Introduction to Web Application Security Course

About this course

Modern web applications handle sensitive data and business processes, which makes security an essential part of software development.

The Introduction to Web Application Security course explains the most common security risks in web applications and how they arise during development. You will learn how attackers exploit weaknesses in web applications and how developers can prevent these vulnerabilities.

The course covers the most important web application vulnerabilities identified by the OWASP Top 10. For each vulnerability, you will learn how it occurs, how it can be exploited, and the practical steps developers can take to reduce the risk.

This course focuses on the principles of secure web application development and does not depend on any specific programming language or technology.

Intended audience

This course is useful if:

  • You are a web application developer, and you need to understand how common security vulnerabilities arise and how to prevent them.
  • You are responsible for development teams and you want to reduce the risk of security vulnerabilities in your organisation’s web applications.
  • You are a network, server or DevOps engineer, and you are responsible for securing the infrastructure that supports web applications.

Prerequisites

  • You should understand the basics of how web applications work.
  • Some experience with web development or web infrastructure will be helpful.

Course details

Price: R6,900 excluding VAT per delegate.

Included:

  • Electronic course material.
  • Attendance certificate (PDF).

Duration: 2 days.

Delivery: Virtual classroom
See how virtual training works.

Note: this course is presented on request only.

Booking information

Email your booking to info@incusdata.com. A purchase order, or completed enrolment form is sufficient.

We will confirm the booking and issue an invoice.

Course contents

Introduction to Web Application Security

  • Recent security breaches and what we can learn from them.
  • How modern web applications work.
  • Common attack vectors and threat agents.
  • Why web applications are frequent attack targets.

How the Web Works

  • HTTP protocol basics.
  • How requests and responses flow between browsers and servers.
  • HTTP vs HTTPS.
  • Key security-related HTTP headers.

Security Standards and Frameworks

  • The Open Web Application Security Project (OWASP).
  • Common Weakness Enumeration (CWE).
  • Industry security frameworks and guidance.

Core Security Principles

  • The CIA model: confidentiality, integrity, availability.
  • Security policies and standards.
  • Secure architecture concepts.
  • Introduction to the Secure Software Development Lifecycle (SSDLC).

OWASP Top 10 Web Application Vulnerabilities

  • Injection attacks.
  • Broken authentication and session management.
  • Broken access control.
  • Security misconfiguration.
  • Cross-site scripting (XSS).
  • XML external entity (XXE) attacks.
  • Insecure deserialization.
  • Vulnerable and outdated components.
  • Security logging and monitoring failures.
  • Cryptographic failures.
  • Real-world examples.
  • Practical countermeasures.

Additional Web Application Vulnerabilities

  • Clickjacking.
  • Cross-Site Request Forgery (CSRF).
  • Server-Side Request Forgery (SSRF).
  • Examples and mitigation strategies.

Security Testing Approaches

  • Static Application Security Testing (SAST).
  • Dynamic Application Security Testing (DAST).
  • Interactive Application Security Testing (IAST).
  • Runtime Application Self-Protection (RASP).
  • Security monitoring tools.

Secure Development Practices

  • The secure SDLC.
  • Threat modelling.
  • Source code review.
  • Common secure coding mistakes.

Secure Design Principles

  • Defence in depth.
  • Least privilege.
  • Fail-safe defaults.
  • Separation of duties.
  • Open design.
  • Economy of mechanism.
  • Complete mediation.

Download the course outline

Download the Introduction to Web Application Security course outline in PDF format.

Your Java tip is on its way!

Check that incusdata.com is an approved sender, so that your Java tips don’t land up in the spam folder.

Our privacy policy means your data is safe. You can unsubscribe from these tips at any time.

Thank You

We're Excited!

Thank you for completing the form. We're excited that you have chosen to contact us about training. We will process the information as soon as we can, and we will do our best to contact you within 1 working day. (Please note that our offices are closed over weekends and public holidays.)

Don't Worry

Our privacy policy ensures your data is safe: Incus Data does not sell or otherwise distribute email addresses. We will not divulge your personal information to anyone unless specifically authorised by you.

If you need any further information, please contact us on tel: (27) 12-666-2020 or email info@incusdata.com

How can we help you?

Let us contact you about your training requirements. Just fill in a few details, and we’ll get right back to you.