TEXT_SIZE

In-depth Assessment Techniques: Design, Code, and Runtime

1-Day Tracks

User Rating: / 0
PoorBest 
Track Name
: In-depth Assessment Techniques: Design, Code, and Runtime
Track ID : SB1DIAT
Instructor : Pravir Chandra
CPE Credits : 7 CPE’s
Duration : 1 Day
Date : November 20th, 2009 (9 AM – 6 PM)
Fortify

Who should attend?

    1. Anyone who is interested in advancing their software assessment skills
    2. Security Architects & Consultants wanting to learn advanced secure design concepts
    3. Team leads and developers interested in learning more about Design reviews, code reviews and
    4. Runtime code analysis
    5. Penetration Testers and security testers

      Class Pre-requisite:

        1. Architects and developers.
        2. Prior experience in Penetration testing or software security assessment preferred.

          Class Requirement:

          1. No laptop required.

          Course Overview

          This tutorial is targeted at those wanting to enhance their software assessment skills. Specifically, the tutorial teaches attendees techniques for design analysis, code review, and penetration testing that uncovers a wide variety of vulnerabilities and weaknesses in applications. If you have pre-existing skills and want to learn more than this course is perfect. The tutorial will generally focus on web applications, but most information applies to software of any type. In addition, attendees will learn general methods for protecting against the security issues uncovered by each assessment technique. The tutorial topics include:
          1. System decomposition for analysis
          2. Lightweight threat/risk modeling
          3. Identifying interfaces/attack surface
          4. Testing business logic and edge cases
          5. Assessing for provision of security mechanisms
          6. Assessing for key vulnerability classes
          7. Risk classification and weighting
          8. Root cause analysis and patching
          The tutorial has a primary focus on intermediate/advanced assessment and testing concepts for architects and developers. Automated security assessment tools will be discussed in context, but not demoed.

          Twitter Updates

          Speakers @ Glance

          Follow Us On

          Facebook Group FeedBurner Linked In Group Twitter YouTube