SWE308 Software SecurityInstitutional InformationDegree Programs Software Engineering (English)Information For StudentsDiploma SupplementErasmus Policy StatementNational Qualifications
Software Engineering (English)

Preview

Bachelor TR-NQF-HE: Level 6 QF-EHEA: First Cycle EQF-LLL: Level 6

Course General Introduction Information

Course Code: SWE308
Course Name: Software Security
Course Semester: Spring
Course Credits:
ECTS
6
Language of instruction:
Course Requirement:
Does the Course Require Work Experience?: No
Type of course: Necessary
Course Level:
Bachelor TR-NQF-HE:6. Master`s Degree QF-EHEA:First Cycle EQF-LLL:6. Master`s Degree
Mode of Delivery: Face to face
Course Coordinator : Prof. Dr. HALİS ALTUN
Course Lecturer(s): Prof Dr Halis ALTUN
Course Assistants:

Course Purpose and Content

Course Objectives: To learn the basic concepts of secure software development, to have information about secure software development processes and tools.
Course Content: Software security principles, Software security methods, Secure software development lifecycle, Security testing tools, Secure software development lifecycle processes and maturity models (Microsoft SDL, OWASP SAMM, BSIMM), Application security and rules, Secure software development checklist, Web Security of Applications, Project studies

Learning Outcomes

The students who have succeeded in this course;
1) Introduces Secure Software Development Life Cycle
2) Learns How to Build Secure Applications
3) Introduces Application Based Attacks

Course Flow Plan

Week Subject Related Preparation
1) Software Security basic concepts
2) SOFTWARE SECURITY PRINCIPLES, METHODS TO ENSURE SOFTWARE SECURITY
3) Secure Development Lifecycle
4) SECURE SOFTWARE DEVELOPMENT MATURITY MODELS, Web Applications Fundemantals and Properties
5) SECURE SOFTWARE DEVELOPMENT MATURITY MODELS, Web Applications Fundemantals and Properties
6) INJECTION ATTACK
7) INJECTION ATTACK
8) Midterm
9) Cross Site Scripting (XSS)
9) Cross Site Scripting (XSS)
10) Cross Site Request Forgery(CSRF)
11) Cross Site Request Forgery(CSRF)
12) Server Side Request Forgery(SSRF)
13) Cross Origin Resource Sharing (CORS)

Sources

Course Notes / Textbooks: Software Security: Building Security In by Gary McGraw. Addison-Wesley
References: TUBITAK Secure Software Development Guide

DDO-Information and Communication Security Guide-3.2.6 Secure Software Development

24 Deadly Sins of Software Security, ISBN: 978-0-07-162675-0 , by Howard, LeBlanc, and Viega

Course - Learning Outcome Relationship

No Effect 1 Lowest 2 Medium 3 Highest
       
Program Outcomes Level of Contribution
1) Sufficient knowledge in mathematics, science and software engineering discipline-specific topics; the theoretical and practical knowledge in these areas, the ability to use in complex engineering problems.
2) The ability to identify, formulate, and solve complex engineering problems; selecting and applying appropriate analysis and modelling methods for this purpose.
3) The ability to design a complex system, process, device or product under realistic constraints and conditions to meet specific requirements; the ability to apply modern design methods for this purpose.
4) Ability to develop, select and use modern techniques and tools necessary for analysis and solution of complex problems in engineering applications; ability to use information technologies effectively.
5) Ability to design experiments, conduct experiments, collect data, analyse and interpret the results of complex engineering problems or discipline-specific research topics.
6) Disiplin içi ve çok disiplinli takımlarda etkin biçimde çalışabilme becerisi; bireysel çalışma becerisi.
7) Awareness of the need for lifelong learning; access to knowledge, ability to follow developments in science and technology, and constant self-renewal.
8) Effective communication skills in Turkish oral and written communication; at least one foreign language knowledge; ability to write effective reports and understand written reports, to prepare design and production reports, to make effective presentations, to give clear and understandable instructions and to receive.
9) Conformity to ethical principles, professional and ethical responsibility; Information on standards used in engineering applications.
10) Information on practices in business, such as project management, risk management and change management; awareness about entrepreneurship, innovation; information on sustainable development.
11) Information on the effects of engineering applications on health, environment, and safety in universal and social dimensions, and on the problems of the modern age in engineering; awareness of the legal consequences of engineering solutions.
12) Adequate skills in the analysis, design, verification, evaluation, implementation, implementation, and maintenance of software systems

Learning Activity and Teaching Methods

Anlatım
Bireysel çalışma ve ödevi
Course
Grup çalışması ve ödevi

Measurement and Evaluation Methods and Criteria

Yazılı Sınav (Açık uçlu sorular, çoktan seçmeli, doğru yanlış, eşleştirme, boşluk doldurma, sıralama)
Homework
Grup Projesi

Assessment & Grading

Semester Requirements Number of Activities Level of Contribution
Quizzes 3 % 15
Homework Assignments 3 % 35
Midterms 1 % 10
Final 1 % 40
total % 100
PERCENTAGE OF SEMESTER WORK % 60
PERCENTAGE OF FINAL WORK % 40
total % 100

İş Yükü ve AKTS Kredisi Hesaplaması

Activities Number of Activities Aktiviteye Hazırlık Aktivitede Harçanan Süre Aktivite Gereksinimi İçin Süre Workload
Course Hours 14 3 42
Study Hours Out of Class 14 4 56
Project 1 20 20
Homework Assignments 3 8 24
Quizzes 3 5 15
Midterms 1 12 12
Final 1 20 20
Total Workload 189