Presented by Security Kaizen Labs
14. 21, 28 April
Course Code: ECSPNET
- Additional information
- Reviews (0)
EC-Council Certified Secure Programmer. NET (ECSP)
Software defects, bugs, and flaws in the logic of a program are consistently the cause for software vulnerabilities. Analysis by software security professionals has proven that most vulnerabilities are due to errors in programming. Hence, it has become crucial for organizations to educate their software developers about secure coding practices.
Attackers scan for security vulnerabilities in applications and servers and attempt to use these vulnerabilities to steal secrets, corrupt programs and data, and gain control of computer systems and networks. Sound programming techniques and best practices should be used to develop high quality code to prevent web application attacks. Secure programming is a defensive measure against attacks targeted towards application systems.
The ECSP.Net course will be invaluable to software developers and programmers alike to code and develop highly secure applications and web applications. This is done throughout the software life cycle that involves designing, implementing, and deployment of applications.
.Net is widely used by organizations as a leading framework to build web applications. ECSP.Net teaches developers how to identify security flaws and implement security countermeasures throughout the software development life cycle to improve the overall quality of products and applications.
This course will:
- Familiarize you with .Net Application Security, ASP.Net Security Architecture and help you understand the need for application security and common security threats to .Net framework
- Discuss security attacks on .Net framework and explain the secure software development life cycle
- Help you to understand common threats to .Net assemblies and familiarize you with stack walking processes
- Discuss the need for input validation, various input validation approaches, common input validation attacks, validation control vulnerabilities, and best practices for input validation
- Familiarize you with authorization and authentication processes and common threats to authorization and authentication
- Discuss various security principles for session management tokens, common threats to session management, ASP.Net session management techniques, and various session attacks
- Cover the importance of cryptography in .Net, different types of cryptographic attacks in .Net, and various .Net cryptography namespaces
- Explain symmetric and asymmetric encryption, hashing concepts, digital certificates, digital and XML signatures
- Describe the principles of secure error handling, different levels of exception handling, and various .Net logging tools
- Examine file handling concepts, file handling security concerns, path traversal attacks on file handling, and defensive techniques against path traversal attack
You must be well-versed with .NET programming
|Who Should Attend||
The ECSP certification is intended for programmers who are responsible for designing and building secure Windows/Web based applications with .NET Framework. It is designed for developers who have .NET development skills.