Security for web applications developed in .NET, Java and C++
Your applications need security built into design and development decisions. Identify vulnerabilities, relate them to coding practices and examine possible safeguards. Strengthen your ability to discuss risks and guide corrective action.
- Duration
- 4 days 28 hours
- Code
- SEC-APP Code
Presentation
Web applications have become established in the digital market thanks to their flexibility, usability and accessibility. Security remains a major concern, however, because applications are targeted by numerous cyberattacks. Whether you are a developer, integrator or Chief Information Security Officer (CISO), you need to consider how your organisation's web applications are protected.
This course provides the key knowledge needed to maximise application security across your information systems. Over 4 days, you will explore security components and techniques in detail. For applications developed in .NET, Java or C++, you will learn about the different attacks you may face and the best practices to adopt.
Alongside essential theory, this application security course includes extensive practical exercises across 8 modules. These help you apply the techniques you learn when you return to your organisation.
Objectives
This web application security course will enable you to:
- Understand security principles for applications developed in Java, .NET and C++.
- Maintain web applications under heavy load and validate their quality.
- Analyse code effectively to detect potential security weaknesses.
- Apply web application development best practices.
Program
Module 1: application security principles
- The 6 elements of application security: authentication, access control, data integrity and confidentiality, non-repudiation, and protection against traffic analysis.
- Using .NET application security tools.
- Implementing runtime security.
- Implementing authentication.
- Implementing access control and data protection.
- Threat forms and types.
- Implementing input validation.
Module 2: reviewing and securing Java code
- Analysing code quality and security with SonarQube and Abstract Syntax Trees (AST).
- Installing and using SonarQube in Eclipse.
- Securing Java 2 Enterprise Edition with web.xml: authentication realms, CAS and SSO.
- Using Spring Security for authentication: resource-based and method-level security.
Module 3: reviewing and securing C++ code
- Protecting assembly code through signatures and data validation.
- C++ protection models.
- Configuring the Common Language Runtime (CLR).
- Implementing a code access security policy for CLR integration.
- Best practices for deploying and running C++ applications.
Practical exercises:
- Load and secure Code Access Security (CAS).
- Load and unload application domain code.
Module 4: securing a .NET application with encryption
- Cryptography principles: symmetric and asymmetric methods, and encryption engine operation.
- Using encryption for certificates and .NET application signing.
- Implementing SSL and HTTPS to secure communications.
Practical exercises:
- Encrypt and decrypt data.
Module 5: authentication and access management
- .NET authentication systems and role-based authentication principles.
- Implementing .NET policies: code groups.
- Implementing a data protection model.
- Application execution restrictions.
- Implementing protected data storage.
Practical exercises:
- Create and modify identity and principal objects in .NET.
- Add and remove access control list entries: ACL and DACL.
- Create security policies with mscorcfg.msc.
Module 6: addressing security vulnerabilities with ASP.NET
- The 10 major vulnerabilities identified by the Open Web Application Security Project (OWASP).
- SQL injection attacks.
- Cross-site scripting (XSS).
- Session hijacking.
- Insecure Direct Object References (IDOR).
- Cross-site request forgery (CSRF).
Module 7: securing applications with C++
- The C++17 memory model.
- Program compilation.
- Function call stack frames.
- Secure coding best practices.
- C++ strings and pointers.
- Memory management.
- Input and output functions.
- Protecting file access.
Practical exercises:
- Analyse secure and insecure code.
Module 8: applying programming best practices
- Basic coding rules.
- Macros and inline functions.
- Memory management and error handling.
- Structures versus classes.
- Compilation from C++14 to C++17.
- Application security standards.
- Code validation.
Audience
This course is intended for:
- Developers, application designers and professionals involved in production, management or integration who want to improve web application security.
Prerequisites
To attend this web application security course, you should:
- Have a solid understanding of object-oriented programming in Java, .NET or C++.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Course content offered in partnership with Softeam Institute (in French).
fr
en