Course Outline
I. Introduction to Secure Coding and Web Application Security
1. The Modern Web Application Threat Landscape
- Typical attack vectors in web applications
- Security challenges in contemporary ASP.NET applications
- The significance of secure coding in software development
- Overview of the OWASP Foundation and its available resources
2. Core Principles of Secure Software Development
- Designing for security
- Defense in depth strategies
- Least privilege access
- Secure failure handling
- Secure default settings
- Basics of threat modeling
II. Secure Development Lifecycle (SDL)
1. The Secure Software Development Lifecycle
- Integrating security across the development lifecycle
- Defining security requirements
- Secure architecture and design practices
- Implementing secure coding standards
- Conducting security testing and validation
- Ensuring secure deployment and maintenance
2. Risk Assessment and Threat Modeling
- Identifying assets and potential threats
- Analysing the attack surface
- Overview of the STRIDE framework
- Prioritising security risks
III. OWASP Top 10 for ASP.NET Applications
1. Understanding the OWASP Top 10
- Broken access control
- Cryptographic failures
- Injection vulnerabilities
- Insecure design
- Security misconfiguration
- Vulnerable and outdated components
- Identification and authentication failures
- Software and data integrity failures
- Failures in security logging and monitoring
- Server-Side Request Forgery (SSRF)
2. Implementing OWASP Recommendations
- Secure coding techniques
- Preventive control measures
- Best practices for secure configuration
- Practical examples and demonstrations
IV. Authentication and Authorization Security
1. Authentication Fundamentals
- Authentication mechanisms within ASP.NET
- Password security standards
- Multi-factor authentication implementation
- Session management strategies
- Identity management concepts
2. Authorization and Access Control
- Role-based authorization models
- Claims-based authorization
- Policy-based authorization
- Preventing privilege escalation attacks
- Safeguarding sensitive resources
V. Preventing Injection Attacks
1. Injection Vulnerabilities
- SQL injection
- Command injection
- LDAP injection
- XML injection
- Overview of NoSQL injection
2. Defensive Coding Techniques
- Using parameterized queries
- Validating input data
- Encoding output
- Security considerations for Object-Relational Mappers (ORM)
- Safe database access protocols
VI. Preventing Cross-Site Scripting (XSS)
1. Understanding XSS
- Stored XSS
- Reflected XSS
- DOM-based XSS
- Common attack scenarios
2. Mitigating XSS
- Output encoding strategies
- Input validation methods
- Implementing Content Security Policy (CSP)
- Secure handling of HTML and JavaScript
- ASP.NET features for XSS prevention
VII. Preventing Cross-Site Request Forgery (CSRF)
1. Understanding CSRF
- How CSRF attacks function
- Typical attack scenarios
- Business impact of CSRF
2. CSRF Protection Strategies
- Use of anti-forgery tokens
- Configuring SameSite cookies
- Secure session management
- ASP.NET anti-forgery mechanisms
VIII. Secure Configuration of ASP.NET Applications
1. ASP.NET Security Features
- Configuration security
- Setting secure HTTP headers
- Configuring HTTPS and TLS
- Managing secrets
- Secure error handling
2. Protecting Sensitive Data
- Data protection APIs
- Secure storage of credentials
- Encryption fundamentals
- Key management practices
IX. Input Validation and Secure Data Handling
1. Validating User Input
- Whitelisting versus blacklisting approaches
- Server-side validation
- Client-side validation considerations
- File upload security
2. Secure Data Processing
- Serialization security
- Risks associated with deserialization
- Maintaining data integrity
- Best practices for secure logging
X. Penetration Testing and Security Verification
1. Penetration Testing Methodology
- Planning security assessments
- Identifying vulnerabilities
- Concepts of exploitation
- Reporting findings effectively
2. Security Testing Techniques
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Dependency and component analysis
- Manual code review processes
XI. Securing ASP.NET Applications
1. Applying Secure Coding Practices
- Implementing secure authentication
- Implementing secure authorization
- Enhancing session security
- Managing exceptions securely
- Logging and monitoring
- Considerations for secure deployment
2. Security Best Practices
- Adhering to secure coding standards
- Managing dependencies
- Patch management strategies
- Continuous security improvement
XII. Hands-on Security Workshop
1. Identifying and Exploiting Common Vulnerabilities
- Analyzing insecure ASP.NET code
- Identifying OWASP Top 10 vulnerabilities
- Understanding attack techniques
- Evaluating application security posture
2. Remediating Security Issues
- Applying secure coding fixes
- Validating mitigation effectiveness
- Testing remediated applications
- Secure coding review exercises
XIII. Summary and Course Review
1. Review of Key Concepts
- Secure design principles
- OWASP Top 10 mitigation strategies
- ASP.NET security features
- The secure development lifecycle
2. Final Discussion
- Secure coding best practices
- Embedding security into development teams
- Additional OWASP resources and tools
- Q&A and next steps
Requirements
Proficiency in ASP.NET development
Practical experience in building web applications
Testimonials (5)
Introductions to the many different types of unsafe behaviors.
Zhongqi
Course - Secure Developer .NET (Inc OWASP)
having a one to one session with Raymond was amazing he was really great and attentive to all my training needs.
Joshua
Course - Secure Developer .NET (Inc OWASP)
The high level of instructor knowledge meant that we got a very good insight into the topics covered.
Dafydd - TATA Steel
Course - Secure Developer .NET (Inc OWASP)
the reference links
Abraham Gonzalez - ATEB Servicios
Course - Secure Developer .NET (Inc OWASP)
The trainer's subject knowledge was excellent, and the way the sessions were set out so that the audience could follow along with the demonstrations really helped to cement that knowledge, compared to just sitting and listening.