Week 19
← all weeks · readme · ctf
marp: true theme: default paginate: true header: "Software Security · Week 19 · Final"
Week 19
Final — Capstone CTF + Project Demos
The grand finale
<!-- The finale — make it celebratory + high-energy. Before class: plant per-student/team flags, bring up all targets + CTFd, set the demo schedule. Confirm projects run. ~2 min. -->
Two parts
- 🏆 Capstone CTF tournament — whole-term, team-based
- 🎤 Final project demos — graded
<!-- Time-box the 240-min block: CTF tournament first (energy), then graded demos. Tell teams their demo slot up front. -->
🏆 CTF tournament
- Web · API · supply chain · cloud · memory safety · LLM/agentic
- Team leaderboard, prizes
- Flags = points
<!-- Run from ctf.md + exams/item-bank.md (CTF pool, incl. the boss chain). Dynamic scoring + first-blood bonus on CTFd; announce first-bloods aloud for hype. Prizes for top Houses. -->
🎤 Final project demo (graded)
Present your secured build end-to-end:
- Threat model → vulnerabilities → remediation
- SBOM + signed artifact
- Security CI/CD pipeline
- 10-min demo + 5-min Q&A
<!-- Graded on the project rubric (project/README.md) + the peer-contribution multiplier. Strict 15-min slots. Score live on the rubric; ask one probing Q each (viva-style) to confirm the work is theirs. -->
Bring
- Threat model + vuln report (CWE/OWASP mapped)
- Fixed code, SBOM, signed artifact, CI pipeline
<!-- Checklist — anything missing costs rubric points. Confirm the CI pipeline actually fails on a finding (don't take their word; have them show it). -->
Thank you
You can now threat-model, break, fix, and ship secure software.
<!-- Close the term: name the arc (threat-model → break → fix → ship). Point to next steps (OWASP, CTFs, the readings). For the research: post-test + post-survey happen now (per the study timeline). Celebrate. -->