Week 19 · slides

Week 19

← all weeks · readme · ctf


marp: true theme: default paginate: true header: "Software Security · Week 19 · Final"


Week 19

Final — Capstone CTF + Project Demos

The grand finale

<!-- The finale — make it celebratory + high-energy. Before class: plant per-student/team flags, bring up all targets + CTFd, set the demo schedule. Confirm projects run. ~2 min. -->


Two parts

  1. 🏆 Capstone CTF tournament — whole-term, team-based
  2. 🎤 Final project demos — graded

<!-- Time-box the 240-min block: CTF tournament first (energy), then graded demos. Tell teams their demo slot up front. -->


🏆 CTF tournament

  • Web · API · supply chain · cloud · memory safety · LLM/agentic
  • Team leaderboard, prizes
  • Flags = points

<!-- Run from ctf.md + exams/item-bank.md (CTF pool, incl. the boss chain). Dynamic scoring + first-blood bonus on CTFd; announce first-bloods aloud for hype. Prizes for top Houses. -->


🎤 Final project demo (graded)

Present your secured build end-to-end:

  • Threat model → vulnerabilities → remediation
  • SBOM + signed artifact
  • Security CI/CD pipeline
  • 10-min demo + 5-min Q&A

<!-- Graded on the project rubric (project/README.md) + the peer-contribution multiplier. Strict 15-min slots. Score live on the rubric; ask one probing Q each (viva-style) to confirm the work is theirs. -->


Bring

  • Threat model + vuln report (CWE/OWASP mapped)
  • Fixed code, SBOM, signed artifact, CI pipeline

<!-- Checklist — anything missing costs rubric points. Confirm the CI pipeline actually fails on a finding (don't take their word; have them show it). -->


Thank you

You can now threat-model, break, fix, and ship secure software.

<!-- Close the term: name the arc (threat-model → break → fix → ship). Point to next steps (OWASP, CTFs, the readings). For the research: post-test + post-survey happen now (per the study timeline). Celebrate. -->