IIKG2001

Software Security

Spring

Gjøvik

English

Overview

94 candidates

Average grade

C

3.13

0.40

Pass rate

90%

7 points

Grade distribution
Average over time
Pass rate over time

About this course

Content

  • Software vulnerabilities, taxonomies, CWE, OWASP Top 10
  • Web application vulnerabilities
  • Offensive security, CAPEC, attack vectors
  • Secure/defensive programming, threat analysis, banned functions
  • Access control implementation, Windows security
  • Certification of products
  • Source code analysis, supply chain, dependencies, code inspection, data flow analysis, patterns, tools, automation
  • Security testing, absence/presence of vulnerabilities, structured testing, abuse cases, penetration testing, fuzzing
  • Secure software development life cycle, principles, practices, activities, integration, software delivery and integrity
  • Software maintenance, greenfield/brownfield, third-party dependencies, risk analysis, patching

Learning outcomes

Knowledge

  • The students have basic knowledge on how software can be created and maintained with security in mind.
  • They understand attack patterns and measures to prevent these.
  • The students have an overview of existing techniques, classes of tools and the methods used in software development today.

Skills

  • Students can apply their knowledge to problem cases in an industrial or research setting.
  • They are able to identify potential threats and vulnerabilities early in a program's lifecycle and apply measures that prevent or reduce vulnerabilities in software.

General competence

  • The students succeed in presenting their analyses and approaches to other developers, superiors and customers.
  • Through the practical application of attack methods and the analysis of their consequences, students develop an awareness of the responsible use and design of information technology.

Teaching methods

  • Lectures partly on campus and partly digitally streamed
  • Laboratory work
  • Compulsory assignments
  • Home reading
  • Group work (encouraged, not mandatory)
  • Sustainability Lab

Coursework requirements: All obligatory exercises must be approved.