Back close

Course Detail

Course Name Web Application Security
Course Code 24CY604
Program M. Tech. in Cyber Security
Semester 1
Credits 4
Campus Coimbatore

Syllabus

Syllabus

Web Application Development basics – client side- server side technologies- session management techniques- OWASP Top 10 flaws – Web Application Technologies – Vulnerabilities – OS command injection – Directory traversal – SQL injection – Cross-site Scripting (XSS) – Cross-site Request Forgery (CSRF) – Clickjacking – Web Cache Poisoning – DOM-based vulnerabilities – Access Control Vulnerabilities and Privilege Escalation – Cross-origin resource sharing (CORS) — XML external entity (XXE) injection – Server-side request forgery (SSRF) – HTTP request smuggling – Web sockets security, API security issues. Web 3.0 Architecture and security. 

Objectives and Outcomes

Prerequisites

Basics of Web development (HTML. CSS, JavaScript, any Server side scripting language) 

 

Course Outcome
 

Course Outcome  

Bloom’s Taxonomy Level  

CO 1  

Understand the fundamentals of web applications 

L2  

CO 2  

Identify and mitigate common server side security vulnerabilities 

L3  

CO 3  

Identify and mitigate common client side security vulnerabilities 

L3  

CO 4  

Apply standard mitigation technique to prevent security vulnerabilities. 

L3  

 

CO-PO Mapping

CO-PO Mapping  

CO/PO  

PO 1 

PO 2 

PO 3 

PO 4 

PO 5 

PO 6 

PO 7 

PO 8 

PO 9 

PO 10 

PSO1 

PSO2 

PSO3 

CO 1 

– 

– 

CO 2 

– 

– 

CO 3 

– 

– 

CO 4 

– 

– 

Text Books / References

  1. Shostack, Adam. Threat modeling: Designing for security . John Wiley & Sons, 2014. 
  2. Dafydd Stuttard, and Marcus Pinto, The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws , 2nd Edition, John Wiley & Sons, 2011. 
  3. Wenliang Du, Computer Security – A hands-on Approach , First Edition, Createspace Independent Pub, 2017 
  4. https:// www.owasp.org  

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now