FIT5003 Software security
Faculty of Information Technology
FIT5003 Software security is a level 5, 6-credit-point, postgraduate unit from the Faculty of Information Technology, offered in 2022 in Semester 1 and Semester 2 at Clayton. It needs FIT9131 or FIT9133.
- Credit points
- 6
- Offered in 2022
- Semester 1, Semester 2
- Clayton
- Assessment
- Exam 50%
- and 2 other tasks
- Workload
- 144 hours
- per semester
This is the 2022 handbook entry. See the 2027 entry.
Reviews
No reviews yetNo reviews yet. Be the first to review FIT5003.
Requisites
Before FIT5003
Prohibitions
You can't enrol if you have passed any of these.
- ITO5003 Software and network security
- ITI5003Software securityNo reviews yet
Prerequisites
Pass these before you enrol.
Corequisites
Pass these before, or take them in the same semester.
After FIT5003
No unit lists FIT5003 as a prerequisite in the 2022 handbook.
Enrolment rules
Prerequisites
- For students enrolled in E3001, E3002, E3005, E3010, E3011, E3007: FIT2099.
- For C6007 students who commended in 2020: None
Equivalent units
The same content under another code. Only one of them counts.
Overview
This unit aims to introduce the secure software development issues including secure software development life cycle, secure software design principles, secure coding practices, threat evaluation models, secure software testing, deployment and maintenance, software development and security policy integration. Students are provided with a range of practical exercises and tasks to reinforce their skills including: identification of security bugs in programs written in different programming languages, design, implementation, and testing of secure concurrent and networked applications, identification of vulnerabilities in networked and mobile/wireless applications. In addition, students will learn input validation techniques to minimise security risks, man-in-the-middle attack techniques to be able to build more secure networked applications, practical secure software testing techniques to be able to test applications for security bugs.
Offerings in 2022
| Teaching period | Campus | Mode |
|---|---|---|
| First semester | Clayton | On campus |
| Second semester | Clayton | On campus |
Assessment
- Assignment 1AssignmentThreshold hurdle30%
- In-class testIn class testThreshold hurdle20%
- Scheduled final assessment (2 hours and 10 minutes)ExamThreshold hurdle50%
Learning outcomes
When you finish this unit, you should be able to:
- 1
Investigate methods that are appropriate for the realisation software security;
- 2
Investigate and model the possible vulnerabilities and threats for a given application system;
- 3
Design, implement and produce test procedures and perform evaluation of software security features of concurrent and networked applications.
- 4
Analyse and evaluate software security related scenarios with reference to the code of ethics and professional practice.
Workload and teaching
- Laboratories24 hours
- Lectures24 hours
- Teaching approachActive learning
Minimum total expected workload to achieve the learning outcomes for this unit is 144 hours per semester typically comprising a mixture of scheduled online and face to face learning activities and independent study. Independent study may include associated reading and preparation for scheduled activities. The unit requires on average three/four hours of scheduled activities per week. Scheduled activities may include a combination of teacher directed learning and online engagement.
Learning resources
Required resources
Software for completing lab exercises will be either supplied in the lab or freely available for download from specified websites.
Recommended resources
Textbooks that we will refer to include:
- 1. G McGraw, Software Security , Addison-Wesley Software Security Series, 2006 (referred to as "McGraw" in reading lists on Moodle). Copy available at the Monash library.
- 2. M Howard and D LeBlanc, Writing Secure Code , Microsoft Press, 2nd Edition, 2003. (referred to as "HowLe" in reading lists on Moodle). Available online via Monash library.
- 3. J Erickson, Hacking: The Art of Exploitation , No Starch Press, 2008. Available online via Monash library. (referred to as "Erick" in reading lists on Moodle).
- 4. D Stuttard and M Pinto, The Web Application Hacker’s Handbook , Wiley, 2nd Edition, 2011. Available at Monash library. (referred to as "StuPint" in reading lists on Moodle).
- 5. Scott Oaks, Java Security: Writing and Deploying Secure Applications, O'Reilly, 2nd Edition, 2013.
- 6. Nikolay Elenkov, Android Security Internals: An In-Depth Guide to Android's Security Architecture, 2014
- 7. Wenliang Du, Computer & Internet Security: A Hands-on Approach, Second Edition, ISBN: 978-1733003926 (hardcover) or 978-1733003933 (paperback), 2019
Where it fits
FIT5003 is part of 2 areas of study in the 2022 handbook.
Contacts
- Unit Coordinators
- Dr Viet Vo
- Mrs Fariha Jaigirdar
- Chief Examiners
- Dr Ron Steinfeld
- Dr Xiaoning Du
Common questions
What are the prerequisites for FIT5003?
You need FIT9131 or FIT9133 before you enrol; and FIT5163 before or alongside it. Enrolment rules also apply.
When is FIT5003 offered?
In 2022, FIT5003 runs in Semester 1 and Semester 2 at Clayton.
How much work is FIT5003?
The handbook expects about 144 hours of study across the semester. No students have rated its difficulty yet.
Does FIT5003 have an exam?
Yes. The exam is worth 50% of the final mark, alongside 2 other tasks.
Which majors and minors include FIT5003?
FIT5003 is part of Computational science and Software engineering.