IIKG2001
Software Security
Spring
Gjøvik
English
About this course
Content
- Software vulnerabilities, taxonomies, CWE, OWASP Top 10
- Web application vulnerabilities
- Offensive security, CAPEC, attack vectors
- Secure/defensive programming, threat analysis, banned functions
- Access control implementation, Windows security
- Certification of products
- Source code analysis, supply chain, dependencies, code inspection, data flow analysis, patterns, tools, automation
- Security testing, absence/presence of vulnerabilities, structured testing, abuse cases, penetration testing, fuzzing
- Secure software development life cycle, principles, practices, activities, integration, software delivery and integrity
- Software maintenance, greenfield/brownfield, third-party dependencies, risk analysis, patching
Learning outcomes
Knowledge
- The students have basic knowledge on how software can be created and maintained with security in mind.
- They understand attack patterns and measures to prevent these.
- The students have an overview of existing techniques, classes of tools and the methods used in software development today.
Skills
- Students can apply their knowledge to problem cases in an industrial or research setting.
- They are able to identify potential threats and vulnerabilities early in a program's lifecycle and apply measures that prevent or reduce vulnerabilities in software.
General competence
- The students succeed in presenting their analyses and approaches to other developers, superiors and customers.
- Through the practical application of attack methods and the analysis of their consequences, students develop an awareness of the responsible use and design of information technology.
Teaching methods
- Lectures partly on campus and partly digitally streamed
- Laboratory work
- Compulsory assignments
- Home reading
- Group work (encouraged, not mandatory)
- Sustainability Lab
Coursework requirements: All obligatory exercises must be approved.