Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. IT Security and Secure Coding
- Core Security Principles: Applying Confidentiality, Integrity, and Availability (CIA) to Java applications.
- Secure Software Development Lifecycle (SSDLC): Embedding security into every phase, from requirements gathering to deployment.
- Secure Coding Paradigms: Implementing defense in depth, least privilege, and fail-safe defaults.
- Vulnerability Classifications: Gaining insight into CWE (Common Weakness Enumeration) and OWASP standards.
2. Web Application Security
- In-Depth Analysis of OWASP Top Ten: Detailed examination of Injection, Broken Authentication, and Sensitive Data Exposure.
- Cross-Site Scripting (XSS): Managing Reflected, Stored, and DOM-based XSS scenarios in Java/JSP environments.
- Cross-Site Request Forgery (CSRF): Understanding attack mechanisms and implementing Anti-CSRF tokens.
- Session Management: Ensuring cookie security, preventing session fixation, and managing timeouts.
- API Security: Protecting REST and SOAP endpoints from misuse.
3. Web Services Security
- Web Services vs. Traditional Web Apps: Differentiating attack surfaces.
- Transport Layer Security: Configuring SSL/TLS for Java clients and servers.
- Message Security: Ensuring Integrity and Confidentiality at the payload level.
- Authentication Standards: Implementing OAuth 2.0, OpenID Connect, and JWT (JSON Web Tokens).
4. XML Security
- XML Parsing Vulnerabilities: Mitigating XML External Entity (XXE) attacks.
- XML Schema Validation: Best practices for enforcing strict schemas.
- XML Digital Signatures: Implementing signatures to guarantee non-repudiation.
- XML Encryption: Standard methods for encrypting XML content.
5. Java Security Fundamentals
- Java Security Architecture: Exploring the
java.securitypackage and provider model. - Security Providers: Setting up and configuring providers such as Bouncy Castle.
- Access Control: Managing policy files, Permissions, and the Security Manager (Legacy vs. Modern approaches).
- KeyStore Management: Creating and maintaining keystores and truststores for certificates.
6. Applied Cryptography
- Cryptographic Algorithms: Overview of Symmetric (AES), Asymmetric (RSA, ECC), and Hashing (SHA-256/512) techniques.
- Random Number Generation: Comparing the risks of
java.util.Randomwithjava.security.SecureRandom. - Key Management: Strategies for key generation, storage, and rotation.
- Java Cryptography Architecture (JCA): Utilizing
Cipher,MessageDigest, andMacclasses. - Java Cryptography Extension (JCE): Understanding policy files and unlimited strength jurisdiction.
7. Java Security Services
- SSL/TLS in Java: Utilizing
SSLSocketFactoryandHttpsURLConnection. - Trust Managers: Customizing trust verification for private PKI environments.
- Authenticators: Performing programmatic authentication using
Authenticator.getDefault()/code>. - Certificate Parsing: Programmatically reading and analyzing X.509 certificates.
8. Java EE Security
- Declarative Security: Implementing Role-Based Access Control (RBAC) via
web.xmland annotations. - Programmatic Security: Employing
HttpServletRequest.isUserInRole()/code> andgetRemoteUser()/code>. - JAAS (Java Authentication and Authorization Service): Configuring
login.confand implementingLoginModules. - Servlet Security: Managing container-based security constraints and authentication methods (FORM, BASIC, DIGEST).
9. Common Coding Errors and Vulnerabilities
- Insecure Deserialization: Assessing risks associated with
ObjectInputStreamand bypassing security checks. - Command Injection: Mitigating OS-level execution vulnerabilities.
- Path Traversal: Sanitizing file system inputs to prevent directory traversal issues.
- Reflection Abuse: Managing risks linked to
java.lang.reflectand access control bypasses. - Hardcoded Credentials: Detecting and removing secrets from source code.
- Cryptography Implementation Errors: Avoiding the use of ECB mode, weak keys, or static IVs.
10. Knowledge Sources
- Static Analysis Tools: Leveraging SonarQube, Checkmarx, and Fortify for automated scanning.
- Dynamic Analysis Tools: Overview of Burp Suite and OWASP ZAP.
- CVE Databases: Tracking and responding to emerging Java framework vulnerabilities.
- Recommended Readings: Curated list of books, documentation, and secure coding checklists.
Requirements
No prior requirements.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 4800 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (4)
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
Practical exercises
Olek - Fireup.PRO
Course - Advanced Java Security
coding excercies
Mirek - Fireup.PRO
Course - Advanced Java Security
It opens up a lot and gives lots of insight what security