|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/cloud-top-ten-risks
课程评论:没有评论
课程名称:云计算十大风险 课程概述:完成本课程后,学生应能够做到以下几点: ● 将OWASP十大风险名单与主要云计算网络安全风险关联起来。 ● 应用适当的加密技术来保护身份验证机制和云数据。 ● 确定抵御注入攻击、跨站脚本攻击和对象反序列化攻击的最有效策略。 ● 评估应对因管理失误(包括配置错误、破损访问控制、脆弱软件组件和安全监控)引发的风险的策略。 课程大纲: 1. 名称:十大风险概述 描述:介绍十大云风险及其与已发布的OWASP十大风险名单的关系。重点考察最高优先级的风险:注入攻击。 2. 名称:云风险2、3和4 描述:本模块回顾因身份验证失败、敏感数据暴露和可用性风险(如洪水攻击)而产生的风险。 3. 名称:云风险5、6和7 描述:本模块回顾因访问控制失败、安全配置错误和跨站脚本攻击而产生的风险。 4. 名称:云风险8、9和10 描述:本模块回顾因不安全的反序列化、缺陷软件组件以及日志或监控不足而产生的风险。
Name:Overview of the Top Ten Risks
Description:Introduce the Top Ten Cloud Risks and their relationship to published OWASP Top Ten risk lists. Examine the highest-priority risk: injection attacks.
Name:Cloud Risks 2, 3, and 4
Description:This module reviews risks arising from authentication failures, sensitive data exposure, and availability risks (e.g. flooding).
Name:Cloud Risks 5, 6, and 7
Description:This module reviews risks arising from access control failures, security misconfiguration, and cross-site scripting.
Name:Cloud Risks 8, 9, and 10
Description:This module reviews risks arising from insecure deserialization, flawed software components, and inadequate logging or monitoring.
After completing the course, the student should be able to do the following: ● Associate lists of OWASP Top Ten Risks with major cloud cybersecurity risks. ● Apply appropriate cryptographic techniques to secure authentication mechanisms and cloud data. ● Identify the most effective strategies for resisting injection attacks, cross-site scripting attacks, and object deserialization attacks. ● Assess strategies to address risks posed by administrative failures, including misconfiguration, broken access control, vulnerable software components, and security monitoring.