Merci d'avoir envoyé votre demande ! Un membre de notre équipe vous contactera sous peu.
Merci d'avoir envoyé votre réservation ! Un membre de notre équipe vous contactera sous peu.
Plan du cours
1. Introduction to IT Security and Secure Coding
- Information security principles
- Confidentiality, Integrity, and Availability (CIA)
- Authentication, authorization, and accountability
- Security by design
- Secure Software Development Lifecycle (SSDLC)
- Common software security risks
- Secure coding principles
2. Requirements of Secure Communication
- Confidentiality
- Integrity
- Authentication
- Non-repudiation
- Availability
- Secure identification
- Privacy and anonymity
- Threat modeling for networked applications
3. Network Security Fundamentals
- OSI and TCP/IP security model
- Network architecture
- Common network protocols
- Attack surfaces in networked applications
- Firewalls and network segmentation
- Secure network design principles
4. Network Attacks and Defenses
- Packet sniffing
- Spoofing attacks
- Man-in-the-Middle (MITM)
- Session hijacking
- Replay attacks
- Denial-of-Service (DoS) and Distributed DoS
- Network monitoring and intrusion detection
5. Practical Cryptography Fundamentals
- Cryptographic terminology
- Symmetric encryption
- Asymmetric encryption
- Hash functions
- Message Authentication Codes (MAC)
- Digital signatures
- Random number generation
- Key management concepts
6. Symmetric and Asymmetric Cryptography
- AES and modern symmetric algorithms
- RSA fundamentals
- Elliptic Curve Cryptography (ECC)
- Hybrid encryption
- Key exchange mechanisms
- Practical implementation considerations
7. Hashing and Password Security
- Cryptographic hash functions
- Password hashing algorithms
- Salt and pepper techniques
- Key derivation functions
- Secure credential storage
- Password attack techniques
- Password security best practices
8. Public Key Infrastructure (PKI)
- Digital certificates
- Certificate Authorities (CA)
- Certificate chains
- Certificate validation
- Certificate revocation
- Trust models
- Practical PKI deployment
9. Security Protocols
- SSL and TLS architecture
- TLS handshake
- HTTPS communication
- IPsec overview
- VPN technologies
- Secure Shell (SSH)
- Secure email protocols
- Secure communication best practices
10. Cryptographic Vulnerabilities
- Weak cryptographic algorithms
- Poor key management
- Insecure random number generation
- Padding oracle attacks
- Timing attacks
- Side-channel attacks
- Cryptographic implementation mistakes
11. Analysis of Real-World Cryptographic Attacks
- BEAST
- BREACH
- CRIME
- TIME
- POODLE
- FREAK
- Logjam
- Lucky Thirteen
- RSA timing attacks
- Lessons learned from historical vulnerabilities
12. Secure Network Application Development
- Secure communication design
- Secure API communication
- Secure session management
- Secure authentication mechanisms
- Secure token handling
- Secure configuration management
13. Web Services Security
- Web services architecture
- SOAP security
- REST security considerations
- Authentication methods
- Authorization strategies
- Secure service communication
14. XML Security
- XML fundamentals
- XML Signature
- XML Encryption
- XML Key Management
- Secure XML processing
- XML validation
15. XML-Based Attacks
- XML Injection
- XPath Injection
- XML External Entity (XXE)
- XML Bomb attacks
- Entity expansion attacks
- Mitigation techniques
16. Secure Coding Best Practices
- Input validation
- Output encoding
- Secure error handling
- Secure logging
- Defensive programming
- Secure exception handling
- Dependency management
17. Security Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Dependency vulnerability scanning
- Penetration testing overview
- Secure code review techniques
18. Secure Deployment and Operations
- Secure software configuration
- Secrets management
- Environment hardening
- Security monitoring
- Patch management
- Secure DevOps concepts
19. Incident Response and Vulnerability Management
- Security incident lifecycle
- Vulnerability assessment
- CVE and CVSS overview
- Security advisories
- Responsible vulnerability disclosure
- Remediation planning
20. Hands-on Secure Coding Workshop
- Implementing secure communication
- Configuring TLS correctly
- Using cryptographic libraries safely
- Identifying insecure code
- Fixing common security flaws
- Secure XML processing exercises
21. Summary and Further Learning
- Review of key security concepts
- Common implementation pitfalls
- Secure coding standards and guidelines
- OWASP recommendations
- Industry frameworks and compliance
- Additional learning resources
- Questions and answers
Pré requis
None.
21 Heures
Nos clients témoignent (3)
Le partage d'expérience, c'est le savoir-faire et la valeur de l'enseignant.
Carey Fan - Logitech
Formation - C/C++ Secure Coding
Traduction automatique
les connaissances du formateur étaient très élevées - il savait de quoi il parlait et avait les réponses à nos questions
Adam - Fireup.PRO
Formation - Advanced Java Security
Traduction automatique
Le sujet est d'actualité et j'avais besoin de me mettre à jour
Damilano Marco - SIAP s.r.l.
Formation - Secure Developer Java (Inc OWASP)
Traduction automatique