Course Overview

Secure Java Web Application Development is a seminar style course designed for Java web developers and technical stakeholders who need to produce secure Java web applications. Our web app security expert will share how to integrate security measures into the development process. You will also explore core concepts and challenges in web application security, showcasing real world examples that illustrate the potential consequences of not following these best practices.

Security experts agree that the least effective approach to security is ‘penetrate and patch’. It is far more effective to ‘bake’ security into an application throughout its lifecycle. After spending significant time examining a poorly designed (from a security perspective) web application, you are ready to learn how to build secure web applications starting at project inception. The final portion of this course builds on the previously learned mechanics for building defenses by exploring how design and analysis can be used to build stronger applications from the beginning of the software lifecycle.

Students who attend Secure Java Web Application Development will gain an understanding of how to recognize actual and potential software vulnerabilities, implement defenses for those vulnerabilities, and test those defenses for sufficiency. This course introduces most common security vulnerabilities faced by web applications today. Each vulnerability is examined from a coding perspective through a process of describing the threat and attack mechanisms, recognizing associated vulnerabilities, and, finally, designing, implementing, and testing effective defenses.

What you’ll learn
  • Ensure that any hacking and bug hunting is performed in a safe and appropriate manner
  • Identify defect/bug reporting mechanisms within their organizations
  • Avoid common mistakes that are made in bug hunting and vulnerability testing
  • Understand the concepts and terminology behind defensive, secure coding including the phases and goals of a typical exploit
  • Develop an appreciation for the need and value of a multilayered defense in depth
  • Understand potential sources for untrusted data
  • Understand the consequences for not properly handling untrusted data such as denial of service, cross-site scripting, and injections
  • Prevent and defend the many potential vulnerabilities associated with untrusted data
  • Understand the vulnerabilities of associated with authentication and authorization
  • Detect, attack, and implement defenses for authentication and authorization functionality and services
  • Understand the dangers and mechanisms behind Cross-Site Scripting (XSS) and Injection attacks
  • Detect, attack, and implement defenses against XSS and Injection attacks
  • Understand the risks associated with XML processing, file uploads, and server-side interpreters and how to best eliminate or mitigate those risks
  • Understand techniques and measures that can used to harden web and application servers as well as other components in your infrastructure

Requirements

  • Real-world programming experience is highly recommended for code reviews, but not required. Students should have basic development skills and a working knowledge in the following topics, or attend these courses as a pre-requisite: TT5102 JEE Web Essentials

Target audiences

  • This is an introductory-level course lecture and demonstration style course, designed to provide technical application project stakeholders with a first-look or baseline understanding of how to develop well defended web applications.

Curriculum

  • 7 Sections
  • 7 Lessons
  • 2 Days
Expand all sectionsCollapse all sections

Instructor

User Avatar

Ashley

Ashley Laing
0.0
0 Reviews
0 Students
1 Courses