- From www.coursera.org
Programming Cloud Services for Android Handheld Systems: Security
- Self-paced
- Free Access
- 5 Sequences
- Introductive Level
Course details
Syllabus
This MOOC describes, by example, the basics of securing mobile applications and back-end cloud services. The class is taught in the context of Java, Android, and the
. Although the cloud service topics in this course will be taught in the context of connecting mobile devices to the cloud, the concepts are broader and will give students the ability to create the cloud services to support large-scale web applications, such as social networking applications; cloud services for embedded systems, such as the Internet of Things and Industrial Internet; and wearable computing devices.The course is organized into the sections outlined below (additional lectures may be provided live once the MOOC has begun):
Module 1: Android App Security and Risks
- Part 1: Traditional App Accounts
- Part 2: Mobile vs. Traditional App Accounts
- Part 3: App Account Mapping to Linux Users
- Part 4: Apps Lie & Steal
- Part 5: How Android Protects Apps
- Part 6: What Android Doesn't Protect
- Part 7: Avoid Storing Sensitive Data in Public Locations
- Part 8: Risks of Insecure File Permissions
- Part 0: The Challenge of Secure Coding
- Part 1: Security Vulnerability Walkthrough
- Part 2: Principles of Secure Abstractions
- Part 3: Avoid Coupling Data & Security State
- Part 4: Build Abstractions that are Hard to Use Insecurely
- Part 5: Bound & Strongly Type Security State
- Part 6: Avoid Conditional Logic in Secure Pathways
- Part 7: Prevent Secure Pathways from Being Broken at Runtime
- Part 8: Privilege Escalation Concepts
- Part 9: Privilege Escalation Scenario
- Part 10: Privilege Escalation Code Walkthrough
- Part 11: Privilege Escalation Fixes
- Part 12: User Interface Attacks
- Part 13: Cross-platform User Interface Attacks
- Part 1: Man in the Middle Attacks Public Key Infrastructure
- Part 2: HTTPS
- Part 3: Challenges of Storing Secrets on Mobile
- Part 4: WebView Security Issues & Best Practices
- Part 1: Sessions
- Part 2: Spring Security Overview
- Part 3: Spring Security Configuration in Java
- Part 4: Building a Custom UserDetailsService
- Part 5: Setting up a custom UserDetailsService
- Part 6: The Principal
- Part 7: Spring Security Role Annotations
- Part 8: More Complex Expression-based Pre Post Authorize Annotations
- Part 9: Spring Security Controller Code Walkthrough
- Part 10: Spring Security Controller Test Code Walkthrough
- Part 1: Stateful Sessions with Cookies Why They Aren't Ideal for Mobile
- Part 2: Stateless Sessions with Tokens
- Part 3: OAuth 2.0
- Part 4: Spring Security OAuth 2.0
- Part 5: A Spring OAuth 2.0 Secured Service
- Part 6: A Retrofit Oauth 2.0 Client for Password Grants
Prerequisite
Instructors
- C. White - Electrical Engineering and Computer Science
- - Electrical Engineering and Computer Science
Editor
Platform
Coursera - это цифровая компания, предлагающая массовые открытые онлайн-курсы, основанные учителями компьютеров Эндрю Нгом и Стэнфордским университетом Дафни Коллер, расположенные в Маунтин-Вью, штат Калифорния.
Coursera работает с ведущими университетами и организациями, чтобы сделать некоторые из своих курсов доступными в Интернете, и предлагает курсы по многим предметам, включая: физику, инженерию, гуманитарные науки, медицину, биологию, социальные науки, математику, бизнес, информатику, цифровой маркетинг, науку о данных и другие предметы.