Course Outline
I. Introduction to Secure Coding and Web Application Security
1. Modern Web Application Threat Landscape
- Common web application attack vectors
- Security risks in contemporary ASP.NET applications
- The significance of secure coding in software development
- Overview of the OWASP Foundation and its resources
2. Secure Software Development Principles
- Security by design
- Defense in depth
- Least privilege
- Failing securely
- Secure defaults
- Fundamentals of threat modeling
II. Secure Development Lifecycle (SDL)
1. Secure Software Development Lifecycle
- Integrating security throughout the development lifecycle
- Defining security requirements
- Secure architecture and design
- Adopting secure coding practices
- Security testing and validation
- Secure deployment and maintenance procedures
2. Risk Assessment and Threat Modeling
- Identifying assets and threats
- Conducting attack surface analysis
- Understanding STRIDE methodology
- Prioritising security risks
III. OWASP Top 10 for ASP.NET Applications
1. Understanding the OWASP Top 10
- Broken Access Control
- Cryptographic Failures
- Injection vulnerabilities
- Insecure Design
- Security Misconfiguration
- Vulnerable and Outdated Components
- Identification and Authentication Failures
- Software and Data Integrity Failures
- Security Logging and Monitoring Failures
- Server-Side Request Forgery (SSRF)
2. Applying OWASP Recommendations
- Implementing secure coding techniques
- Establishing preventive controls
- Adhering to secure configuration practices
- Analyzing real-world examples and demonstrations
IV. Authentication and Authorization Security
1. Authentication Fundamentals
- Authentication mechanisms within ASP.NET
- Password security standards
- Implementing multi-factor authentication
- Effective session management
- Identity management strategies
2. Authorization and Access Control
- Role-based authorization
- Claims-based authorization
- Policy-based authorization
- Preventing privilege escalation
- Protecting sensitive resources
V. Preventing Injection Attacks
1. Injection Vulnerabilities
- SQL Injection
- Command Injection
- LDAP Injection
- XML Injection
- Overview of NoSQL Injection
2. Secure Coding Techniques
- Utilising parameterized queries
- Rigorous input validation
- Output encoding strategies
- Security considerations for ORMs
- Best practices for safe database access
VI. Preventing Cross-Site Scripting (XSS)
1. Understanding XSS
- Stored XSS
- Reflected XSS
- DOM-based XSS
- Typical attack scenarios
2. XSS Prevention Strategies
- Implementing output encoding
- Enforcing input validation
- Deploying Content Security Policy (CSP)
- Secure handling of HTML and JavaScript
- Leveraging ASP.NET security features for XSS prevention
VII. Preventing Cross-Site Request Forgery (CSRF)
1. Understanding CSRF
- How CSRF attacks operate
- Common attack scenarios
- Business impact analysis
2. CSRF Protection Measures
- Implementing anti-forgery tokens
- Configuring SameSite cookies
- Securing session management
- Utilising ASP.NET anti-forgery mechanisms
VIII. Secure Configuration of ASP.NET Applications
1. ASP.NET Security Features
- Configuration security
- Implementing secure HTTP headers
- Configuring HTTPS and TLS
- Secrets management
- Secure error handling protocols
2. Protecting Sensitive Data
- Utilising Data Protection APIs
- Securely storing credentials
- Fundamentals of encryption
- Key management procedures
IX. Input Validation and Secure Data Handling
1. Validating User Input
- Whitelisting versus blacklisting approaches
- Server-side validation techniques
- Considerations for client-side validation
- Securing file uploads
2. Secure Data Processing
- Serialization security
- Risks associated with deserialization
- Ensuring data integrity
- Best practices for secure logging
X. Penetration Testing and Security Verification
1. Penetration Testing Methodology
- Planning security assessments
- Identifying vulnerabilities
- Concepts of exploitation
- Reporting findings effectively
2. Security Testing Techniques
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Analyzing dependencies and components
- Conducting manual code reviews
XI. Securing ASP.NET Applications
1. Applying Secure Coding Practices
- Implementing secure authentication
- Implementing secure authorization
- Managing session security
- Effective exception handling
- Logging and monitoring protocols
- Considerations for secure deployment
2. Security Best Practices
- Adhering to secure coding standards
- Managing dependencies effectively
- Executing patch management
- Continuous security improvement initiatives
XII. Hands-on Security Workshop
1. Identifying and Exploiting Common Vulnerabilities
- Analyzing insecure ASP.NET code samples
- Identifying OWASP Top 10 vulnerabilities
- Understanding attack techniques
- Evaluating application security posture
2. Remediating Security Issues
- Applying secure coding fixes
- Validating mitigations
- Testing remediated applications
- Conducting a secure coding review exercise
XIII. Summary and Course Review
1. Review of Key Concepts
- Principles of secure design
- Mitigation strategies for the OWASP Top 10
- ASP.NET security features
- The secure development lifecycle
2. Final Discussion
- Best practices for secure coding
- Integrating security into development teams
- Additional OWASP resources and tools
- Q&A session and next steps
Requirements
Experience with ASP.NET
Experience in developing web applications
Testimonials (5)
Introductions to the many different types of unsafe behaviors.
Zhongqi
Course - Secure Developer .NET (Inc OWASP)
having a one to one session with Raymond was amazing he was really great and attentive to all my training needs.
Joshua
Course - Secure Developer .NET (Inc OWASP)
The high level of instructor knowledge meant that we got a very good insight into the topics covered.
Dafydd - TATA Steel
Course - Secure Developer .NET (Inc OWASP)
the reference links
Abraham Gonzalez - ATEB Servicios
Course - Secure Developer .NET (Inc OWASP)
The trainer's subject knowledge was excellent, and the way the sessions were set out so that the audience could follow along with the demonstrations really helped to cement that knowledge, compared to just sitting and listening.