COURSE DESCRIPTION:Android is an open platform for mobile devices such
as handsets and tablets. It has a large variety of security features
to make developing secure software easier; however, it is also missing
certain security aspects that are present in other hand-held
platforms. This advanced course gives a comprehensive overview of
these features putting an equal emphasis on both native code issues
and Java security, allowing a deeper analysis of the vulnerabilities,
attacks, protection techniques and counter attacks in three days.
The course is recommended to those developers who extensively use both
Java and native code to develop complex Android applications.
COURSE TOPICS:
DAY 1
1. IT security and secure coding
2. Android security overview
3. Application SECURITY
DAY 2
1. Basics of cryptography
2. ANDROID NATIVE CODE SECURITY
DAY 3
1. Android and Java vulnerabilities
2. Testing Android code
3. Advices and principles
4. Knowledge sources
COURSE OUTLINE:
IT SECURITY AND SECURE CODING
● Nature of security
● IT security related terms
● Definition of risk
● IT security vs. secure coding
● From vulnerabilities to botnets and cybercrime
● Classification of security flaws
ANDROID SECURITY OVERVIEW
● Android fragmentation challenges
● The Android software stack
● OS security features and exploit mitigation techniques
● The Linux kernel
● Filesystem security
● Dalvik
● Deploying applications
APPLICATION SECURITY
● Permissions
● Writing secure Android applications
● Digital Rights Management (DRM)
● Reverse engineering and debugging
BASICS OF CRYPTOGRAPHY
● Cryptosystems
● Symmetric-key cryptography
● Other cryptographic algorithms
● Asymmetric (public-key) cryptography
● Public Key Infrastructure (PKI)
● Cryptography on Android
ANDROID NATIVE CODE SECURITY
● Buffer overflow possibilities in Android
● ARM architecture
● Buffer overflow on the stack
● Protection techniques – ASLR, XN, RELRO, …
ANDROID AND JAVA VULNERABILITIES
● Input validation
● SQL Injection
● Cross-Site Scripting (XSS)
● Improper use of security features
● Improper error and exception handling
● Code quality problems
TESTING ANDROID CODE
● Testing Android code
● Android Lint
● Android Lint – Security features
● Lint exercise
● PMD
● PMD exercise
● FindBugs
● FindBugs exercise
ADVICES AND PRINCIPLES
● Matt Bishop’s principles of robust programming
● The security principles of Saltzer and Schroeder
KNOWLEDGE SOURCES
● Secure coding sources – a starter kit
● Vulnerability database
COURSE FEATURES:
LEARNING OBJECTIVES:
Individuals certified at this level will have demonstrated:
● Understand basic concepts of security, IT security and
secure coding
● Learn the security solutions on Android
● Learn to use various security features of the Android
platform
● Get information about some recent vulnerabilities in Java
on Android
● Get understanding on native code vulnerabilities on
Android
● Learn about typical coding mistakes and how to avoid them
● Get practical knowledge in using security testing tools
● Get sources and further reading on secure coding practice
CERTIFICATION:
Once after the TRAINING WE WILL PROVIDE YOU THE COURSE COMPLETION
CERTIFICATE.
WHO CAN ATTEND?
Android application developers, architects and testers.
culture
sports
2562
Views
25/01/2020 Last update