このコースについて

100%オンライン

自分のスケジュールですぐに学習を始めてください。

柔軟性のある期限

スケジュールに従って期限をリセットします。

中級レベル

1-2 years of experience with some form of computer programming language like C/C++ or Java.

約12時間で修了

推奨:4 weeks of study, 2-5 hours/week...

英語

字幕:英語

習得するスキル

CryptographyAuthentication Methodssecure programming

100%オンライン

自分のスケジュールですぐに学習を始めてください。

柔軟性のある期限

スケジュールに従って期限をリセットします。

中級レベル

1-2 years of experience with some form of computer programming language like C/C++ or Java.

約12時間で修了

推奨:4 weeks of study, 2-5 hours/week...

英語

字幕:英語

シラバス - 本コースの学習内容

1
5時間で修了

Foundational Topics in Secure Programming

In this module, you will gain exposure to the ideas of threat modeling and applied cryptography. By the end of the module, you will be able to start to create threat models, and think critically about the threat models created by other people. You will be able to apply the STRIDE Method to your threat model and distinguish the trust boundaries in a given system. You will also gain a basic understanding of applied cryptography, such as encryption and secure hashing.

...
14件のビデオ (合計83分), 3 readings, 2 quizzes
14件のビデオ
The STRIDE Method Via Example9 分
STRIDE Threats In More Detail Via Example4 分
Trust Boundaries2 分
Cryptography Basics Introduction3 分
Cryptography Basics: Block Ciphers9 分
Cryptography Basics: Symmetric and Asymmetric Cryptography5 分
Cryptography Basics: Hash Functions9 分
Cryptography Basics: Application to Threat Models4 分
Lab: Threat Model Activity3 分
OWASP Top 10 Proactive Controls and Exploits - Part 16 分
OWASP Top 10 Proactive Controls and Exploits - Part 29 分
3件の学習用教材
A Note From UC Davis10 分
Welcome to Peer Review Assignments!10 分
Reading and Resource20 分
1の練習問題
Module 1 Quiz30 分
2
3時間で修了

Injection Problems

By the end of this module, you will have a fundamental understanding of injection problems in web applications. You'll be able to discuss and describe the three most common types of injection problems: SQL injection, cross-site scripting, and command injection. In order to drive home these concepts, you will be able to work on exploiting a SQL injection vulnerability in the WebGoat application. You'll be able to formulate plans to mitigate injection problems in your applications.

...
17件のビデオ (合計87分), 1 reading, 1 quiz
17件のビデオ
Mitigating SQL Injection Using Prepared Statements3 分
Mitigating SQL Injection Using Stored Procedures3 分
Mitigating SQL Injection Using Whitelisting2 分
Injection Problems in Real Life5 分
Solution Screencast for Lab: Exploit Using WebGoat's SQLi Example7 分
Cross-Site Scripting Introduction3 分
HTTP and Document Isolation8 分
DOM, Dynamically Generating Pages, and Cross-Site Scripting7 分
The 3-Kinds of Cross-Site Scripting Vulnerabilities6 分
Comparing and Contrasting Cross-Site Scripting Vulnerabilities3 分
OWASP Prescribed Cross-site Scripting Prevention Rules - Part 16 分
OWASP Prescribed Cross-site Scripting Prevention Rules - Part 26 分
Command Injection Problems3 分
OWASP Proactive Controls Related to Injections4 分
1件の学習用教材
Resources20 分
1の練習問題
Module 2 Quiz30 分
3
4時間で修了

Problems Arising From Broken Authentication

By the end of this module, you will be able to evaluate a system to determine if it follows the generally prescribed secure methods for authentication and session management in web applications. You'll be able to distinguish the relationship between authentication, session management, and access control. You will also be able to exploit WebGoat's authentication and session management vulnerability. As well as be able to evaluate a system to determine if it performs sufficient security logging such that non-repudiation is enforced. This will help drive the concepts that you will learn in this module.

...
11件のビデオ (合計71分), 1 reading, 1 quiz
11件のビデオ
Handling Error Messages During Authentication4 分
Introduction to Session Management7 分
Enforcing Access Control with Session Management7 分
Session Management Threat: Bruteforce Session IDs10 分
Session Management Theat: Session Fixation Vulnerabilities3 分
Logging and Monitoring3 分
Solution for Lab #3: WebGoat’s Session Management Vulnerability9 分
OWASP Proactive Controls Related to Session Management and Authentication6 分
1件の学習用教材
Resources20 分
1の練習問題
Module 3 Quiz30 分
4
4時間で修了

Sensitive Data Exposure Problems

By the end of this module, you will understand how to effectively store password-related information, and NOT to store the actual plaintext passwords. You will also have a hands on coding assignment that will help you to better understand the mechanisms for effectively storing password-related information. Ready?

...
9件のビデオ (合計36分), 1 reading, 2 quizzes
9件のビデオ
Issue 2: Not Encrypting Sensitive Information2 分
Issue 3: Improperly Storing Passwords5 分
Slowing Down Password Bruteforce Attacks7 分
Issue 4: Using HTTP for Sensitive Client-server4 分
OWASP Proactive Controls Related to Sensitive Data Exposure3 分
Course Summary1 分
1件の学習用教材
Resources20 分
1の練習問題
Module 4 Quiz30 分

講師

Avatar

Sandra Escandor-O'Keefe

Offensive Security Engineer at Fastly
Continuing and Professional Education

カリフォルニア大学デービス校(University of California, Davis)について

UC Davis, one of the nation’s top-ranked research universities, is a global leader in agriculture, veterinary medicine, sustainability, environmental and biological sciences, and technology. With four colleges and six professional schools, UC Davis and its students and alumni are known for their academic excellence, meaningful public service and profound international impact....

よくある質問

  • 修了証に登録すると、すべてのビデオ、テスト、およびプログラミング課題(該当する場合)にアクセスできます。ピアレビュー課題は、セッションが開始してからのみ、提出およびレビューできます。購入せずにコースを検討することを選択する場合、特定の課題にアクセスすることはできません。

さらに質問がある場合は、受講者向けヘルプセンターにアクセスしてください。