Community developer events

Writing Secure Code in .NET

Date
14-16 May 2007 (Add to calendar) GMT
Venue
JB International , London, GB
Cost
£1200+VAT

Writing Secure Code in .NET Training Course Outline

Security Overview

The Need for Secure Systems
Trustworthy Computing
Proactive Security Development
SD 3 : Secure by Design, by Default, and in Deployment
Security Principles
Threat Modelling

Security Techniques

Preventing Buffer Overruns
Determining Appropriate Access Control
Running with Least Privilege
Cryptographic Techniques
Protecting Secret Data
Guarding against Input
Canonical Representation Issues
Database Input Issues
Web-Specific Input Issues
Internationalization Issues
Socket Security
Securing RPC, ActiveX Controls, and DCOM
Protecting Against Denial of Service Attacks


Writing Secure .NET Code

Code Access Security Overview
Using FxCop
Strong-Named Assemblies
Specifying Assembly Permission Requirements
Use of Assert
Demands and Link Demands
Limiting Who Uses Your Code
XML and Configuration Files
Partial Trust Assemblies
Issues with Delegates
Issues with Serialization
The Role of Isolated Storage
Tracing and Debugging
General Good Practices


Security Testing

The Role of the Security Tester
Building Security Test Plans from a Threat Model
Testing Clients with Rogue Servers
Determining Attack Surface
Performing a Security Code Review


Secure Software Installation

Principle of Least Privilege
Using the Security Configuration Editor
Low-Level Security APIs



Building Privacy into Your Application

Malicious vs. Annoying Invasions of Privacy
Major Privacy Legislation
Privacy vs. Security
Building a Privacy Infrastructure
Designing Privacy-Aware Applications

 

Writing Security Documentation and Error Messages

Security Issues in Documentation
Security Issues in Error Messages
Information Disclosure Issues
Security Usability


Developers Security Checklist

Comments

  1. 01 Jan 1999 at 00:00

    This thread is for discussions of Writing Secure Code in .NET.

Leave a comment

Sign in or Join us (it's free).

Map

Other nearby events

  • Feb 4

    Securing Web Applications Training Course

    6km away in London

    The Securing Web Applications training course is a one day hands on event targeted at web developers. The courses is delivered by Sec-1 whos main activity is the assessment of web applications for corporate and government clients.

  • Dec 12

    Ruby Manor 2 : Manor Harder

    8km away in London

    Ruby Manor 2 : Manor Harder The Guvner is opening the doors to The Manor once again, and just like last time it’s up to you to fill my echoing halls with the sound of Ruby. It'll be the same process as last year, so you can just read last year’s announcement again () and skip straight to making a topic suggestion (something you’d like to listen to) or talk proposal (something you’d like to speak about) in a new thread on the mailing list

  • Nov 27

    Agile Specifications, Bdd And Testing Exchange

    8km away in London

    Following the excellent response to our Agile Testing and BDD community events and courses during the last 10 months, Skills Matter is proud to organise the first, annual Agile Specification, BDD and Testing eXchange - an intensive and intimate event aimed at bringing together leading thinkers and passionate community members. The aim of this eXchange is to promote awareness and adoption of modern Agile Testing techniques and ideas.

  • Dec 2

    David Laribee's Towards a New Architect workshop

    8km away in London

    Calling all technical leads, senior developers, coaches & architects: you can nto afford to miss David Laribee's David Laribee's Towards a New Architect 2-day workshop. David's highly-anticipated workshop is a must for anyone wanting to learn actionable techniques and tools for leading your team toward greater throughput and technical excellence.

  • Dec 4

    HTML 5 Communication: Using Web Sockets, Server-Sent Events, and more to build real-time Web applications

    8km away in London

    he HTML 5 Communication Workshop is a highly practical, one-day workshop about HTML 5 Communication for Real-time Web applications, using Web Sockets, Server-Sent Events (SSE), PostMessage, Cross-Document Messaging, and more. Presented by Kaazing consultants, this workshop will teach you how to create next generation real-time Web 2.0 solutions, using HTML 5 Communication, which will work in today's browsers. The afternoon session is hands-on, so bring your laptop!

Related podcasts

We'd love to hear what you think! Submit ideas or give us feedback