Web Security Fundamentals

8.–9.12.2026 | remote: Etäkoulutus, Etäkoulutus

Ohjelma

Tiistaina 8.12.

09:00

Introduction to Web Security

  • Why do we need web security? 
  • Protecting your users and their data 
  • Social Engineering 
  • Goals and focus 
  • Trust boundaries and the basic principles of web security 
10:30

Break

10:45

Character Encoding and HTTPS

  • Character sets, Unicode and the problem with characters 
  • Encodings: UTF-8 and UTF-16 
  • The problem with HTTP and the fundamentals of HTTPS 
  • Protocols, ciphers and moving from HTTP to HTTPS 
  • HTTP Strict Transport Security (HSTS) 
12:00

Lunch Break

13:00

Certificates and Secure Connections

  • Certificate Authorities (CAs) and certificate trust 
  • Certificate lifetime and renewal 
  • Certificate pinning 
  • Mutual TLS (mTLS) 
  • Managing certificates securely 
14:15

Coffee Break

14:30

Cross-Site Scripting (XSS)

  • Reflected, stored and self-XSS 
  • Data sanitization and safe handling of user input 
  • Mutation XSS 
  • Preventing and mitigating XSS vulnerabilities 
15:30

Content Security Policy (CSP)

  • Policies and directives 
  • Creating effective CSP policies 
  • CSP reporting and production use 
  • Strict CSP 
16:00

See you tomorrow! The first training day ends

Keskiviikkona 9.12.

09:00

CSRF, Cookies and Browser Security

  • Understanding cookies and Cross-Site Request Forgery (CSRF) 
  • Protecting applications against CSRF 
  • Securing cookies with HttpOnly and Secure 
  • Prefixed cookie names, CHIPS and partitioned cookies 
  • SameSite cookies: Strict, Lax and None 
10:30

Break

10:45

Securing Dependencies and Injection Attacks

  • Typosquatting and source control attacks 
  • Build server security and Subresource Integrity 
  • SQL injection and blind SQL injection 
  • Code and XML injection attacks 
  • File inclusion attacks 
12:00

Lunch Break

13:00

Securing the Session and Authentication

  • Detecting stolen cookies 
  • Fingerprinting and Cookie Confusion 
  • Multi-Factor Authentication (MFA) 
  • Mobile authenticators 
  • Protecting user sessions and authentication flows 
14:15

Coffee Break

14:30

Denial-of-Service and Building Secure Websites

  • Denial-of-Service attacks against applications 
  • Attacking XML and regular expressions 
  • Trust boundaries and Zero Trust 
  • Hack yourself: testing your own security 
  • Honeypots and defensive security techniques 
15:30

Summary and Key Takeaways

  • Review of the most important web security principles 
  • Connecting the different security controls 
  • Practical considerations for building secure web applications 
16:00

Thank you! The training ends