Application Security — Comprehensive Study Notes (Bulleted Summary)
Introduction & Course Structure
The Application Security (MBI26H) course, part of the Bachelor Toegepaste Informatica / Applied Computer Science program, focuses on integrating security throughout the software development lifecycle.
Units and Objectives
The course objectives, detailed on Page 3, align with DLR 3 (Design/Build/Document/Test High-Quality IT Solutions) and DLR 4 (Understand Key Security Principles). Students are expected to learn how to design, build, document, and test IT solutions that include robust security features. This involves applying fundamental security principles, identifying common vulnerabilities, assessing their impact, and becoming familiar with industry security frameworks and standards. A central tenet of the course is the shift-left approach, which stresses the importance of integrating security early in the development lifecycle. This includes continuous security testing methods, the use of various tools, and the interpretation of results based on risk prioritization. Overall, this unit promotes a proactive security approach, embedding security into every development stage—from design and coding to deployment—and mandating continuous testing and maintenance even after initial delivery.
Prerequisites
Prerequisites for the course, outlined on Page 4, include a foundational understanding of cybersecurity concepts from an introductory course, encompassing basic principles from a management perspective. Essential technical skills required are experience with Frontend, Backend, or Full Stack development, strong programming abilities, and knowledge of cryptography, including hashing and encryption schemes. Furthermore, familiarity with TLS/HTTP(S) protocols, the ability to use proxies for traffic interception, and experience with sandboxed or containerized environments for secure execution are also necessary.
Software Needed
On Page 5, the required software is listed. Students will need (Virtual) Kali Linux (2024.4), which is a Debian-derived Linux distribution tailored for digital forensics and penetration testing, and is crucial for hands-on security labs. An IDE such as VS Code or IntelliJ is also necessary for coding and project management. BurpSuite Community Edition, a prominent web vulnerability scanner and proxy tool, is vital for intercepting, inspecting, modifying, and replaying web traffic during Dynamic Application Security Testing (DAST). Any additional software will be specified later.
Course Setup
The course setup, detailed on Page 6, comprises two main components. A theoretical class of 2 hours per week requires compulsory presence, with all course materials, including PowerPoint slides, accessible on the Toledo learning platform; no separate syllabus summaries will be provided. Additionally, a coaching class of 2 hours per week is available for students needing extra support or clarification. Questions for these sessions should be submitted through the official Toledo form, and they will be addressed based on priority.
Course Evaluation
Regarding course evaluation, outlined on Page 7, the first attempt (1st take) determines the final grade through a combination of assignments, contributing 6 points out of 20, and a comprehensive exam, accounting for 14 points out of 20. For students undertaking a second attempt (2nd take), the grading structure is adjusted, with assignments contributing 4 points and the exam increasing to 16 points. It is important to note that non-attendance or late submission of practical work will result in penalties.