Get in Touch
 Duration 21 hours

Course Outline

1. IT Security and Secure Coding

  • Core Security Principles: Applying Confidentiality, Integrity, and Availability (CIA) to Java applications.
  • Secure Software Development Lifecycle (SSDLC): Embedding security into every phase, from requirements gathering to deployment.
  • Secure Coding Paradigms: Implementing defense in depth, least privilege, and fail-safe defaults.
  • Vulnerability Classifications: Gaining insight into CWE (Common Weakness Enumeration) and OWASP standards.

2. Web Application Security

  • In-Depth Analysis of OWASP Top Ten: Detailed examination of Injection, Broken Authentication, and Sensitive Data Exposure.
  • Cross-Site Scripting (XSS): Managing Reflected, Stored, and DOM-based XSS scenarios in Java/JSP environments.
  • Cross-Site Request Forgery (CSRF): Understanding attack mechanisms and implementing Anti-CSRF tokens.
  • Session Management: Ensuring cookie security, preventing session fixation, and managing timeouts.
  • API Security: Protecting REST and SOAP endpoints from misuse.

3. Web Services Security

  • Web Services vs. Traditional Web Apps: Differentiating attack surfaces.
  • Transport Layer Security: Configuring SSL/TLS for Java clients and servers.
  • Message Security: Ensuring Integrity and Confidentiality at the payload level.
  • Authentication Standards: Implementing OAuth 2.0, OpenID Connect, and JWT (JSON Web Tokens).

4. XML Security

  • XML Parsing Vulnerabilities: Mitigating XML External Entity (XXE) attacks.
  • XML Schema Validation: Best practices for enforcing strict schemas.
  • XML Digital Signatures: Implementing signatures to guarantee non-repudiation.
  • XML Encryption: Standard methods for encrypting XML content.

5. Java Security Fundamentals

  • Java Security Architecture: Exploring the java.security package and provider model.
  • Security Providers: Setting up and configuring providers such as Bouncy Castle.
  • Access Control: Managing policy files, Permissions, and the Security Manager (Legacy vs. Modern approaches).
  • KeyStore Management: Creating and maintaining keystores and truststores for certificates.

6. Applied Cryptography

  • Cryptographic Algorithms: Overview of Symmetric (AES), Asymmetric (RSA, ECC), and Hashing (SHA-256/512) techniques.
  • Random Number Generation: Comparing the risks of java.util.Random with java.security.SecureRandom.
  • Key Management: Strategies for key generation, storage, and rotation.
  • Java Cryptography Architecture (JCA): Utilizing Cipher, MessageDigest, and Mac classes.
  • Java Cryptography Extension (JCE): Understanding policy files and unlimited strength jurisdiction.

7. Java Security Services

  • SSL/TLS in Java: Utilizing SSLSocketFactory and HttpsURLConnection.
  • Trust Managers: Customizing trust verification for private PKI environments.
  • Authenticators: Performing programmatic authentication using Authenticator.getDefault()/code>.
  • Certificate Parsing: Programmatically reading and analyzing X.509 certificates.

8. Java EE Security

  • Declarative Security: Implementing Role-Based Access Control (RBAC) via web.xml and annotations.
  • Programmatic Security: Employing HttpServletRequest.isUserInRole()/code> and getRemoteUser()/code>.
  • JAAS (Java Authentication and Authorization Service): Configuring login.conf and implementing LoginModules.
  • Servlet Security: Managing container-based security constraints and authentication methods (FORM, BASIC, DIGEST).

9. Common Coding Errors and Vulnerabilities

  • Insecure Deserialization: Assessing risks associated with ObjectInputStream and bypassing security checks.
  • Command Injection: Mitigating OS-level execution vulnerabilities.
  • Path Traversal: Sanitizing file system inputs to prevent directory traversal issues.
  • Reflection Abuse: Managing risks linked to java.lang.reflect and access control bypasses.
  • Hardcoded Credentials: Detecting and removing secrets from source code.
  • Cryptography Implementation Errors: Avoiding the use of ECB mode, weak keys, or static IVs.

10. Knowledge Sources

  • Static Analysis Tools: Leveraging SonarQube, Checkmarx, and Fortify for automated scanning.
  • Dynamic Analysis Tools: Overview of Burp Suite and OWASP ZAP.
  • CVE Databases: Tracking and responding to emerging Java framework vulnerabilities.
  • Recommended Readings: Curated list of books, documentation, and secure coding checklists.

Requirements

No prior requirements.

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 4800 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (4)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories