Get in Touch

Course Outline

Day 1

IT Security and Secure Coding

  • The nature of security
  • Key terminology related to IT security
  • Defining risk
  • Various aspects of IT security
  • Security requirements for different application domains
  • Distinction between general IT security and secure coding
  • The progression from vulnerabilities to botnets and cybercrime
    • Characteristics of security flaws
    • Challenges in identifying these flaws
    • The escalation from a single infected computer to targeted attacks
  • Classification of security flaws
    • Landwehr’s taxonomy
    • The Seven Pernicious Kingdoms
    • OWASP Top Ten (2013)
    • Comparison of OWASP Top Ten trends from 2003 to 2013

Introduction to the Microsoft® Security Development Lifecycle (SDL)

  • Course Agenda
  • The reality of applications under attack...
    • Evolution of cybercrime
    • Shift in attack focus toward applications
    • Prevalence of vulnerabilities in smaller Independent Software Vendor (ISV) applications
  • The origins of the Microsoft SDL...
    • Historical security timeline at Microsoft...
    • Determining which applications must adhere to SDL
  • Components of the Microsoft Security Development Lifecycle (SDL)
    • Overview of the Microsoft SDL framework
    • Prerequisites: Mandatory security training
    • Phase One: Requirements gathering
    • Phase Two: Design phase
    • Phase Three: Implementation stage
    • Phase Four: Verification process
    • Phase Five: Release – Response Planning
    • Phase Five: Release – Final Security Review
    • Phase Five: Release – Archiving
    • Post-SDL Requirement: Incident Response
    • SDL Process Guidance for Line of Business (LOB) Applications
    • Applying SDL Guidance in Agile Methodologies
    • The necessity of process improvement for secure software development

Principles of Secure Design

  • Attack Surface Management
    • Strategies for reducing attack surface
    • Illustrative example of attack surface
    • Conducting an attack surface analysis
    • Practical examples of attack surface reduction
  • Privacy Considerations
    • Understanding privacy implications
    • Analyzing application behaviors and associated concerns
  • Defense in Depth
    • Core SDL Principle: Defense in Depth
    • Practical example of defense in depth
  • Least Privilege Principle
    • Example of applying least privilege
  • Secure Defaults
    • Examples of implementing secure defaults

Principles of Secure Implementation

  • Section Agenda
  • Microsoft Security Development Lifecycle (SDL) Context
  • Fundamentals of Buffer Overflow
    • Primary registers in Intel 80x86 Processors
    • Memory address layout structure
    • Function calling mechanisms in C/C++ on x86 architecture
    • Local variables and the stack frame
    • Understanding Stack Overflow
      • Buffer overflow specifically on the stack
      • Introduction to exercises
      • Exercise: BOFIntro
      • Exercise: BOFIntro – mapping the stack layout
      • Exercise: BOFIntro – executing a simple exploit
  • Input Validation Techniques
    • Core concepts of input validation
    • Challenges with Integer Problems
      • Representation of negative integers
      • Concept of integer overflow
      • Arithmetic overflow prediction exercise
      • Exercise: IntOverflow
      • What is the value of Math.Abs(int.MinValue)?
    • Mitigation strategies for integer problems
      • General mitigation approaches
      • Avoiding arithmetic overflow in addition
      • Avoiding arithmetic overflow in multiplication
      • Detecting overflow using the 'checked' keyword in C#
      • Exercise – Utilizing the checked keyword in C#
      • Exceptions generated by overflows in C#
    • Case Study – Integer Overflow in .NET
      • Analyzing a real-world integer overflow vulnerability
      • Exploiting the identified vulnerability
    • Path Traversal Vulnerability
      • Mitigating path traversal risks

Day 2

Principles of Secure Implementation (Continued)

  • Injection Attacks
    • Common SQL Injection attack methods
    • Blind and time-based SQL injection techniques
    • Methods for protecting against SQL Injection
    • Command injection risks
  • Broken Authentication – Password Management
    • Exercise – Assessing the weakness of hashed passwords
    • Best practices for password management and storage
    • Specialized hash algorithms designed for password storage
  • Cross-Site Scripting (XSS)
    • Understanding Cross-Site Scripting (XSS)
    • CSS injection vulnerabilities
    • Exploitation via other HTML tags
    • Preventive measures for XSS
  • Missing Function-Level Access Control
    • Techniques for filtering file uploads
  • Practical Cryptography
    • Achieving confidentiality via symmetric cryptography
    • Overview of symmetric encryption algorithms
    • Block ciphers and their modes of operation
    • Understanding hash or message digest functions
    • Common hash algorithms
    • Message Authentication Code (MAC)
    • Ensuring integrity and authenticity using a symmetric key
    • Providing confidentiality through public-key encryption
    • General rule regarding private key possession
    • Common mistakes in password management
    • Exercise – Risks of hardcoded passwords
    • Conclusion

Principles of Secure Verification

  • Differentiating functional testing from security testing
  • Identifying security vulnerabilities
  • Prioritizing remediation efforts
  • Integrating security testing within the SDLC
  • Key steps in test planning (risk analysis)
  • Scoping and Information Gathering
    • Identifying stakeholders
    • Assessing critical assets
    • Analyzing the attack surface
    • Defining security objectives for testing
  • Threat Modeling
    • Fundamentals of threat modeling
    • Developing attacker profiles
    • Approaches based on attack trees
    • Approaches based on misuse/abuse cases
    • Example: Misuse/abuse cases in a simple Web shop
    • STRIDE per element approach to threat modeling (MS SDL)
    • Defining security objectives
    • Diagramming – examples of Data Flow Diagram (DFD) elements
    • DFD example walkthrough
    • Threat enumeration using MS SDL’s STRIDE and DFD elements
    • Risk analysis – classifying threats
    • The DREAD threat/risk ranking model
  • Security Testing Techniques and Tools
    • General testing approaches
    • Techniques applied at various SDLC stages
  • Code Review
    • Conducting code reviews for software security
    • Performing taint analysis
    • Applying heuristics in review
  • Static Code Analysis
    • Introduction to static code analysis
    • Exercise – Utilizing static code analysis tools
  • Testing the Implementation
    • Manual run-time verification techniques
    • Comparing manual versus automated security testing
    • Penetration testing methodologies
    • Conducting stress tests
  • Fuzzing
    • Automated security testing through fuzzing
    • Challenges associated with fuzzing
  • Web Vulnerability Scanners
    • Exercise – Using a vulnerability scanner
  • Checking and Hardening the Environment
    • Common Vulnerability Scoring System – CVSS
    • Utilizing vulnerability scanners
    • Accessing public vulnerability databases
  • Case Study – Forms Authentication Bypass
    • Understanding NULL byte termination vulnerabilities
    • Locating the Forms Authentication Bypass vulnerability in code
    • Exploiting the identified bypass vulnerability

Knowledge Sources

  • Secure Coding Starter Kit – Essential Resources
  • Vulnerability Databases
  • .NET Secure Coding Guidelines on MSDN
  • .NET Secure Coding Cheat Sheets
  • Recommended Reading – Focus on .NET and ASP.NET
 14 Hours

Number of participants


Price per participant

Testimonials (3)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories