Software Development

Secure Application Development

Overview

Secure Application Development is designed to provide engineering staff with a comprehensive overview of building secure applications in the modern computing world. All aspects of software development (design, construction, testing, and deployment) are impacted by security concerns. This course addresses both vulnerabilities and mitigation techniques throughout the development cycle to ensure a robust development environment.

Each module presented covers a new aspect of development security and is followed by a lab that presents vulnerability examples and their mitigation techniques. All of the vulnerabilities in the OWASP Top 10 are covered throughout the presentations and labs.

Upon completion, developers will be equipped to shift security concerns left, produce more secure code and to eliminate the most prevalent software weaknesses.

Duration

2 Days

Who Should Take This Course

Audience

Developers and QA Professionals.

Prerequisites

Intermediate programming experience with C, Java and/or Python.

Why You Should Take This Course

Upon completing the Secure Application Development course, attendees will be able to:

  • Understand the challenges associated with building secure applications
  • Articulate what must be protected (personal & corporate)
  • Describe how language choice affects security
  • Define security needs within the SDLC and supply chain
  • List common threats and how to mitigate them
  • Demonstrate an understanding of and ability to manage the OWASP Top 10
  • Test for security

Course Outline

Secure Application Development

Day 1

1. Introduction to Secure Programming

  • Software and Security Overview
  • Common Vulnerabilities and Exposures
  • Layers of Defense
  • Security Requirements
  • Security in Design and Development
  • OWASP
  • Future Attacks
LAB:
  • A03:2021 – Injection
  • SQL Injection
  • Path Injection
  • Cross-Site Scripting

2. Auth

  • AuthN & AuthZ (Authentication & Authorization)
  • 1, 2 & multi Factor AuthN Techniques
  • Zero Trust
  • Least Privilege
  • Encryption & Network Security
LAB:
  • A01:2021 – Broken Access Control
  • A07:2021 – Identification and Authentication Failures

3. Software Supply Chain Security

  • NIST – Secure Software Development Framework
  • Supply-chain Levels for Software Artifacts
  • Secure Supply Chain Consumption Framework
  • Graph for Understanding Artifact Composition
  • Examples of Package Vulnerabilities
  • Libraries vs. Frameworks & Security
  • Practical Security Tips for Package Use
LAB:
  • A06:2021 – Vulnerable and Outdated Components
  • A08:2021 – Software and Data Integrity Failures

4. Secure Design and Threat Modeling

  • What is Threat Modeling
  • Creating a Threat Matrix
  • Policy Compliance
  • Mitigation Controls
  • Tests Derived from Matrix
  • Secure Design Patterns
  • Protecting Data & Systems
  • Personally Identifiable Information (PII)
  • Corporate Assets & Proprietary Information (PI)
LAB:
  • A04:2021-Insecure Design

Day 2

5. Language-centric Security

  • Common Python Threats
  • Network Vulnerabilities in Python
  • Common C Threats
  • Common Java Threats
  • Resource leak exploitation
LAB:
  • Buffer Overruns
  • Remote Code Execution

6. Testing for Security

  • Right vs. Wrong Ways to Test for Security
  • Using the Threat Matrix for Testing
  • Unit vs. System Tests & Security
  • Can Test-Driven-Design (TDD) Test for Security?
LAB:
  • Cross-Site Request Forgery
  • Building security tests

7. Secure Deployment

  • Deployment Vulnerabilities
  • Cloud vs. Local Deployment Concerns
  • Continuous Integration & Deployment (CI/CD) & Security
  • Engaging Production Early & Continuously
  • Security is a Continuous Process
LAB:
  • A10:2021 – Server-Side Request Forgery
  • A02:2021 – Cryptographic Failures

8. Monitoring

  • Tools & Techniques for Monitoring
  • Notifications
  • Regular Reporting
  • Responding to an Attack
LAB:
  • A09:2021 – Security Logging and Monitoring Failures
Search UMBC Training Centers