PDF + GitHub repo
  • Must include: Threat model, security architecture, test results
  • Bonus: Working POC, bug bounty findings

Required Tools

  • OWASP ZAP for scanning
  • draw.io for threat modeling
  • GitHub for secure code

🎯 Key Takeaways - Chapter 13 Mastery

Summary: "Security engineering builds systems to remain dependable in the face of malice, error, or mischance through systematic application of principles, practices, and processes."
🧠 Foundations

• CIA Triad
• Security ≠ Safety
• Organizational policy

📋 Requirements

• STRIDE model
• Misuse cases
• 10 requirements

🏗️ Design

• 10 guidelines
• Architecture patterns
• Secure coding

🧪 Testing

• 4 approaches
• Tool selection
• Continuous testing

Success Formula

Islamic Ethics + Technical Excellence + Saudi Context + Global Standards = Security Leadership

Self-Reflection Prompts

  • Which security principle from Islam resonates most with you?
  • Rate your confidence in each STRIDE category (1-5)
  • What's your security specialization path?

📖 Chapter 13 Quick Reference

Essential Concepts at a Glance

Section Key Topics Pages Must Know
13.1 Security dimensions 366-373 CIA triad, terminology
13.2 Organizational security 373-375 Policy, risk stages
13.3 Requirements 376-382 STRIDE, misuse cases
13.4 Secure design 383-399 10 guidelines, architecture
13.5 Security testing 400-402 4 approaches, challenges

🚨 Common Attacks

  • SQL Injection
  • XSS
  • Buffer Overflow
  • CSRF
  • Session Hijacking

🛡️ Key Defenses

  • Input validation
  • Parameterized queries
  • Encryption
  • MFA
  • Least privilege

🔧 Essential Tools

  • OWASP ZAP
  • Burp Suite
  • Metasploit
  • Nmap
  • Wireshark

🤝 Your Security Engineering Commitment

إِنَّ اللَّهَ يُحِبُّ إِذَا عَمِلَ أَحَدُكُمْ عَمَلًا أَنْ يُتْقِنَهُ

"Allah loves when one of you does work, that they perfect it" - Hadith

(Transliteration: Inna Allāha yuḥibbu idhā ʿamila aḥadukum ʿamalan an yutqinahu)

Every system you secure protects millions of Muslims' data, privacy, and trust.
افهم

Foundation

Understand threats

Know the enemy

مارس

Application

Practice daily

Break things ethically

Learn from failures

اتقن

Excellence

Master defense

Write secure code

ميز

Innovation

Create new defenses

Lead globally

Protect the Ummah

Your Security Pledge:

  • What system will you protect first?
  • How will you apply Islamic ethics?
  • What vulnerability will you eliminate?
  • Who will you teach security to?

🙏 شكرًا - Your Journey as a Guardian Begins

وَقُل رَّبِّ زِدْنِي عِلْمًا

"My Lord, increase me in knowledge" - Qur'an 20:114

Security knowledge evolves daily - keep learning, keep protecting!

You now understand how to build systems that protect digital trust
From basic CIA to advanced testing - you're ready to defend!
📧 Contact

Office Hours: By Email

Email: arnoor@kau.edu.sa

📅 Next Class

Chapter 14

Resilience Engineering

Monday, 2:30 PM

📝 Due Soon

Security Assessment

Next week

Start TODAY!

🎯 Resources

OWASP guides

NCA resources

Saudi CTF prep

بروف: أديب بن رضا نور

See you next class, إن شاء الله
Remember: You are the firewall between attackers and millions!