Back close

Course Detail

Course Name Web Application Security
Course Code 26CY604
Program M. Tech. in Cyber Security
Semester 1
Credits 4
Campus Coimbatore

Syllabus

Syllabus

Web application development basics – Client-side technologies – Server-side technologies– Authentication and access control – Session management techniques – OWASP Top 10 flaws – Web application technologies – vulnerabilities.

Server-side attacks – SQL injection – OS command injection – Directory traversal – Business logic vulnerabilities – Access Control Vulnerabilities and Privilege Escalation –XML external entity (XXE) injection – Server-side request forgery (SSRF) – Web cache deception – API testing.
Client-side attacks – Cross-site Scripting (XSS) – Cross-site Request Forgery (CSRF) – Cross-origin resource sharing (CORS) – Clickjacking – Web Cache Poisoning – DOM-based vulnerabilities.
Web 3.0 architecture and security – Web sockets security – Web LLM attacks – HTTP request smuggling – Web Cache Poisoning – JWT attacks.

Objectives and Outcomes

Prerequisites

Basics of Web development (HTML. CSS, JavaScript, any Server side scripting language)

Course Outcome
Course Outcome Bloom’s Taxonomy Level
CO 1 Understand the fundamentals of web applications L2
CO 2 Identify and mitigate common server side security vulnerabilities L3
CO 3 Identify and mitigate common client side security vulnerabilities L3
CO 4 Apply standard mitigation technique to prevent security vulnerabilities. L3

 

CO-PO Mapping

CO-PO Mapping

CO/PO

PO 1 PO 2 PO 3 PO 4 PO 5 PO 6 PO 7 PO 8 PO 9 PO 10 PSO1 PSO2 PSO3
CO 1 2 2 2 2 3 1 1 1 2 2 2
CO 2 2 2 3 3 3 1 1 2 3 3 3
CO 3 2 2 3 3 3 1 1 2 3 3 3
CO 4 2 2 3 3 3 1 1 2 3 3 3

Text Books / References

  1. Shostack, Adam. Threat modeling: Designing for security . John Wiley & Sons, 2014.
  2. Dafydd Stuttard, and Marcus Pinto, The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws , 2nd Edition, John Wiley & Sons, 2011.
  3. Wenliang Du, Computer Security – A hands-on Approach , First Edition, Createspace Independent Pub, 2017
  4. https:// www.owasp.org

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now