Next-Gen Security for .NET:
5 days of Training and Migration
Welcome to the "Application Security Training" course! This five-day program is designed to provide you with a comprehensive understanding of application security, including the necessary prerequisites for effective learning and a section on migrating from .NET 4.5 to modern .NET. By the end of this course, you will be equipped with the knowledge and skills to secure applications effectively using the latest .NET technologies.
Learning Outcomes
By the end of this course, you will be able to:
- Understand the fundamentals of C# and .NET.
- Implement authentication and authorization in .NET applications.
- Manage sessions and access control to prevent security vulnerabilities.
- Securely handle input and output data to prevent common attacks.
- Protect sensitive data using encryption and secure data management practices.
- Implement secure error handling and logging.
- Manage vulnerable dependencies and protect business logic.
- Handle untrusted files securely.
- Harden application configuration.
- Understand ISO27001 requirements and API security.
- Migrate from .NET 4.5 to modern .NET versions.
Prerequisites
Before attending this course, you should have:
- Basic understanding of programming concepts.
- Familiarity with basic web development.
- A laptop with internet connectivity and the ability to install software.
Detailed Training Outline
- C# Recap:
- Overview of C# syntax and features.
- Object-oriented programming principles in C#.
- Key libraries and frameworks in the .NET ecosystem.
- Migrating from .NET 4.5 to Modern .NET:
- Challenges of using obsolete versions.
- Step-by-step migration process.
- Key features and improvements in modern .NET versions (e.g., .NET Core, .NET 5/6/7).
- Dotnet Authentication and Authorization:
- Implementing authentication through the login page.
- Overview of .NET Core identity.
- Role-based authorization.
- Authentication and authorization in .NET Core Razor pages.
- Session Management:
- Importance of session management.
- Techniques for managing sessions in .NET applications.
- Best practices for secure session management.
- Access Control:
- Fundamentals of access control.
- Preventing Cross-site Request Forgery (CSRF) attacks.
- Implementing access control mechanisms in .NET.
- Securely Handling Input and Output Data:
- Input validation techniques.
- Encoding output data to prevent XSS attacks.
- Preventing SQL injection attacks with Entity Framework Core and ADO.NET.
- Preventing operating system command injection.
- Demo: Invoking encoders in code.
- Protecting Sensitive Data:
- Encrypting and decrypting sensitive data.
- Secrets management in .NET applications.
- Protecting data in the browser.
- Sending sensitive data in HTTP request bodies.
- Preventing data from being cached in the browser.
- Data privacy best practices.
- Implementing export and deletion of personal data.
- Protecting data in transit.
- Demo: Enforce use of HTTPS protocol.
- Secure TLS configuration for outbound network connections.
- Secure Error Handling and Logging:
- ASP.NET Core logging and exception handling.
- Redacting sensitive information before logging.
- Logging relevant security events.
- Preventing the leaking of sensitive information through error pages.
- Managing Vulnerable Dependencies:
- Understanding risks from dependencies.
- Managing NuGet packages securely.
- Tools and techniques for managing vulnerable dependencies.
- Protecting the Business Logic:
- Identifying business logic flaws.
- Techniques for protecting business logic integrity.
- Handling Untrusted Files:
- Securely handling files in ASP.NET.
- Preventing large file uploads.
- Scanning uploaded files for viruses and malware.
- Securely storing uploaded files.
- Preventing server-side request forgery (SSRF) attacks.
- Hardening Configuration:
- Disabling debugging facilities.
- Hiding system component information.
- Validating HTTP request headers.
- Setting HTTP security headers in responses.
- ISO27001 Requirements:
- Overview of ISO27001 requirements.
- Implementing ISO27001 in .NET applications.
- Best practices for compliance.
- API Security:
- Securing APIs with SSL.
- Using service credentials to authenticate to the API.
- Using the HTTP Basic Authorization method.
This training course is designed to be hands-on and interactive, ensuring that you not only learn theoretical concepts but also apply them in practical scenarios. By the end of these five days, you will be proficient in securing applications using the latest .NET technologies and best practices.
Practical, connected learning
My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.