Subject

Mobile and Web Application Security

1. Course Title Mobile and Web Application Security
Mobile and Web Application Security
2. Code m23_w_053
3. Study Programme
4. Organizer of the study programme (unit, institute, department or division) Faculty of Computer Science and Engineering
5. Degree level (first, second, third cycle) Second cycle
6. Academic year / semester 9 / Winter
7. Number of ECTS credits 6
8. Teacher Riste Stojanov
9. Prerequisites for enrolling in the course
10. Objectives of the course programme (competences) The course will introduce students to possible threats and attacks on web and mobile applications and their detection. It will provide a detailed overview of approaches to achieving greater security for mobile and web applications, using: web server security, utilizing the security design of mobile operating systems, implementation of application-level protection mechanisms, enhancing Ajax security, and protecting web services.
Upon completion of the course, the student is expected to be able to: configure web server security, design a security solution for mobile applications, and implement appropriate techniques for protecting mobile and web applications. Students will be able to analyze and identify vulnerabilities in existing mobile and web applications, as well as propose solutions to address them.
11. Course content - Modeling web security
Mobile Application Security Modeling
HTTP Security Configuration
Detection of unauthorized modification of content
Protection of the interaction between the application and the databases
Session Authentication Management
Performing input validation
Protection of Web Services
Scanning application vulnerabilities
Security model in mobile operating systems
12. Learning methods Lectures, projects, discussions and workshops
13. Total available time 6 ECTS x 30 hours = 180 hours
14. Distribution of available time 60 + — + 45 + 45 + 30 = 180 hours
15. Forms of teaching activities
15.1. Lectures - theoretical instruction 60 hours
15.2. Exercises (laboratory, auditory), seminars, teamwork — hours
16. Other forms of activities
16.1. Project assignments 45 hours
16.2. Independent assignments 45 hours
16.3. Home study 30 hours
17. Assessment method
17.1. Tests 0 points
17.2. Seminar paper / project (presentation: written and oral) 45 points
17.3. Activities and learning 20 points
17.4. Final exam 0 points
18. Grading criteria (points / grade)
up to 50 points5 (five) (F)
from 51 to 60 points6 (six) (E)
from 61 to 70 points7 (seven) (D)
from 71 to 80 points8 (eight) (C)
from 81 to 90 points9 (nine) (B)
from 91 to 100 points10 (ten) (A)
19. Requirement for obtaining a signature and taking the final exam Completed activities 15, 16
20. Language of instruction Macedonian and English
21. Method for monitoring the quality of teaching Internal evaluation and survey mechanism
22. Literature
22.1. Required literature
1. Michal Zalewski | The Tangled Web: A Guide to Securing Modern Web Application | No Starch Press | 2011
2. Himanshu Dwivedi, Chris Clark, David Thiel | Mobile Application Security | McGraw-Hill Osborne Media | 2010
3. Bryan Sullivan | Web Application Security, A Beginner's Guide | McGraw-Hill Osborne Media | 2011
22.2. Additional literature
No. Author Title Publisher Year