课程信息

39,143 次近期查看
可分享的证书
完成后获得证书
100% 在线
立即开始,按照自己的计划学习。
第 2 门课程(共 4 门)
可灵活调整截止日期
根据您的日程表重置截止日期。
中级

1-2 years of experience with some form of computer programming language like C/C++ or Java.

完成时间大约为15 小时
英语(English)
字幕:英语(English)

您将获得的技能

CryptographyAuthentication Methodssecure programming
可分享的证书
完成后获得证书
100% 在线
立即开始,按照自己的计划学习。
第 2 门课程(共 4 门)
可灵活调整截止日期
根据您的日程表重置截止日期。
中级

1-2 years of experience with some form of computer programming language like C/C++ or Java.

完成时间大约为15 小时
英语(English)
字幕:英语(English)

提供方

加州大学戴维斯分校 徽标

加州大学戴维斯分校

教学大纲 - 您将从这门课程中学到什么

1

1

完成时间为 5 小时

Foundational Topics in Secure Programming

完成时间为 5 小时
14 个视频 (总计 83 分钟), 3 个阅读材料, 2 个测验
14 个视频
Module 1 Introduction1分钟
Fundamental Concepts in Security8分钟
The STRIDE Method Via Example9分钟
STRIDE Threats In More Detail Via Example4分钟
Trust Boundaries2分钟
Cryptography Basics Introduction3分钟
Cryptography Basics: Block Ciphers9分钟
Cryptography Basics: Symmetric and Asymmetric Cryptography5分钟
Cryptography Basics: Hash Functions9分钟
Cryptography Basics: Application to Threat Models4分钟
Lab: Threat Model Activity3分钟
OWASP Top 10 Proactive Controls and Exploits - Part 16分钟
OWASP Top 10 Proactive Controls and Exploits - Part 29分钟
3 个阅读材料
A Note From UC Davis10分钟
Welcome to Peer Review Assignments!10分钟
Reading and Resource20分钟
1 个练习
Module 1 Quiz30分钟
2

2

完成时间为 3 小时

Injection Problems

完成时间为 3 小时
17 个视频 (总计 87 分钟), 1 个阅读材料, 1 个测验
17 个视频
General Concepts: Injection Problems4分钟
SQL Injection Problems8分钟
Mitigating SQL Injection Using Prepared Statements3分钟
Mitigating SQL Injection Using Stored Procedures3分钟
Mitigating SQL Injection Using Whitelisting2分钟
Injection Problems in Real Life5分钟
Solution Screencast for Lab: Exploit Using WebGoat's SQLi Example7分钟
Cross-Site Scripting Introduction3分钟
HTTP and Document Isolation8分钟
DOM, Dynamically Generating Pages, and Cross-Site Scripting7分钟
The 3-Kinds of Cross-Site Scripting Vulnerabilities6分钟
Comparing and Contrasting Cross-Site Scripting Vulnerabilities3分钟
OWASP Prescribed Cross-site Scripting Prevention Rules - Part 16分钟
OWASP Prescribed Cross-site Scripting Prevention Rules - Part 26分钟
Command Injection Problems3分钟
OWASP Proactive Controls Related to Injections4分钟
1 个阅读材料
Resources20分钟
1 个练习
Module 2 Quiz30分钟
3

3

完成时间为 4 小时

Problems Arising From Broken Authentication

完成时间为 4 小时
11 个视频 (总计 71 分钟), 1 个阅读材料, 1 个测验
11 个视频
Overview of HTTP Protocol7分钟
Introduction to Authentication10分钟
Handling Error Messages During Authentication4分钟
Introduction to Session Management7分钟
Enforcing Access Control with Session Management7分钟
Session Management Threat: Bruteforce Session IDs10分钟
Session Management Theat: Session Fixation Vulnerabilities3分钟
Logging and Monitoring3分钟
Solution for Lab #3: WebGoat’s Session Management Vulnerability9分钟
OWASP Proactive Controls Related to Session Management and Authentication6分钟
1 个阅读材料
Resources20分钟
1 个练习
Module 3 Quiz30分钟
4

4

完成时间为 4 小时

Sensitive Data Exposure Problems

完成时间为 4 小时
9 个视频 (总计 36 分钟), 1 个阅读材料, 2 个测验
9 个视频
Introduction to Sensitive Data Exposure Problems5分钟
Issue 1: Using PII to Compose Session IDs3分钟
Issue 2: Not Encrypting Sensitive Information2分钟
Issue 3: Improperly Storing Passwords5分钟
Slowing Down Password Bruteforce Attacks7分钟
Issue 4: Using HTTP for Sensitive Client-server4分钟
OWASP Proactive Controls Related to Sensitive Data Exposure3分钟
Course Summary1分钟
1 个阅读材料
Resources20分钟
1 个练习
Module 4 Quiz30分钟

审阅

来自IDENTIFYING SECURITY VULNERABILITIES的热门评论

查看所有评论

关于 Secure Coding Practices 专项课程

This Specialization is intended for software developers of any level who are not yet fluent with secure coding and programming techniques.Through four courses, you will cover the principles of secure coding, concepts of threat modeling and cryptography and exploit vulnerabilities in both C/C++ and Java languages, which will prepare you to think like a hacker and protect your organizations information. The courses provide ample practice activities including exploiting WebGoat, an OWASP project designed to teach penetration testing....
Secure Coding Practices

常见问题

  • Access to lectures and assignments depends on your type of enrollment. If you take a course in audit mode, you will be able to see most course materials for free. To access graded assignments and to earn a Certificate, you will need to purchase the Certificate experience, during or after your audit. If you don't see the audit option:

    • The course may not offer an audit option. You can try a Free Trial instead, or apply for Financial Aid.
    • The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
  • 您注册课程后,将有权访问专项课程中的所有课程,并且会在完成课程后获得证书。您的电子课程证书将添加到您的成就页中,您可以通过该页打印您的课程证书或将其添加到您的领英档案中。如果您只想阅读和查看课程内容,可以免费旁听课程。

  • 如果订阅,您可以获得 7 天免费试听,在此期间,您可以取消课程,无需支付任何罚金。在此之后,我们不会退款,但您可以随时取消订阅。请阅读我们完整的退款政策

  • 是的,Coursera 可以为无法承担费用的学生提供助学金。通过点击左侧“注册”按钮下的“助学金”链接可以申请助学金。您可以根据屏幕提示完成申请,申请获批后会收到通知。您需要针对专项课程中的每一门课程完成上述步骤,包括毕业项目。了解更多

还有其他问题吗?请访问 学生帮助中心