Subject
Software-defined security
| 1. | Course Title |
Software-defined security Software defined security |
||||||||||||
| 2. | Code | F23L3S159 | ||||||||||||
| 3. | Study Programme | Internet, networks and security | ||||||||||||
| 4. | Organizer of the study programme (unit, institute, department or division) | Faculty of Computer Science and Engineering | ||||||||||||
| 5. | Degree level (first, second, third cycle) | First Cycle | ||||||||||||
| 6. | Academic year / semester | 6 / Summer | ||||||||||||
| 7. | Number of ECTS credits | 6 | ||||||||||||
| 8. | Teacher | Анастас Мишев, Ристе Стојанов | ||||||||||||
| 9. | Prerequisites for enrolling in the course | Освоени најмалку 100 ЕКТС | ||||||||||||
| 10. | Objectives of the course programme (competences) | Разбирање и примена на клучните концепти од развој на безбеден софтвер во поглед на податоци, автентикација, авторизација и безбедни веб апликации. | ||||||||||||
| 11. | Course content | Lectures: 1. Вовед во животниот циклус на развој на безбеден софтвер Secure Development LifeCycle (SDL) 2. Introduction to Hacking Web Applications 3. Securing Modern Web Applications. 4. Cross-Site Scripting (XSS). Cross-Site Request Forgery (CSRF). XML External Entity (XXE). 5. Injection, Denial of Service (DoS), Exploiting Third-Party Dependencies 6. Secure Application Architecture 7. Code constructs promoting security -Domain Driven Design 8. Domain primitives, Ensuring integrity of state, Reducing complexity of state 9. Reviewing Code for Security 10. Leveraging your delivery pipeline for security 11. Vulnerability Discovery 12. Vulnerability Management Practical Classes: 1. Вовед во животниот циклус на развој на безбеден софтвер Secure Development LifeCycle (SDL) 2. 3. 4. Defending Against XSS Attacks, Defending Against CSRF Attacks, Defending Against XXE 5. Defending Against Injection, Defending Against DoS, Securing Third-Party Dependencies. 6. Secure Application Architecture 7. Code constructs promoting security 8. Domain primitives, Ensuring integrity of state, Reducing complexity of state 9. Reviewing Code for Security 10. Leveraging your delivery pipeline for security 11. Vulnerability Discovery 12. Vulnerability Management |
||||||||||||
| 12. | Learning methods | Lectures using presentations, interactive lectures, exercises (using equipment and software packages), teamwork, case studies, guest lectures, independent preparation and defense of a project assignment and a seminar paper. | ||||||||||||
| 13. | Total available time | 6 ECTS x 30 hours = 180 hours | ||||||||||||
| 14. | Distribution of available time | 30 + 45 + 15 + 15 + 75 = 180 hours | ||||||||||||
| 15. | Forms of teaching activities |
|
||||||||||||
| 16. | Other forms of activities |
|
||||||||||||
| 17. | Assessment method |
|
||||||||||||
| 18. | Grading criteria (points / grade) |
|
||||||||||||
| 19. | Requirement for obtaining a signature and taking the final exam | Laboratory exercises were conducted. | ||||||||||||
| 20. | Language of instruction | Macedonian and English | ||||||||||||
| 21. | Method for monitoring the quality of teaching | internal evaluation and survey mechanism | ||||||||||||
| 22. | Literature |
|