Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
1. IT security and secure coding
- Core Security Principles: Applying Confidentiality, Integrity, and Availability (CIA) to Java applications.
- Secure Software Development Lifecycle (SSDLC): Embedding security from the requirements phase through to deployment.
- Secure Coding Paradigms: Utilizing defense in depth, least privilege, and fail-safe defaults.
- Vulnerability Taxonomies: Gaining familiarity with CWE (Common Weakness Enumeration) and OWASP standards.
2. Web application security
- OWASP Top Ten Analysis: In-depth examination of Injection, Broken Authentication, and Sensitive Data Exposure.
- Cross-Site Scripting (XSS): Addressing Reflected, Stored, and DOM-based XSS scenarios in Java/JSP.
- Cross-Site Request Forgery (CSRF): Understanding attack mechanisms and implementing Anti-CSRF tokens.
- Session Management: Managing cookie security, preventing session fixation, and handling timeouts.
- API Security: Protecting REST and SOAP endpoints from misuse.
3. Security of Web services
- Web Services vs. Traditional Web Apps: Analyzing distinct attack surfaces.
- Transport Layer Security: Configuring SSL/TLS for Java clients and servers.
- Message Security: Ensuring Integrity and Confidentiality at the payload level.
- Authentication Protocols: Implementing OAuth 2.0, OpenID Connect, and JWT (JSON Web Tokens).
4. XML security
- XML Parsing Risks: Preventing XML External Entity (XXE) attacks.
- XML Schema Validation: Adopting best practices for strict schema enforcement.
- XML Digital Signatures: Applying signatures to guarantee non-repudiation.
- XML Encryption: Utilizing standard methods for encrypting XML content.
5. Foundations of Java security
- Java Security Architecture: Exploring the
java.securitypackage and the provider model. - Security Providers: Installing and configuring providers such as Bouncy Castle.
- Access Control: Managing Policy files, Permissions, and the Security Manager (Legacy vs. Modern approaches).
- KeyStore Management: Creating and maintaining keystores and truststores for certificate handling.
6. Practical cryptography
- Cryptographic Algorithms: Overview of Symmetric (AES), Asymmetric (RSA, ECC), and Hashing (SHA-256/512) methods.
- Random Number Generation: Comparing the risks of
java.util.Randomwithjava.security.SecureRandom. - Key Management: Strategies for key generation, storage, and rotation.
- Java Cryptography Architecture (JCA): Utilizing
Cipher,MessageDigest, andMacclasses. - Java Cryptography Extension (JCE): Understanding policy files and unlimited strength jurisdictions.
7. Java security services
- SSL/TLS in Java: Leveraging
SSLSocketFactoryandHttpsURLConnection. - Trust Managers: Customizing trust verification for private PKI environments.
- Authenticators: Implementing programmatic authentication via
Authenticator.getDefault(). - Certificate Analysis: Programmatically reading and interpreting X.509 certificates.
8. Java EE security
- Declarative Security: Implementing Role-based access control (RBAC) using
web.xmland annotations. - Programmatic Security: Utilizing
HttpServletRequest.isUserInRole()andgetRemoteUser(). - JAAS (Java Authentication and Authorization Service): Configuring
login.confand buildingLoginModules. - Servlet Security: Managing container-controlled security constraints and authentication methods (FORM, BASIC, DIGEST).
9. Common coding errors and vulnerabilities
- Insecure Deserialization: Mitigating risks associated with
ObjectInputStreamand bypassing security checks. - Command Injection: Preventing OS-level execution vulnerabilities.
- Path Traversal: Sanitizing file system inputs to block directory traversal.
- Reflection Abuse: Addressing risks related to
java.lang.reflectand circumventing access controls. - Hardcoded Credentials: Detecting and removing secrets from source code.
- Cryptography Implementation Errors: Avoiding ECB mode, weak keys, or static IVs.
10. Knowledge sources
- Static Analysis Tools: Employing SonarQube, Checkmarx, and Fortify for automated code scanning.
- Dynamic Analysis Tools: Overview of Burp Suite and OWASP ZAP capabilities.
- CVE Databases: Tracking and responding to new vulnerabilities in the Java framework.
- Recommended Readings: A curated list of books, documentation, and secure coding checklists.
Requirements
None.
Testimonials (4)
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
Practical exercises
Olek - Fireup.PRO
Course - Advanced Java Security
coding excercies
Mirek - Fireup.PRO
Course - Advanced Java Security
It opens up a lot and gives lots of insight what security