|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/application-security-the-complete-guide/
课程评论:没有评论
课程名称:应用安全 - 完整指南 课程概述: 在当今这个每家公司都成为软件公司的时代,应用程序的安全性变得愈发重要。本课程为软件开发者和安全专业人士提供了全面的知识和工具,以保护应用程序在整个软件开发生命周期(SDLC)中的安全性。课程首先介绍基础安全概念,如“深度防御”,通过真实案例(例如“PrintNightmare”漏洞)探讨攻击的组成,包括漏洞、攻击方式和载荷,分析如何实施多层次的安全措施以构建全面的防御策略。 学员将深入理解保密性、完整性和可用性(CIA)等基本安全原则,以及管理身份验证、授权和会话管理的关键实践。课程还将重点讨论现代应用安全面临的挑战,尤其是API安全,包括如何有效保护应用程序编程接口(APIs)、相关风险和安全策略。 此外,课程将探讨行业标准和框架,如OWASP Top 10,识别当前Web应用程序最严重的安全风险,包括实施强大的安全控制措施和风险评级方法(如NIST、FAIR、OWASP和CIS RAM)。 学员还会接触到软件供应链安全的高级主题,确保软件从开发到部署的完整性。 课程内容涵盖漏洞管理的全范围,从识别和评估到修复和报告,帮助学员持续维护IT系统的安全与完整性。还将深入探讨密码技术,如哈希、对称和非对称加密、数字证书和公钥基础设施(PKI),保证学员能够有效保护敏感数据和安全通信。同时,课程也涉及JSON Web Tokens (JWTs)、JSON Web Encryption (JWE)和JSON Web Signatures (JWS),用以说明这些技术在Web应用程序中的数据传输安全。 随着课程的深入,学员将探索安全与DevOps过程的关键整合——DevSecOps,强调在开发生命周期中早期和持续嵌入安全实践的重要性。我们将审视持续集成与持续部署(CI/CD)管道的安全性,以及如何防范未授权访问和代码篡改等威胁。学员将学习实施各种安全测试工具,包括静态应用安全测试(SAST)、动态应用安全测试(DAST)、交互式应用安全测试(IAST)、运行时应用自我保护(RASP)和Web应用防火墙(WAF)等。 此外,课程会涵盖应用安全态势管理(ASPM),通过整合各种安全实践和工具,为软件应用提供全面的安全健康状况视图。本课程将通过实际演示和动手活动,帮助学员在真实场景中应用所学知识,从探讨攻击树和威胁建模技术到开展渗透测试和使用CodeQL进行安全编码,学员将获得识别、减轻和应对安全威胁的宝贵经验。 通过本课程,学员将对应用安全有深刻的理解,能够无缝地将安全实践融入SDLC中,确保他们的应用程序不仅功能齐全,更能抵御各种网络威胁。无论您是经验丰富的安全专业人士还是新手开发者,本课程都将赋予您在当今数字环境中构建和维护安全可靠软件所需的知识和技能。
Every company is a software company, and it' becoming more difficult to secure applications. In an era where cyber threats are ever-evolving and increasingly sophisticated, securing applications from the ground up is more essential than ever. This course is a robust, all-encompassing course designed to equip software developers, and security professionals with the knowledge and tools necessary to protect their applications throughout the entire software development lifecycle (SDLC).This course begins by introducing participants to foundational security concepts such as "Defense in Depth," where we explore the anatomy of attacks, including vulnerabilities, exploits, and payloads, using real-world examples like the "PrintNightmare" vulnerability. We will examine how to implement multiple layers of security to build a comprehensive defense strategy against these threats. As participants progress, they will gain a deep understanding of essential security principles, including confidentiality, integrity, and availability (CIA), alongside key practices for managing authentication, authorization, and session management.A significant portion of the course is dedicated to modern challenges in application security, such as API security. Participants will learn how Application Programming Interfaces (APIs) function within web applications, the risks they pose, and the strategies to secure them effectively. This includes a deep dive into industry standards and frameworks like the OWASP Top 10, which highlight the most critical security risks to web applications today. We'll explore the nuances of implementing robust security controls, risk rating methodologies such as those from NIST, FAIR, OWASP, and CIS RAM, and how to develop and enforce these controls to counteract various security threats.Participants will also delve into advanced topics like software supply chain security, ensuring the integrity of software from development to deployment. The course covers the full spectrum of vulnerability management, from identification and evaluation to remediation and reporting, providing participants with the skills needed to maintain the security and integrity of IT systems continuously.A thorough exploration of cryptographic techniques, including hashing, encryption (both symmetric and asymmetric), and the use of digital certificates and Public Key Infrastructure (PKI), will be provided to ensure that participants can protect sensitive data and secure communications effectively. We will cover JSON Web Tokens (JWTs), JSON Web Encryption (JWE), and JSON Web Signatures (JWS) to illustrate how these technologies are used to secure data transmissions in web applications.As the course progresses, participants will explore the critical integration of security within the DevOps process, known as DevSecOps. Here, we emphasize the importance of embedding security practices early and continuously throughout the development lifecycle. We'll examine the security of Continuous Integration and Continuous Deployment (CI/CD) pipelines, understanding how to secure these processes against unauthorized access, code tampering, and other threats. Participants will learn to implement security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), Web Application Firewalls (WAF), and more!Moreover, the course will cover emerging areas like Application Security Posture Management (ASPM), which offers a comprehensive view of the security health of software applications by integrating various security practices and tools. This holistic approach ensures that organizations can manage vulnerabilities, configuration weaknesses, and compliance with security policies across the entire application lifecycle.Practical demonstrations and hands-on activities will allow participants to apply what they've learned in real-world scenarios. From exploring attack trees and threat modeling techniques to conducting penetration tests and leveraging tools like CodeQL for secure coding, participants will gain valuable experience in identifying, mitigating, and responding to security threats.By the end of this course, participants will have developed a deep, nuanced understanding of application security. They will be able to integrate security practices seamlessly into the SDLC, ensuring their applications are not only functional but resilient and secure against the full spectrum of cyber threats. Whether you're a seasoned security professional or a developer new to application security, this course will empower you with the knowledge and skills to build and maintain secure, reliable software in today's digital landscape.