Securing Java and Java EE Applications
Your applications need to integrate security into design and development decisions. Identify vulnerabilities, connect them with coding practices and examine possible safeguards. Strengthen your ability to discuss risks and guide corrective action.
- Duration
- 3 days 21 hours
- Code
- JAV32FR Code
Presentation
Like other computer networks and software, Java and Java EE applications face security challenges that must be understood. This course provides a comprehensive understanding of application risks and trains you in the tools and techniques needed to protect them.
Objectives
- Understand security challenges.
- Understand the role of CERTs.
- Implement a security policy for a Java application.
- Apply CERT recommendations.
- Secure a Java EE application using Tomcat and WildFly.
- Implement an SSL/TSL layer.
- Understand encryption principles.
Teaching approach:
- Presentation of concepts followed by practical workshops.
- 60% workshops.
Program
- Basic concepts.
- Security challenges.
- Risks.
- Security monitoring organisations.
- CERT and OWASP.
- Exploits and proofs of concept.
- Coding best practices.
- Common attacks.
- The WASP top 10.
- Injection.
- XSS.
- The WASP top 10.
- Encryption.
- Cryptography objectives.
- Weak encryption.
- Symmetric encryption.
- DES, AES, Blowfish and others.
- Asymmetric encryption.
- RSA, GPS, ECC keys and others.
- The Diffie-Hellman protocol.
- Digests.
- Blocks.
- MD2, MD5, SHA-1, SHA-2 and SHA-3.
- Sealing and signatures.
- Certificates.
- CA: Certificate Authority.
- Certificate structure.
- Certificate life cycle.
- Keytool tools.
- Java certificate factory.
- Securing Java applications.
- Writing secure applications.
- CERT - Platform Security (SEC).
- Logs, networks and databases.
- Applications and sandboxes.
- ClassLoaders.
- SecurityManager and AccessControler.
- java.policy and security.policy files.
- Access Control Lists (ACLs).
- Principles.
- Calculating permissions.
- Adding entries and checking access.
- Writing secure applications.
- JAAS.
- Basic principles.
- Main classes.
- Security policies.
- Creating JAAS plugins.
- SSO - Kerberos.
- Securing Java web applications.
- Session management.
- Timeouts, URL rewriting and session ID rotation.
- Realms.
- Security constraints in web.xml.
- Tomcat.
- Configuring a realm.
- Setting up SSL.
- JBoss 7 / WildFly.
- Configuring a realm.
- Setting up SSL.
- Session management.
- Securing EJBs.
- Annotations and XML.
- Interceptors.
Audience
This course is intended for developers and project managers.
Prerequisites
- Knowledge of Java.
- Knowledge of Java EE architecture.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en