Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Introduction to IT Security and Secure Coding
- Information security principles
- Confidentiality, Integrity, and Availability (CIA)
- Authentication, authorization, and accountability
- Security by design
- Secure Software Development Lifecycle (SSDLC)
- Common software security risks
- Secure coding principles
2. Requirements of Secure Communication
- Confidentiality
- Integrity
- Authentication
- Non-repudiation
- Availability
- Secure identification
- Privacy and anonymity
- Threat modeling for networked applications
3. Network Security Fundamentals
- OSI and TCP/IP security model
- Network architecture
- Common network protocols
- Attack surfaces in networked applications
- Zones and network segmentation
- Secure network design principles
4. Network Attacks and Defenses
- Packet sniffing
- Spoofing attacks
- Man-in-the-Middle (MITM)
- Session hijacking
- Replay attacks
- Denial-of-Service (DoS) and Distributed DoS
- Network monitoring and intrusion detection
5. Practical Cryptography Fundamentals
- Cryptographic terminology
- Symmetric encryption
- Asymmetric encryption
- Hash functions
- Message Authentication Codes (MAC)
- Digital signatures
- Random number generation
- Key management concepts
6. Symmetric and Asymmetric Cryptography
- AES and modern symmetric algorithms
- RSA fundamentals
- Elliptic Curve Cryptography (ECC)
- Hybrid encryption
- Key exchange mechanisms
- Practical implementation considerations
7. Hashing and Password Security
- Cryptographic hash functions
- Password hashing algorithms
- Salt and pepper techniques
- Key derivation functions
- Secure credential storage
- Password attack techniques
- Password security best practices
8. Public Key Infrastructure (PKI)
- Digital certificates
- Certificate Authorities (CA)
- Certificate chains
- Certificate validation
- Certificate revocation
- Trust models
- Practical PKI deployment
9. Security Protocols
- SSL and TLS architecture
- TLS handshake
- HTTPS communication
- IPsec overview
- VPN technologies
- Secure Shell (SSH)
- Secure email protocols
- Secure communication best practices
10. Cryptographic Vulnerabilities
- Weak cryptographic algorithms
- Poor key management
- Insecure random number generation
- Padding oracle attacks
- Timing attacks
- Side-channel attacks
- Cryptographic implementation mistakes
11. Analysis of Real-World Cryptographic Attacks
- BEAST
- BREACH
- CRIME
- TIME
- POODLE
- FREAK
- Logjam
- Lucky Thirteen
- RSA timing attacks
- Lessons learned from historical vulnerabilities
12. Secure Network Application Development
- Secure communication design
- Secure API communication
- Secure session management
- Secure authentication mechanisms
- Secure token handling
- Secure configuration management
13. Web Services Security
- Web services architecture
- SOAP security
- REST security considerations
- Authentication methods
- Authorization strategies
- Secure service communication
14. XML Security
- XML fundamentals
- XML Signature
- XML Encryption
- XML Key Management
- Secure XML processing
- XML validation
15. XML-Based Attacks
- XML Injection
- XPath Injection
- XML External Entity (XXE)
- XML Bomb attacks
- Entity expansion attacks
- Mitigation techniques
16. Secure Coding Best Practices
- Input validation
- Output encoding
- Secure error handling
- Secure logging
- Defensive programming
- Secure exception handling
- Dependency management
17. Security Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Dependency vulnerability scanning
- Penetration testing overview
- Secure code review techniques
18. Secure Deployment and Operations
- Secure software configuration
- Secrets management
- Environment hardening
- Security monitoring
- Patch management
- Secure DevOps concepts
19. Incident Response and Vulnerability Management
- Security incident lifecycle
- Vulnerability assessment
- CVE and CVSS overview
- Security advisories
- Responsible vulnerability disclosure
- Remediation planning
20. Hands-on Secure Coding Workshop
- Implementing secure communication
- Configuring TLS correctly
- Using cryptographic libraries safely
- Identifying insecure code
- Fixing common security flaws
- Secure XML processing exercises
21. Summary and Further Learning
- Review of key security concepts
- Common implementation pitfalls
- Secure coding standards and guidelines
- OWASP recommendations
- Industry frameworks and compliance
- Additional learning resources
- Questions and answers
Requirements
None.
21 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated