YAZ308 Software SecurityInstitutional InformationDegree Programs Computer EngineeringInformation For StudentsDiploma SupplementErasmus Policy StatementNational Qualifications
Computer Engineering

Preview

Bachelor TR-NQF-HE: Level 6 QF-EHEA: First Cycle EQF-LLL: Level 6

Course General Introduction Information

Course Code: YAZ308
Course Name: Software Security
Course Semester: Spring
Course Credits:
ECTS
6
Language of instruction: TR
Course Requirement:
Does the Course Require Work Experience?: No
Type of course: Departmental Elective
Course Level:
Bachelor TR-NQF-HE:6. Master`s Degree QF-EHEA:First Cycle EQF-LLL:6. Master`s Degree
Mode of Delivery: Face to face
Course Coordinator : Prof. Dr. HALİS ALTUN
Course Lecturer(s): Prof Dr Halis ALTUN
Course Assistants:

Course Purpose and Content

Course Objectives: To learn the basic concepts of secure software development, to have information about secure software development processes and tools.
Course Content: Software security principles, Software security methods, Secure software development lifecycle, Security testing tools, Secure software development lifecycle processes and maturity models (Microsoft SDL, OWASP SAMM, BSIMM), Application security and rules, Secure software development checklist, Web Security of Applications, Project studies

Learning Outcomes

The students who have succeeded in this course;
1) Introduces Secure Software Development Life Cycle
2) Learns How to Build Secure Applications
3) Introduces Application Based Attacks

Course Flow Plan

Week Subject Related Preparation
1) Software Security basic concepts
2) SOFTWARE SECURITY PRINCIPLES, METHODS TO ENSURE SOFTWARE SECURITY
3) Secure Development Lifecycle
4) SECURE SOFTWARE DEVELOPMENT MATURITY MODELS, Web Applications Fundemantals and Properties
5) SECURE SOFTWARE DEVELOPMENT MATURITY MODELS, Web Applications Fundemantals and Properties
6) INJECTION ATTACK
7) INJECTION ATTACK
8) Midterm
9) Cross Site Scripting (XSS)
9) Cross Site Scripting (XSS)
10) Cross Site Request Forgery(CSRF)
11) Cross Site Request Forgery(CSRF)
12) Server Side Request Forgery(SSRF)
13) Cross Origin Resource Sharing (CORS)

Sources

Course Notes / Textbooks: Software Security: Building Security In by Gary McGraw. Addison-Wesley
References: TUBITAK Secure Software Development Guide

DDO-Information and Communication Security Guide-3.2.6 Secure Software Development

24 Deadly Sins of Software Security, ISBN: 978-0-07-162675-0 , by Howard, LeBlanc, and Viega

Course - Learning Outcome Relationship

No Effect 1 Lowest 2 Medium 3 Highest
       
Program Outcomes Level of Contribution
1) Adequate knowledge in mathematics, science and engineering subjects pertaining to the relevant discipline; ability to use theoretical and applied knowledge in these areas in complex engineering problems.
2) Ability to identify, formulate, and solve complex engineering problems; ability to select and apply proper analysis and modeling methods for this purpose.
3) Ability to design a complex system, process, device or product under realistic constraints and conditions, in such a way as to meet the desired result; ability to apply modern design methods for this purpose
4) Ability to devise, select, and use modern techniques and tools needed for analyzing and solving complex problems encountered in engineering practice; ability to employ information technologies effectively.
5) Ability to design and conduct experiments, gather data, analyze and interpret results for investigating complex engineering problems or discipline specific research questions.
6) Ability to work efficiently in intra-disciplinary and multi-disciplinary teams; ability to work individually.
7) Ability to communicate effectively in Turkish, both orally and in writing; knowledge of a minimum of one foreign language; ability to write effective reports and comprehend written reports, prepare design and production reports, make effective presentations, and give and receive clear and intelligible instructions.
8) Knowledge of the global and societal impacts of engineering practices on priority issues such as health, environment and safety and contemporary issues; knowledge of the legal aspects of engineering solutions. awareness of the consequences
9) Consciousness to behave according to ethical principles and professional and ethical responsibility; knowledge on standards used in engineering practice.
10) Information about business life practices such as project management, risk management, and change management; awareness of entrepreneurship, innovation, and knowledge about sustainable development.
11) Ability to design systems to meet desired needs
12) Ability to apply basic sciences in the field of computer engineering
13) Ability to implement designs by experiments
14) Recognition of the need for lifelong learning; ability to access information, to follow developments in science and technology, and to continue to educate him/herself.

Learning Activity and Teaching Methods

Anlatım
Bireysel çalışma ve ödevi
Course
Grup çalışması ve ödevi

Measurement and Evaluation Methods and Criteria

Yazılı Sınav (Açık uçlu sorular, çoktan seçmeli, doğru yanlış, eşleştirme, boşluk doldurma, sıralama)
Homework
Grup Projesi

Assessment & Grading

Semester Requirements Number of Activities Level of Contribution
Quizzes 3 % 15
Homework Assignments 3 % 35
Midterms 1 % 10
Final 1 % 40
total % 100
PERCENTAGE OF SEMESTER WORK % 60
PERCENTAGE OF FINAL WORK % 40
total % 100

İş Yükü ve AKTS Kredisi Hesaplaması

Activities Number of Activities Aktiviteye Hazırlık Aktivitede Harçanan Süre Aktivite Gereksinimi İçin Süre Workload
Course Hours 14 3 42
Study Hours Out of Class 14 4 56
Project 1 20 20
Homework Assignments 3 8 24
Quizzes 3 5 15
Midterms 1 12 12
Final 1 20 20
Total Workload 189