YoVDO

Building Layers of Defense with Spring Security

Offered By: GOTO Conferences via YouTube

Tags

GOTO Conferences Courses Web Security Courses Application Security Courses Authorization Courses Access Control Lists Courses Browser Security Courses Spring Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore layers of defense in application security using Spring Security in this GOTO Amsterdam 2017 conference talk. Dive into essential concepts like authentication, authorization, and web security. Learn how to implement crucial security measures including HTTP headers, CSRF protection, and CORS attack prevention. Discover techniques for securing method invocations, implementing multi-tenancy, and ownership-based access control. Gain insights on browser caching, content sniffing prevention, and protection against clickjacking and cross-site scripting attacks. Understand the importance of HTTPS, proper session management, and secure password handling. Apply these concepts to build robust, multi-layered security for modern web applications using the Spring Framework.

Syllabus

Introduction
Who am I
What is security
Application level security
Layers of defense
Redundancy
Spring Security
Application Security
Getting Started
Authentication Manager
Web Security
Authorization
Default Setup
Default Login Page
Browser Caching
Browser Headers
Content Sniffing
HTTP Strict Transport Security
Clickjacking Attacks
XFrame Options
Reflected CrossSite Scripting
Public Key Pinning
Headers
CSRef Protection
Custom Tokens
State Changing Operations
Session Scope Token
Single Page Applications
CSRF Security
Authorization Requests
Limitations
Ordering Rules
Denial of Access
Gutshots
NetEnabled
Method Security Annotation
PostAuthorize
Custom Functions
Method Level Security
Net Roles Allowed
Accessing Current Users
Custom Authorization
Access Control List
HTTPS Everywhere
Coverage Sessions
Passwords
Conclusion
Defaults


Taught by

GOTO Conferences

Related Courses

Introduction to Cyber Security
Uttarakhand Open University, Haldwani via Swayam
The Complete Cyber Security Course : Network Security!
Udemy
The Beginners 2024 Cyber Security Awareness Training Course
Udemy
Modern Browser Security Reports
Pluralsight
JavaScript Security Part 1
Infosec via Coursera