Java Spring & Python Security Training
Web Secure Coding (Java & Python)
Learning Objective:
To offer training in microservice security and open web security, ensuring the
implementation of cutting-edge security measures and adept handling of vulnerabilities for
maximum efficiency.
Assumption:
The audience comprises individuals from diverse backgrounds such as testing, development,
architects, and more.
Total Duration : 27 hours for TWO Batches Java & Python
Mode of training : Class Room for India Participant
Schedule Time :
CLASS ROOM SESSION for INDIA
JAVA
PYTHON
26 Total Hrs
Training Training Time 23
Date Day Participants Java &
Day IST Participants
Trainer - Python
Trainer - Hari
Suneesh
1 26-02-2024 Monday 2pm to 5pm Combined Session 3
2 27-02-2024 Tuesday 10am to 1pm Separate Separate 6
3 28-02-2024 Wednesday 2pm to 5pm Separate Separate 6
4 29-02-2024 Thursday 10am to 1pm Separate Separate 6
5 01-03-2024 Friday 2pm to 5pm Separate Seperate 6
27
Java
OWASP Security (Day 1 – 3 hours - Combined Session)
Topics:
1. Web penetration testing
2. Information gathering
3. Scanning and Enumeration
4. Mapping
5. Reflected XSS
6. Attacking the users
7. Attacking Server
8. Attacking Authentication
9. Attacking Datastore
Blurays Technologies
Java Spring & Python Security Training
Microservices Security (Day 2 – 3 hours)
Topics:
1. OWASP API Vulnerabilities
2. Software Security
3. Thread Modelling
4. Thread Modelling Methodologies
5. Secure Architecture
Application & Data Security (Day 3 – 3 hours)
Topics:
1. Authentication
2. OAuth2 Protocol
3. Authentication and Architect
4. Authorization
5. Secure communication
6. Secure code and data
7. Logging and Monitoring
8. Security challenges with microservices
9. Securing microservices network, identity and data
Service Mesh, Logging and Monitoring (Day 4- 3 hours)
Topics:
1. Introduction to service mesh
2. Problems solved by service mesh
3. Anatomy and types of service mesh
4. Products and implementations
5. Service mesh and security
6. Logging vs Monitoring and implementation
7. Logging and security
Security for Developers (Day 5 -3 hours)
Topics:
1. HTTP Headers
2. JSON Web Tokens
3. Technical measures and best practices
4. Cryptography
5. OWASP Web Vulnerabilities
Blurays Technologies
Java Spring & Python Security Training
Python Microservice Security
RESTful API Security in Microservices (Day 1 - 3 hours)
Topics:
1. Microservices Architecture and Security Concerns
2. API Gateway Security
3. Securing Service-to-Service Communication
4. Container Security
5. API Security Standards
6. Vulnerability Management in Microservices
Application & Data Security (Day 2 - 3 hours)
Topics:
1. Advanced Authentication Mechanisms
2. Session Management in Python
3. Input Validation and Sanitization
4. File Upload Security
5. Python Security Libraries and Tools
6. Securing WebSocket Communications
7. Rate Limiting and Throttling
8. Content Security Policy (CSP)
Service Mesh, Logging and Monitoring (Day 3 - 3 hours)
Topics:
1. Introduction to Service Mesh in Python Microservices
2. Implementing Service Mesh for Security
3. Logging Best Practices
4. Tracing Python Applications
5. Audit Trails and Compliance
Security for Developers (Day 4 - 3 hours)
Topics:
1. Principles of Secure Design
2. Code Analysis and Review
3. Dependency Management and Security
4. Secure Development Practices in Python
5. Integrating Security in Agile and DevOps
Blurays Technologies