• DocumentCode
    2230624
  • Title

    A Comprehensive Undergraduate Application Security Project

  • Author

    Uppuluri, Prem ; Pittges, Jeff

  • Author_Institution
    Dept. of Inf. Technol., Radford Univ., Radford, VA, USA
  • fYear
    2012
  • fDate
    16-18 April 2012
  • Firstpage
    600
  • Lastpage
    607
  • Abstract
    The importance of teaching application security at an undergraduate level is well-understood. However, comprehensive coverage of application security must cover a vast range of topics from system administration to secure software development. In our experience, providing students with hands-on experience poses a challenge: either the entire project is limited to a specific area, such as system administration, or the project consists of disconnected assignments each covering one area. Neither option is satisfactory as both fail to address an important learning outcome of any security course: securing computing infrastructure requires a comprehensive approach. In this paper, we describe a semester-long project for an undergraduate application security course that (a) provides students with a comprehensive view of security and (b) reinforces the theoretical skills with intensive hands-on experience. The project consists of several independent assignments that enable students to accomplish smaller tasks as they implement a fully integrated solution. The project requires limited laboratory facilities and utilizes software tools and and technologies that are freely available to academic institutions.
  • Keywords
    computer science education; educational courses; educational institutions; security of data; teaching; academic institution; application security teaching; computing infrastructure; learning outcome; secure software development; software technology; software tool; system administration; undergraduate application security course; undergraduate application security project; Access control; Authentication; Databases; Encoding; Java; Standards; Application security; security education;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology: New Generations (ITNG), 2012 Ninth International Conference on
  • Conference_Location
    Las Vegas, NV
  • Print_ISBN
    978-1-4673-0798-7
  • Type

    conf

  • DOI
    10.1109/ITNG.2012.127
  • Filename
    6209218