Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
1. Introduction to IT Security and Secure Coding
- Core principles of information security
- Confidentiality, Integrity, and Availability (CIA)
- Authentication, authorization, and accountability mechanisms
- Principles of security by design
- Secure Software Development Lifecycle (SSDLC)
- Common software security risks
- Fundamentals of secure coding
2. Requirements of Secure Communication
- Ensuring confidentiality
- Maintaining data integrity
- User authentication
- Non-repudiation
- System availability
- Secure identification
- Privacy and anonymity considerations
- Threat modeling for networked applications
3. Network Security Fundamentals
- OSI and TCP/IP security models
- Network architecture basics
- Common network protocols
- Attack surfaces in networked applications
- Firewalls and network segmentation strategies
- Principles of secure network design
4. Network Attacks and Defenses
- Packet sniffing techniques
- Spoofing attacks
- Man-in-the-Middle (MITM) threats
- Session hijacking
- Replay attacks
- Denial-of-Service (DoS) and Distributed DoS
- Network monitoring and intrusion detection systems
5. Practical Cryptography Fundamentals
- Key cryptographic terminology
- Symmetric encryption basics
- Asymmetric encryption basics
- Hash functions
- Message Authentication Codes (MAC)
- Digital signatures
- Random number generation
- Key management concepts
6. Symmetric and Asymmetric Cryptography
- AES and modern symmetric algorithms
- RSA fundamentals
- Elliptic Curve Cryptography (ECC)
- Hybrid encryption approaches
- Key exchange mechanisms
- Practical implementation considerations
7. Hashing and Password Security
- Cryptographic hash functions
- Password hashing algorithms
- Salt and pepper techniques
- Key derivation functions
- Secure credential storage methods
- Common password attack techniques
- Best practices for password security
8. Public Key Infrastructure (PKI)
- Digital certificates
- Certificate Authorities (CA)
- Certificate chains
- Certificate validation processes
- Certificate revocation mechanisms
- Trust models
- Practical PKI deployment strategies
9. Security Protocols
- SSL and TLS architecture
- TLS handshake process
- HTTPS communication
- IPsec overview
- VPN technologies
- Secure Shell (SSH)
- Secure email protocols
- Best practices for secure communication
10. Cryptographic Vulnerabilities
- Weak cryptographic algorithms
- Poor key management practices
- Insecure random number generation
- Padding oracle attacks
- Timing attacks
- Side-channel attacks
- Common cryptographic implementation errors
11. Analysis of Real-World Cryptographic Attacks
- BEAST attack
- BREACH attack
- CRIME attack
- TIME attack
- POODLE attack
- FREAK attack
- Logjam attack
- Lucky Thirteen attack
- RSA timing attacks
- Lessons learned from historical vulnerabilities
12. Secure Network Application Development
- Designing secure communication
- Securing API communication
- Secure session management
- Secure authentication mechanisms
- Secure token handling
- Secure configuration management
13. Web Services Security
- Web services architecture
- SOAP security
- REST security considerations
- Authentication methods
- Authorization strategies
- Secure service-to-service communication
14. XML Security
- XML fundamentals
- XML Signature
- XML Encryption
- XML Key Management
- Secure XML processing
- XML validation
15. XML-Based Attacks
- XML Injection
- XPath Injection
- XML External Entity (XXE)
- XML Bomb attacks
- Entity expansion attacks
- Mitigation techniques
16. Secure Coding Best Practices
- Input validation
- Output encoding
- Secure error handling
- Secure logging practices
- Defensive programming techniques
- Secure exception handling
- Dependency management
17. Security Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Dependency vulnerability scanning
- Penetration testing overview
- Secure code review techniques
18. Secure Deployment and Operations
- Secure software configuration
- Secrets management
- Environment hardening
- Security monitoring
- Patch management
- Secure DevOps concepts
19. Incident Response and Vulnerability Management
- Security incident lifecycle
- Vulnerability assessment processes
- CVE and CVSS overview
- Security advisories
- Responsible vulnerability disclosure
- Remediation planning
20. Hands-on Secure Coding Workshop
- Implementing secure communication
- Configuring TLS correctly
- Using cryptographic libraries safely
- Identifying insecure code patterns
- Fixing common security flaws
- Secure XML processing exercises
21. Summary and Further Learning
- Review of key security concepts
- Common implementation pitfalls
- Secure coding standards and guidelines
- OWASP recommendations
- Industry frameworks and compliance requirements
- Additional learning resources
- Questions and answers session
Requirements
No prior experience is required.
21 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated