Get in Touch
 Duration 21 hours (3 days)

Course Outline

Introduction to IT Security and Secure Coding

  • Overview of secure software development principles
  • Identifying common security risks in application development
  • Cultivating a security mindset and defensive programming habits
  • Adhering to secure coding standards and best practices

.NET Security Architecture and Services

  • Examining the .NET security model
  • Comprehending managed code security concepts
  • Safeguarding resources and application components
  • Exploring authentication and authorization mechanisms
  • Mitigating unauthorized access and privilege escalation

Secure Application Design in .NET

  • Architecting secure application structures
  • Integrating security principles throughout the development lifecycle
  • Managing trust boundaries and handling untrusted code
  • Ensuring secure management of application resources
  • Implementing secure communication patterns

Practical Cryptography for .NET Developers

  • Cryptographic fundamentals
  • Understanding encryption, hashing, and digital signatures
  • Utilising cryptographic features within .NET
  • Key management and secure cryptographic operations
  • Correct application of cryptography in software development

Cryptographic Vulnerabilities and Attacks

  • Identifying weaknesses in cryptographic implementations
  • Overview of contemporary cryptographic threats
  • RSA timing attacks and side-channel vulnerabilities
  • Best practices for using cryptographic algorithms and protocols securely

ASP.NET Security Architecture

  • Examining ASP.NET security mechanisms
  • Authentication and authorization within ASP.NET applications
  • Secure session management strategies
  • Protecting application state and sensitive user data
  • Implementing secure web application standards

ASP.NET Configuration and Hardening

  • Securing the ASP.NET environment
  • Best practices for application configuration
  • Hardening web servers and application settings
  • Minimising potential attack surfaces
  • Managing security-relevant configuration options

XML and Data Security

  • Understanding security risks associated with XML
  • Preventing XML injection attacks
  • Securing XML processing workflows
  • Defending applications against malicious data inputs

Common .NET and ASP.NET Vulnerabilities

  • Input validation deficiencies
  • Improper error and exception handling
  • Race conditions
  • Insecure coding patterns
  • Denial-of-service vulnerabilities
  • ASP.NET-specific threats:
    • ViewState manipulation
    • String termination attacks

Secure Coding Practices and Testing Techniques

  • Applying secure development methodologies
  • Identifying and rectifying common coding errors
  • Utilising security testing tools
  • Conducting vulnerability analysis
  • Enhancing application resilience against attacks

Practical Workshop and Course Review

  • Applying secure coding techniques through hands-on exercises
  • Identifying vulnerabilities within .NET applications
  • Implementing effective mitigation strategies
  • Reviewing security best practices and recommended learning resources

Requirements

No prior requirements.

Testimonials (3)

Upcoming Courses

Related Categories