IMT3501
Software Security
Last taught 2021
Autumn
Gjøvik
English
About this course
Content
- Secure software development lifecycle
- Low level and application related vulnerability analysis
- Security requirement and secure design
- Secure coding practices and software inspection
- Security testing
Learning outcomes
Knowledge
-The students have basic knowledge on how software can be created and maintained with security in mind, i.e. deviation from expected functionality owing to interaction with an adversary.
-They understand attack patterns, e.g. buffer overflows, format string
problems, command injection and cross-site scripting.
-The students have an overview of existing techniques, classes of tools and the methods used in software development today.
Skills
-Students can apply their knowledge to problem cases in an industrial or research setting.
-They are able to identify potential threats and vulnerabilities early in a program's lifecycle and apply measures that prevent or reduce vulnerabilities in software.
General competence
-The students succeed in presenting their analyses and approaches to other developers, superiors and customers.
Teaching methods
-Lectures
-Laboratory exercises
-Compulsory assignments
Coursework requirements:
All obligatory exercises must be approved.