> For the complete documentation index, see [llms.txt](https://zisoft-awareness.gitbook.io/fawry-cloud-devops-internship/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://zisoft-awareness.gitbook.io/fawry-cloud-devops-internship/application-architecture/application-security-course.md).

# Application Security Course

Prepared by Omar-Abdalhamid  (Oct .2022)

Application security refers to security precautions used at the application level to prevent the theft or hijacking of data or code within the application. It includes security concerns made during application development and design, as well as methods and procedures for protecting applications once they've been deployed.

{% hint style="info" %}
**Course Overview**\
\
Application security is the process of developing, adding, and testing security features within applications to **prevent security vulnerabilities against threats such as unauthorized access and modification**.

\
All tasks that introduce a secure software development life cycle to development teams are included in application security shortly known as AppSec. Its ultimate purpose is to improve security practices and, as a result, detect, repair, and, ideally, avoid security flaws in applications. It covers the entire application life cycle, including requirements analysis, design, implementation, testing, and maintenance.

{% endhint %}

### Course Outline

<table><thead><tr><th width="94">Day</th><th>Description</th></tr></thead><tbody><tr><td><strong>Day 1</strong></td><td><mark style="color:green;"><strong>Application Security Introduction</strong></mark></td></tr><tr><td><strong>Day 2</strong></td><td><mark style="color:green;"><strong>Methodologies &#x26; VAPT</strong></mark></td></tr><tr><td><strong>Day 3</strong></td><td><mark style="color:green;"><strong>Secure Coding [ input validation &#x26; Session Management ]</strong></mark></td></tr><tr><td><strong>Day 4</strong></td><td><mark style="color:green;"><strong>Risk Rating , Threat Modeling , Encryption and Hashing</strong></mark> </td></tr><tr><td><strong>Day 5</strong></td><td> <mark style="color:green;"><strong>DevSecOps</strong></mark></td></tr></tbody></table>

###

### Course content&#x20;

{% hint style="success" %} <mark style="color:green;">**Day 1 :**</mark> <mark style="color:green;">**Application Security Introduction**</mark>

**Overview:**\
The first section of the course will set the stage for the course with the fundamentals of web applications such as the HTTP protocol and the various mechanisms that make web applications work. We then transition over to the architecture of the web applications which plays a big role in securing the application.

**Topics:**&#x20;

* Application Security Introduction
* Application Security Terms and Definitions
* Application Security Goals&#x20;
* OWASP WebGoat Demo
* Introduction to OWASP Top 10
* SANS Top 25 Threat&#x20;
  {% endhint %}

{% hint style="success" %} <mark style="color:green;">**Day 2: Methodologies & VAPT.**</mark>

**Methodologies for developing secure code:**&#x20;

* Risk analysis&#x20;
* Threat modeling&#x20;
* <mark style="color:blue;">**Lab :**</mark> Threat modeling - exercise&#x20;
* OWASP community Guidelines for secure coding&#x20;
* Verification testing .

**VAPT (Vulnerability Assessment and Penetration Test)**

* Introduction to HTTP Protocol&#x20;
* Overview of Web Authentication Technologies&#x20;
* Web Application Architecture&#x20;
* Recent Attack Trends&#x20;
* Web Infrastructure Security/Web Application Firewalls
* &#x20;Managing Configurations for Web Apps
* <mark style="color:blue;">**Lab :**</mark> using Burp proxy to test web applications

{% endhint %}

&#x20;&#x20;

&#x20;

{% hint style="success" %} <mark style="color:green;">**Day 3 : Secure Coding \[ input validation & Session Management ]**</mark>

**Secure Coding  input validation:**

* SQL Injection vulnerability
* <mark style="color:blue;">**Lab :**</mark>**&#x20;** SQL Injection vulnerability Lab&#x20;
* LDAP and XPath Injection vulnerabilities
* Cross-Site Scripting (XSS) vulnerability
* <mark style="color:blue;">**Lab :**</mark> Cross-Site Scripting (XSS) vulnerability Lab&#x20;
* OS Command Injection vulnerability
* <mark style="color:blue;">**Lab :**</mark> OS Command Injection vulnerability Lab&#x20;
* LFI (Local File Inclusion) and RFI (Remote File Inclusion) vulnerabilities&#x20;
* <mark style="color:blue;">**Lab :**</mark>  LFI / RFI vulnerabilities Lab&#x20;
* Invalidated File Upload vulnerability&#x20;
* <mark style="color:blue;">**Lab :**</mark>**&#x20;** Invalidated File Upload vulnerability Lab&#x20;
* Buffer Overflow vulnerabilities&#x20;
* XXE (XML External Entities) Vulnerabilities&#x20;
* <mark style="color:blue;">**Lab :**</mark>**&#x20;** XXE (XML External Entities) &#x20;
* Insecure Deserialization
  {% endhint %}

{% hint style="success" %} <mark style="color:green;">**Day 4 : Risk Rating , Threat Modeling , Encryption and Hashing**</mark>&#x20;

**Risk Rating and Threat Modeling:**

* Risk Rating Introduction&#x20;
* <mark style="color:blue;">**Lab :**</mark> Risk Rating Demo&#x20;
* Introduction to Threat Modeling&#x20;
* Type of Threat Modeling&#x20;
* Introduction to Manual Threat Modeling
* <mark style="color:blue;">**Lab :**</mark> Manual Threat Model demo&#x20;

**Encryption and Hashing:**

* Encryption Overview&#x20;
* Encryption Use Cases Hashing&#x20;
* <mark style="color:blue;">**Lab :**</mark> Overview Hashing Demo PKI (Public Key Infrastructure)&#x20;
* Password Management
* &#x20;<mark style="color:blue;">**Lab :**</mark> Password Demo
  {% endhint %}

&#x20;

&#x20;

{% hint style="success" %} <mark style="color:green;">**Day 5 : DevSecOps**</mark>

* SAST (Static Application Security Testing)&#x20;
* <mark style="color:blue;">**Lab :**</mark> Spot Bugs Demo .
* SCA (Software Composition Analysis)
* <mark style="color:blue;">**Lab :**</mark> Snyk Open-Source (SCA)
* DAST (Dynamic Application Security Testing)
* <mark style="color:blue;">**Lab :**</mark> OWASP ZAP  Scanning .
* IAST (Interactive Application Security Testing)
* &#x20;RASP (Runtime Application Self-Protection)
* &#x20;WAF (Web Application Firewall) Penetration Testing&#x20;
* SCA (Software Composition Analysis)

{% endhint %}
