Subject

Софтверски дефинирана безбедност

1. Course Title Софтверски дефинирана безбедност
Software defined security
2. Code F23L3S159
3. Study Programme Интернет, мрежи и безбедност
4. Organizer of the study programme (unit, institute, department or division) Faculty of Computer Science and Engineering
5. Degree level (first, second, third cycle) Прв циклус
6. Academic year / semester 6 / Летен
7. Number of ECTS credits 6
8. Teacher Анастас Мишев, Ристе Стојанов
9. Prerequisites for enrolling in the course Освоени најмалку 100 ЕКТС
10. Objectives of the course programme (competences) Разбирање и примена на клучните концепти од развој на безбеден софтвер во поглед на податоци, автентикација, авторизација и безбедни веб апликации.
11. Course content Предавања:
1. Вовед во животниот циклус на развој на безбеден софтвер Secure Development LifeCycle (SDL)
2. Introduction to Hacking Web Applications
3. Securing Modern Web Applications.
4. Cross-Site Scripting (XSS). Cross-Site Request Forgery (CSRF). XML External Entity (XXE).
5. Injection, Denial of Service (DoS), Exploiting Third-Party Dependencies
6. Secure Application Architecture
7. Code constructs promoting security -Domain Driven Design
8. Domain primitives, Ensuring integrity of state, Reducing complexity of state
9. Reviewing Code for Security
10. Leveraging your delivery pipeline for security
11. Vulnerability Discovery
12. Vulnerability Management

Вежби:
1. Вовед во животниот циклус на развој на безбеден софтвер Secure Development LifeCycle (SDL)
2.
3.
4. Defending Against XSS Attacks, Defending Against CSRF Attacks, Defending Against XXE
5. Defending Against Injection, Defending Against DoS, Securing Third-Party Dependencies.
6. Secure Application Architecture
7. Code constructs promoting security
8. Domain primitives, Ensuring integrity of state, Reducing complexity of state
9. Reviewing Code for Security
10. Leveraging your delivery pipeline for security
11. Vulnerability Discovery
12. Vulnerability Management
12. Learning methods Предавања со користење на презентации, интерактивни предавања, вежби (користење на опрема и софтверски пакети), тимска работа, пример случаи, поканети гости предавачи, самостојна изработка и одбрана на проектна задача и семинарска работа.
13. Total available time 6 ECTS x 30 hours = 180 hours
14. Distribution of available time 30 + 45 + 15 + 15 + 75 = 180 часа
15. Forms of teaching activities
15.1. Lectures - theoretical instruction 30 hours
15.2. Exercises (laboratory, auditory), seminars, teamwork 45 hours
16. Other forms of activities
16.1. Project assignments 15 часови
16.2. Independent assignments 15 часови
16.3. Home study 75 часови
17. Assessment method
17.1. Tests 10 бодови
17.2. Seminar paper / project (presentation: written and oral) 15 бодови
17.3. Activities and learning 10 бодови
17.4. Final exam 70 бодови
18. Grading criteria (points / grade)
up to 50 points5 (five) (F)
from 51 to 60 points6 (six) (E)
from 61 to 70 points7 (seven) (D)
from 71 to 80 points8 (eight) (C)
from 81 to 90 points9 (nine) (B)
from 91 to 100 points10 (ten) (A)
19. Requirement for obtaining a signature and taking the final exam реализирани лабораториски вежби
20. Language of instruction Macedonian and English
21. Method for monitoring the quality of teaching internal evaluation and survey mechanism
22. Literature
22.1. Required literature
1. Ransome, James, and Anmol Misra | Core software security: security at the source | CRC Press | 2013
2. Matulevičius, Raimundas | Fundamentals of Secure System Modelling | Springer | 2017
3. Dan Bergh Johnsson, Daniel Deogun, and Daniel Sawano | Secure by Design | Manning Publications Co. | 2019
4. Andrew Hoffman | Web Application Security: Exploitation and Countermeasures for Modern Web Applications 1st Edition | O`Reilly Media | 2020
22.2. Additional literature
No. Author Title Publisher Year