|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/cloud-application-security
课程评论:没有评论
课程名称:云应用安全 课程概述:完成本课程后,学生将能够: ● 列出并描述OWASP前十大漏洞。 ● 确定在开发生命周期中提供云安全保证的方法,例如在持续交付环境中。 ● 列出并描述用于保护云应用的不同类型的虚拟化或沙箱技术,适用于服务器或客户端。 ● 描述身份验证因素和联合身份解决方案在云客户端和服务器身份验证中的应用。 ● 针对云应用,解释必要的加密密钥、密码和其他安全秘密应如何存储和分发。 课程大纲: 1. **应用安全风险** 描述:本模块介绍了课程的基本内容,并回顾了与云计算相关的OWASP“十大”风险。此外,还包括有关数据包网络操作的背景视频。 2. **架构与身份验证** 描述:讨论服务器架构原则,并调查用户身份验证机制的现状。 3. **会话管理** 描述:会话机制用于在独立的无状态HTTP事务或Web API中维护应用状态。 4. **服务提供者、加密与脚本** 描述:这些视频涵盖了额外的主题,包括服务提供者信任、使用服务提供者的加密以及防止基于脚本攻击的安全机制。 本课程旨在帮助学生深入理解云应用中的安全问题,提供实用的知识和技能,以提升他们在云安全领域的专业能力。
Name:Application Security Risks
Description:This module introduces the course and reviews OWASP "Top Ten" risks relevant to cloud computing. There are also background videos on packet network operation.
Name:Architecture and Authentication
Description:A discussion of server architecture principles and survey of user authentication mechanisms.
Name:Session Management
Description:The session mechanism maintains application state across independent, stateless transactions via HTTP or a web API.
Name:Providers, Crypto, and Scripts
Description:These videos cover additional topics: provider trust, using provider crypto, and security mechanisms for preventing script-based attacks.
After completing the course, the student should be able to do the following: ● List and describe the OWASP Top 10 vulnerabilities. ● Identify methods to provide cloud security assurance as part of the development life cycle, e.g. in a continuous delivery environment. ● List and describe the different types of virtualization or sandboxing used to protect cloud applications at either the server or client. ● Describe the application of authentication factors and federated identity solutions in cloud client and server authentication. ● Given a cloud application, explain where and how the necessary crypto keys, passwords, and other security secrets should be stored and distributed.