Secure Web and Distributed Application Development Training

Secure Web and Distributed Application Development is a hands-on, two-day intermediate course built around the OWASP Top 10. Java/JEE developers learn to recognize, test and defend the most critical web application security risks — injection, broken authentication, sensitive data exposure, XXE, broken access control, security misconfiguration, XSS, insecure deserialization and insufficient logging — writing code that implements security best practices.

LevelIntermediate
Duration2 days
DeliveryInstructor-led · live online or classroom
LabsHands-on labs & demos (Eclipse/TomEE)
PrerequisiteJava / JEE experience
Learning Objectives
  • Perform bug hunting safely and ethically, and use organizational defect-reporting mechanisms
  • Understand the concepts and terminology behind defensive, secure coding and the goals of a typical exploit
  • Identify the OWASP Top 10 Most Critical Web Application Security Risks and the consequences of their exploitation
  • Recognize common web application exploits and implement secure-coding standards to mitigate them
  • Identify untrusted data sources and test web applications with attack techniques to verify layered defenses
  • Detect, attack and defend authentication and authorization mechanisms
  • Write web application code that implements security best practices, including secure database use
  • Harden web and application servers and apply strong encryption for data at rest and in flight
Prerequisites

Experience programming in Java or a similar object-oriented language; familiarity with JEE.

Course Outline
  • Module 1: Bug Hunting Foundations
    • Security and insecurity, dangerous assumptions, attack vectors, safe and ethical bug hunting, working ethically, respecting privacy, defect notification and bug-bounty programs.
  • Module 2: Moving Forward from Hunting Bugs
    • Removing bugs with OWASP and the OWASP Top Ten, the Web Application Security Consortium, CERT Secure Coding Standards, mistakes to avoid, and tools and resources.
  • Module 3: Securing Web Applications
    • Principles of information security, security as a lifecycle issue, minimizing attack surface, layered defense and compartmentalization — with Eclipse (JEE) and Apache TomEE lab setup and a HyperSQL database tutorial.
  • Module 4: Unvalidated Data
    • Buffer overflows, integer arithmetic vulnerabilities, crossing trust boundaries, defending trust boundaries, and whitelisting versus blacklisting.
  • Module 5: OWASP A1 — Injection
    • Injection flaws, how SQL injection attacks evolve, stored procedures, other forms of injection, and minimizing injection flaws.
  • Module 6: OWASP A2 — Broken Authentication
    • Quality and protection of authentication data, server-side password handling, database authentication defenses, session-ID risk reduction, and HttpOnly and security headers.
  • Module 7: OWASP A3 — Sensitive Data Exposure
    • Protecting data to mitigate impact, in-memory data handling, secure pipes, and failures in the TLS/SSL framework.
  • Module 8: OWASP A4 — XML External Entities
    • XML parser coercion, XML attack structure and injection, safe XML processing, and dynamic loading using XSLT.
  • Module 9: OWASP A5 — Broken Access Control
    • Excessive privileges, insufficient flow control, unprotected resource access, unsafe direct object references, and session management.
  • Module 10: OWASP A6 — Security Misconfiguration
    • System hardening and IA mitigation, application whitelisting, least privilege, anti-exploitation and a secure baseline.
  • Module 11: OWASP A7 — Cross-Site Scripting
    • XSS patterns, persistent and reflective XSS, DOM-based XSS, and best practices for untrusted data.
  • Module 12: OWASP A8/A9 — Deserialization & Vulnerable Components
    • Deserialization issues, identifying serialization and deserialization, vulnerable components, software inventory and managing updates.
  • Module 13: OWASP A10 — Insufficient Logging & Monitoring
    • Logging best practices, error-handling fixes, and forensics and data loss prevention.

Related training topics

Get approved to attend

Justify your training

Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.

Sample training request letter

Subject: Request for Programming & Development training from Applied Technology Academy

[Decision Maker Name],

I'm writing to request time and budget approval to complete Applied Technology Academy's course, Secure Web and Distributed Application Development Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.

Course Description
Secure Web and Distributed Application Development is a hands-on, two-day intermediate course built around the OWASP Top 10. Java/JEE developers learn to recognize, test and defend the most critical web application security risks — injection, broken authentication, sensitive data exposure, XXE, broken access control, security misconfiguration, XSS, insecure deserialization and insufficient logging — writing code that implements security best practices. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.

Course Objectives
Once I've completed the course, I'll be able to:

  • Perform bug hunting safely and ethically, and use organizational defect-reporting mechanisms
  • Understand the concepts and terminology behind defensive, secure coding and the goals of a typical exploit
  • Identify the OWASP Top 10 Most Critical Web Application Security Risks and the consequences of their exploitation
  • Recognize common web application exploits and implement secure-coding standards to mitigate them
  • Identify untrusted data sources and test web applications with attack techniques to verify layered defenses
  • Detect, attack and defend authentication and authorization mechanisms
  • Write web application code that implements security best practices, including secure database use
  • Harden web and application servers and apply strong encryption for data at rest and in flight

Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.

Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.

Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in programming & development. Additional course information is available at https://appliedtechnologyacademy.com/secure-web-and-distributed-application-development/.

Thank you for your consideration,
[Your Name]

Design training around your team, not the other way around.

Talk to a training advisor about private cohorts, funding paths and program management.

Request a Quote Call 800.674.3550