About this course
Modern web applications handle sensitive data and business processes, which makes security an essential part of software development.
The Introduction to Web Application Security course explains the most common security risks in web applications and how they arise during development. You will learn how attackers exploit weaknesses in web applications and how developers can prevent these vulnerabilities.
The course covers the most important web application vulnerabilities identified by the OWASP Top 10. For each vulnerability, you will learn how it occurs, how it can be exploited, and the practical steps developers can take to reduce the risk.
This course focuses on the principles of secure web application development and does not depend on any specific programming language or technology.
Intended audience
This course is useful if:
- You are a web application developer, and you need to understand how common security vulnerabilities arise and how to prevent them.
- You are responsible for development teams and you want to reduce the risk of security vulnerabilities in your organisation’s web applications.
- You are a network, server or DevOps engineer, and you are responsible for securing the infrastructure that supports web applications.
Prerequisites
- You should understand the basics of how web applications work.
- Some experience with web development or web infrastructure will be helpful.
Course details
Price: R6,900 excluding VAT per delegate.
Included:
- Electronic course material.
- Attendance certificate (PDF).
Duration: 2 days.
Delivery: Virtual classroom
See how virtual training works.
Note: this course is presented on request only.
Booking information
Email your booking to info@incusdata.com. A purchase order, or completed enrolment form is sufficient.
We will confirm the booking and issue an invoice.
Course contents
Introduction to Web Application Security
- Recent security breaches and what we can learn from them.
- How modern web applications work.
- Common attack vectors and threat agents.
- Why web applications are frequent attack targets.
How the Web Works
- HTTP protocol basics.
- How requests and responses flow between browsers and servers.
- HTTP vs HTTPS.
- Key security-related HTTP headers.
Security Standards and Frameworks
- The Open Web Application Security Project (OWASP).
- Common Weakness Enumeration (CWE).
- Industry security frameworks and guidance.
Core Security Principles
- The CIA model: confidentiality, integrity, availability.
- Security policies and standards.
- Secure architecture concepts.
- Introduction to the Secure Software Development Lifecycle (SSDLC).
OWASP Top 10 Web Application Vulnerabilities
- Injection attacks.
- Broken authentication and session management.
- Broken access control.
- Security misconfiguration.
- Cross-site scripting (XSS).
- XML external entity (XXE) attacks.
- Insecure deserialization.
- Vulnerable and outdated components.
- Security logging and monitoring failures.
- Cryptographic failures.
- Real-world examples.
- Practical countermeasures.
Additional Web Application Vulnerabilities
- Clickjacking.
- Cross-Site Request Forgery (CSRF).
- Server-Side Request Forgery (SSRF).
- Examples and mitigation strategies.
Security Testing Approaches
- Static Application Security Testing (SAST).
- Dynamic Application Security Testing (DAST).
- Interactive Application Security Testing (IAST).
- Runtime Application Self-Protection (RASP).
- Security monitoring tools.
Secure Development Practices
- The secure SDLC.
- Threat modelling.
- Source code review.
- Common secure coding mistakes.
Secure Design Principles
- Defence in depth.
- Least privilege.
- Fail-safe defaults.
- Separation of duties.
- Open design.
- Economy of mechanism.
- Complete mediation.
Download the course outline
Download the Introduction to Web Application Security course outline in PDF format.