Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours (3 days)
Course Outline
1. IT security and secure coding
- Core Security Principles: Application of Confidentiality, Integrity, and Availability (CIA) to Java applications.
- Secure Software Development Lifecycle (SSDLC): Embedding security measures from the requirements phase through to deployment.
- Secure Coding Principles: Implementing defense in depth, the principle of least privilege, and fail-safe defaults.
- Standard Vulnerability Classifications: Familiarization with CWE (Common Weakness Enumeration) and OWASP standards.
2. Web application security
- In-Depth Analysis of OWASP Top Ten: Detailed examination of Injection, Broken Authentication, and Sensitive Data Exposure.
- Cross-Site Scripting (XSS): Analyzing Reflected, Stored, and DOM-based XSS scenarios in Java/JSP environments.
- Cross-Site Request Forgery (CSRF): Understanding attack mechanisms and implementing Anti-CSRF tokens.
- Session Management: Enhancing cookie security, preventing session fixation, and managing timeouts.
- API Security: Protecting REST and SOAP endpoints from abuse.
3. Security of Web services
- Web Services vs. Traditional Web Apps: Identifying distinct differences in attack surfaces.
- Transport Layer Security: Configuring SSL/TLS for Java clients and servers.
- Message Security: Ensuring integrity and confidentiality at the payload level.
- Authentication Standards: Implementation of OAuth 2.0, OpenID Connect, and JWT (JSON Web Tokens).
4. XML security
- XML Parsing Vulnerabilities: Preventing XML External Entity (XXE) attacks.
- XML Schema Validation: Best practices for enforcing strict schema validation.
- XML Digital Signatures: Implementing signatures to guarantee non-repudiation.
- XML Encryption: Adopting standard methods for encrypting XML content.
5. Foundations of Java security
- Java Security Architecture: Exploration of the
java.securitypackage and provider architecture. - Security Providers: Installation and configuration of providers such as Bouncy Castle.
- Access Control: Managing policy files, Permissions, and the Security Manager (comparing legacy and modern approaches).
- KeyStore Management: Creation and administration of keystores and truststores for certificate management.
6. Practical cryptography
- Cryptographic Algorithms: Overview of Symmetric (AES), Asymmetric (RSA, ECC), and Hashing (SHA-256/512) algorithms.
- Random Number Generation: Comparison of the risks associated with
java.util.Randomversusjava.security.SecureRandom. - Key Management: Strategies for key generation, secure storage, and rotation.
- Java Cryptography Architecture (JCA): Utilization of
Cipher,MessageDigest, andMacclasses. - Java Cryptography Extension (JCE): Understanding policy files and unlimited strength jurisdiction settings.
7. Java security services
- SSL/TLS in Java: Utilizing
SSLSocketFactoryandHttpsURLConnection. - Trust Managers: Customizing trust verification for private PKI environments.
- Authenticators: Implementing programmatic authentication using
Authenticator.getDefault(). - Certificate Parsing: Programmatic reading and analysis of X.509 certificates.
8. Java EE security
- Declarative Security: Implementing Role-based access control (RBAC) via
web.xmland annotations. - Programmatic Security: Utilizing
HttpServletRequest.isUserInRole()andgetRemoteUser(). - JAAS (Java Authentication and Authorization Service): Configuration of
login.confand implementation ofLoginModules. - Servlet Security: Managing container security constraints and authentication methods (FORM, BASIC, DIGEST).
9. Common coding errors and vulnerabilities
- Insecure Deserialization: Assessing risks associated with
ObjectInputStreamand potential security check bypasses. - Command Injection: Mitigating OS-level execution vulnerabilities.
- Path Traversal: Sanitizing file system inputs to prevent directory traversal attacks.
- Reflection Abuse: Evaluating risks linked to
java.lang.reflectand potential access control bypasses. - Hardcoded Credentials: Identifying and eliminating secrets embedded in source code.
- Cryptography Implementation Errors: Avoiding the use of ECB mode, weak keys, or static IVs.
10. Knowledge sources
- Static Analysis Tools: Leveraging SonarQube, Checkmarx, and Fortify for automated code scanning.
- Dynamic Analysis Tools: Overview of Burp Suite and OWASP ZAP capabilities.
- CVE Databases: Strategies for tracking and responding to new Java framework vulnerabilities.
- Recommended Readings: A curated list of books, documentation, and secure coding checklists.
Requirements
No prior prerequisites are required.
Testimonials (4)
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
Practical exercises
Olek - Fireup.PRO
Course - Advanced Java Security
coding excercies
Mirek - Fireup.PRO
Course - Advanced Java Security
It opens up a lot and gives lots of insight what security