Secure Software Development - Part I

所在平台: Udemy

课程主页: https://www.udemy.com/course/secure-software-development-part-i/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:安全软件开发 - 第一部分 课程概述:本系列课程涵盖了软件安全的基础知识,重点在于开发新的软件应用程序。安全性贯穿整个软件开发生命周期(SDLC)。该系列深入审查了关键的软件漏洞及其利用方式,然后探讨了旨在发现软件中新未知漏洞的策略,包括先进的测试和程序分析技术。课程讨论并实施的缓解策略可有效降低软件遭受攻击的风险。缓解措施的应用不仅仅是一个理论概念,而是可以显著增强软件系统安全性的实用方法。 在第一部分中,课程开始于安全应用程序的建模。我们将逐步构建一个安全的功能模型、安全对象模型、安全动态模型、安全系统模型和威胁模型。每个步骤都建立在前一步的基础上。这个过程是迭代性的,我们会回顾并更新之前模型,在发现的新知识的基础上进行修正。 第二部分将关注在早期建模阶段发现的风险所使用的具体缓解措施。我们将研究授权与认证、输入验证与清理、标准网络应用程序漏洞以及数据库安全方面的缓解措施。 第三部分将探讨如何测试软件,确保所开发的产品与早期阶段开发的模型相符。我们还将关注渗透测试,以发现建模过程中遗漏的漏洞。

课程评论(0条)

课程详情

This series of courses covers the foundations of software security, focusing on developing new software applications. Security is woven into the software development lifecycle (SDLC). The series thoroughly examines critical software vulnerabilities and the attacks that exploit them. It then explores strategies, including advanced testing and program analysis techniques, that can be used to discover new unknown vulnerabilities in the software. Mitigation strategies are discussed and implemented to reduce the risk of attacks against the software. The application of mitigations is not just a theoretical concept but a practical approach that can significantly strengthen the security of software systems. In part one, we start by modeling a secure application. We walk through building a secure, functional model, secure object model, secure dynamic model, secure system model, and threat model. Each step builds on the previous steps. The process is iterative, where we revisit the models developed in the previous steps and update them with the new knowledge discovered.Part two will look at specific mitigations used to lower the risks discovered in the earlier modeling phases. We investigate authorization and authentication, input validation and sanitization, standard web application vulnerabilities, and mitigates and database security.Part three will look at testing the software to ensure what was developed matched the models developed in earlier phases. We will also look at penetration testing to discover vulnerabilities missed in our modeling.

课程标签

0人关注该课程

主题相关的课程