Prenez contact avec nous

Plan du cours

1. Introduction to IT Security and Secure Coding

  • Information security principles
  • Confidentiality, Integrity, and Availability (CIA)
  • Authentication, authorization, and accountability
  • Security by design
  • Secure Software Development Lifecycle (SSDLC)
  • Common software security risks
  • Secure coding principles

2. Requirements of Secure Communication

  • Confidentiality
  • Integrity
  • Authentication
  • Non-repudiation
  • Availability
  • Secure identification
  • Privacy and anonymity
  • Threat modeling for networked applications

3. Network Security Fundamentals

  • OSI and TCP/IP security model
  • Network architecture
  • Common network protocols
  • Attack surfaces in networked applications
  • Firewalls and network segmentation
  • Secure network design principles

4. Network Attacks and Defenses

  • Packet sniffing
  • Spoofing attacks
  • Man-in-the-Middle (MITM)
  • Session hijacking
  • Replay attacks
  • Denial-of-Service (DoS) and Distributed DoS
  • Network monitoring and intrusion detection

5. Practical Cryptography Fundamentals

  • Cryptographic terminology
  • Symmetric encryption
  • Asymmetric encryption
  • Hash functions
  • Message Authentication Codes (MAC)
  • Digital signatures
  • Random number generation
  • Key management concepts

6. Symmetric and Asymmetric Cryptography

  • AES and modern symmetric algorithms
  • RSA fundamentals
  • Elliptic Curve Cryptography (ECC)
  • Hybrid encryption
  • Key exchange mechanisms
  • Practical implementation considerations

7. Hashing and Password Security

  • Cryptographic hash functions
  • Password hashing algorithms
  • Salt and pepper techniques
  • Key derivation functions
  • Secure credential storage
  • Password attack techniques
  • Password security best practices

8. Public Key Infrastructure (PKI)

  • Digital certificates
  • Certificate Authorities (CA)
  • Certificate chains
  • Certificate validation
  • Certificate revocation
  • Trust models
  • Practical PKI deployment

9. Security Protocols

  • SSL and TLS architecture
  • TLS handshake
  • HTTPS communication
  • IPsec overview
  • VPN technologies
  • Secure Shell (SSH)
  • Secure email protocols
  • Secure communication best practices

10. Cryptographic Vulnerabilities

  • Weak cryptographic algorithms
  • Poor key management
  • Insecure random number generation
  • Padding oracle attacks
  • Timing attacks
  • Side-channel attacks
  • Cryptographic implementation mistakes

11. Analysis of Real-World Cryptographic Attacks

  • BEAST
  • BREACH
  • CRIME
  • TIME
  • POODLE
  • FREAK
  • Logjam
  • Lucky Thirteen
  • RSA timing attacks
  • Lessons learned from historical vulnerabilities

12. Secure Network Application Development

  • Secure communication design
  • Secure API communication
  • Secure session management
  • Secure authentication mechanisms
  • Secure token handling
  • Secure configuration management

13. Web Services Security

  • Web services architecture
  • SOAP security
  • REST security considerations
  • Authentication methods
  • Authorization strategies
  • Secure service communication

14. XML Security

  • XML fundamentals
  • XML Signature
  • XML Encryption
  • XML Key Management
  • Secure XML processing
  • XML validation

15. XML-Based Attacks

  • XML Injection
  • XPath Injection
  • XML External Entity (XXE)
  • XML Bomb attacks
  • Entity expansion attacks
  • Mitigation techniques

16. Secure Coding Best Practices

  • Input validation
  • Output encoding
  • Secure error handling
  • Secure logging
  • Defensive programming
  • Secure exception handling
  • Dependency management

17. Security Testing

  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Interactive Application Security Testing (IAST)
  • Dependency vulnerability scanning
  • Penetration testing overview
  • Secure code review techniques

18. Secure Deployment and Operations

  • Secure software configuration
  • Secrets management
  • Environment hardening
  • Security monitoring
  • Patch management
  • Secure DevOps concepts

19. Incident Response and Vulnerability Management

  • Security incident lifecycle
  • Vulnerability assessment
  • CVE and CVSS overview
  • Security advisories
  • Responsible vulnerability disclosure
  • Remediation planning

20. Hands-on Secure Coding Workshop

  • Implementing secure communication
  • Configuring TLS correctly
  • Using cryptographic libraries safely
  • Identifying insecure code
  • Fixing common security flaws
  • Secure XML processing exercises

21. Summary and Further Learning

  • Review of key security concepts
  • Common implementation pitfalls
  • Secure coding standards and guidelines
  • OWASP recommendations
  • Industry frameworks and compliance
  • Additional learning resources
  • Questions and answers

Pré requis

None.

 21 Heures

Nombre de participants


Prix par participant

Nos clients témoignent (3)

Cours à venir

Catégories Similaires