Secure Web Application And Coding
| March 21, 2012 | to | March 23, 2012 |
Philippines
Today, there are no web developers who want to go extra mile of introducing security into their code, unless they are security conscious or have an interest in security. The strict deadlines and pressures on developers themselves exhaust their time on projects resulting in a vulnerable web applications which could lead to theft of millions of credit cards, major financial and reputational damage, and even the compromise of thousands of browsing machines that visited Web sites altered by attackers.
This topic discusses security logging, input validation, encoding, authorization, authentication, prepared statements, exception handling, and other topics in the context of web development languages.
WORKSHOP OUTLINE
• Security Principles Overview
o Importance of Security In the Software Development Lifecycle
o Elements of Secure Application Development
o Risk Assessment
o Threat Modeling
o Defense In-Depth
o Positive Security Model
o Principle of Least Privilege
o Separation of Duties
o Security by Obscurity
• Cryptography
o Symmetric and Asymmetric Encryption
o Hashing
o Digital Signatures
o Certificates
o SSL
• Authentication
o Methods of Authentication
o Common Authentication Attacks
o Implementing Secure Authentication – Design and Coding
• Authorization and Access Control
o Methods of Access Control
Discretionary Access Control
Rule-Based Access Control
Role-Based Access Control
o Common Authorization Attacks
o Implementing Secure Authentication – Design and Coding
• Session Management
o Overview of Sessions
o Threats to Sessions and Impact
o Common Implementation Mistakes and Exploits
o Implementing Secure Sessions – Design and Coding
• Input/Output Validation
o Validation Overview
o Common Exploits (SQL Injection, Cross-Site Scripting, HTTP Response Splitting, etc.)
o Implementing Secure Input/Output Validation – Design and Coding
• Error Handling
• Logging
• Building Secure AJAX Applications
Attendance cost: contact us
Event organizer: Judy
Register for the Secure Web Application And Coding Training
Your Comment