Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Introduction to IT Security and Secure Coding
- Principles of information security
- Confidentiality, Integrity, and Availability (CIA) triad
- Authentication, authorization, and accountability
- Security by design principles
- Secure Software Development Lifecycle (SSDLC)
- Common software security risks
- Foundational secure coding principles
2. Requirements of Secure Communication
- Data confidentiality
- Data integrity
- Authentication mechanisms
- Non-repudiation
- System availability
- Secure identification
- Privacy and anonymity
- Threat modeling for networked applications
3. Network Security Fundamentals
- OSI and TCP/IP security models
- Network architecture analysis
- Common network protocols
- Attack surfaces in networked applications
- Firewalls and network segmentation strategies
- Principles of secure network design
4. Network Attacks and Defenses
- Packet sniffing techniques
- Spoofing attacks
- Man-in-the-Middle (MITM) scenarios
- Session hijacking
- Replay attacks
- Denial-of-Service (DoS) and Distributed DoS
- Network monitoring and intrusion detection systems
5. Practical Cryptography Fundamentals
- Cryptographic terminology and concepts
- Symmetric encryption basics
- Asymmetric encryption basics
- Hash functions
- Message Authentication Codes (MAC)
- Digital signatures
- Random number generation
- Key management concepts
6. Symmetric and Asymmetric Cryptography
- AES and modern symmetric algorithms
- RSA fundamentals
- Elliptic Curve Cryptography (ECC)
- Hybrid encryption schemes
- Key exchange mechanisms
- Practical implementation considerations
7. Hashing and Password Security
- Cryptographic hash functions
- Password hashing algorithms
- Salt and pepper techniques
- Key derivation functions
- Secure credential storage
- Password attack techniques
- Password security best practices
8. Public Key Infrastructure (PKI)
- Digital certificates
- Certificate Authorities (CA)
- Certificate chains
- Certificate validation processes
- Certificate revocation
- Trust models
- Practical PKI deployment strategies
9. Security Protocols
- SSL and TLS architecture
- TLS handshake process
- HTTPS communication
- IPsec overview
- VPN technologies
- Secure Shell (SSH)
- Secure email protocols
- Best practices for secure communication
10. Cryptographic Vulnerabilities
- Weak cryptographic algorithms
- Poor key management practices
- Insecure random number generation
- Padding oracle attacks
- Timing attacks
- Side-channel attacks
- Cryptographic implementation errors
11. Analysis of Real-World Cryptographic Attacks
- BEAST attack
- BREACH attack
- CRIME attack
- TIME attack
- POODLE attack
- FREAK attack
- Logjam attack
- Lucky Thirteen vulnerability
- RSA timing attacks
- Lessons from historical vulnerabilities
12. Secure Network Application Development
- Designing secure communication
- Secure API interaction
- Secure session management
- Secure authentication mechanisms
- Secure token handling
- Secure configuration management
13. Web Services Security
- Web services architecture
- SOAP security
- REST security considerations
- Authentication methods
- Authorization strategies
- Secure service-to-service communication
14. XML Security
- XML fundamentals
- XML Signature
- XML Encryption
- XML Key Management
- Secure XML processing
- XML validation techniques
15. XML-Based Attacks
- XML Injection
- XPath Injection
- XML External Entity (XXE)
- XML Bomb attacks
- Entity expansion attacks
- Mitigation techniques
16. Secure Coding Best Practices
- Input validation
- Output encoding
- Secure error handling
- Secure logging
- Defensive programming
- Secure exception handling
- Dependency management
17. Security Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Dependency vulnerability scanning
- Penetration testing overview
- Secure code review techniques
18. Secure Deployment and Operations
- Secure software configuration
- Secrets management
- Environment hardening
- Security monitoring
- Patch management
- Secure DevOps concepts
19. Incident Response and Vulnerability Management
- Security incident lifecycle
- Vulnerability assessment
- CVE and CVSS overview
- Security advisories
- Responsible vulnerability disclosure
- Remediation planning
20. Hands-on Secure Coding Workshop
- Implementing secure communication protocols
- Configuring TLS correctly
- Using cryptographic libraries safely
- Identifying insecure code patterns
- Fixing common security flaws
- Secure XML processing exercises
21. Summary and Further Learning
- Review of key security concepts
- Common implementation pitfalls
- Secure coding standards and guidelines
- OWASP recommendations
- Industry frameworks and compliance
- Additional learning resources
- Q&A session
Requirements
No prior specific prerequisites are required.
21 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated