Domenico PARENTE | PROGRAMMAZIONE SICURA
Domenico PARENTE PROGRAMMAZIONE SICURA
cod. 0522500065
PROGRAMMAZIONE SICURA
0522500065 | |
DIPARTIMENTO DI INFORMATICA | |
COMPUTER SCIENCE | |
2014/2015 |
YEAR OF DIDACTIC SYSTEM 2010 | |
SECONDO SEMESTRE |
SSD | CFU | HOURS | ACTIVITY | |
---|---|---|---|---|
INF/01 | 7 | 56 | LESSONS | |
INF/01 | 2 | 16 | LAB |
Objectives | |
---|---|
KNOWLEDGE AND UNDERSTANDING THE STUDENT WILL ACQUIRE KNOWLEDGE, SKILLS, AND PRACTICAL EXPERIENCES of software static analysis to be able to understand the security degree of a software. APPLYING KNOWLEDGE AND UNDERSTANDING THE goal of the COURSE is also that to teach to use main tools of software analysis, in particular those currently mainly utilized to deal the safety and the security of the software. MAKING JUDGEMENTS THE STUDENT WILL BE ABLE TO evaluate the safety and the security OF A software based on the tools which have been taught him. COMMUNICATION SKILLS THE COURSE AIMS TO MAKE THE STUDENT AWARE OF the security and safety ISSUES related to a software and WILL BE ABLE TO COMMUNICATE TO A SPECIALIZED PUBLIC AND NON-SPECIALIZED AUDIENCE, WITH COMPETENCE, CONFIDENCE, AND PROPER TERMS, possible approaches to their solution. LEARNING SKILLS THE COURSE WILL PROVIDE THE STUDENT WITH THE TOOLS NECESSARY TO ALLOW CONTINUOUS UPDATING OF HIS/HER KNOWLEDGE EVEN AFTER THE CONCLUSION THE COURSE ITSELF (LIFE LONG LEARNING). THE STUDENT WILL BE ABLE TO READ ANY DOCUMENTATION ON safety and security, UNDERSTANDING THE BASIC MEANING, ALTHOUGH HE/SHE WILL ABLE TO PARTIALLY GET THE THEORETICAL ISSUES THAT MIGHT BE PRESENT IN SUCH DOCUMENTS. |
Prerequisites | |
---|---|
KNOWLEDGE of linux operating system and C, Java and Php programming |
Contents | |
---|---|
the course introduces to the static analysis of software code to make it safe and secure, showing a global view of the main security problems that occurs nowadays. The main points are shown in C and JAVA language, using security accidents occurred in reality and showing how code errors are exploited and show how they should be prevented and how static analysis could rapidly locate them. The course does not need any particular prerequisite and is addressed to everybody who cares to safe programming. Many examples from real life will be shown, like vulnerability of FIREFOX, OPENSSH, MYSPACE, ETRADE, APACHE HTTPD and other techniques to deal with unreliable input and how to deal with the problem of the buffer overflow. Tactics and strategies to avoid specific web applications, web SERVICES and AJAX, safe LOGGING, debugging and error handling and exceptions. Creations, maintainance and secret sharings and confidential information. |
Teaching Methods | |
---|---|
The course has some theoretical lectures to transfer necessary knowledge to understand the main topics and some practical lectures where main tools of static analysis for software are shown. The course will also push students for individual and group exercises. |
Verification of learning | |
---|---|
One practical exam in laboratory along with an oral colloquium or a single project to develop |
Texts | |
---|---|
Secure Programming with Static Analysis, Brian Chess, Jacob West, Pearson Addison Wesley, ISBN 978-0321424778 |
BETA VERSION Data source ESSE3 [Ultima Sincronizzazione: 2016-09-30]