Please enable JavaScript to use CodeHS

AP Cybersecurity

Securing Applications and Data

Students learn how adversaries attack the data and applications at the center of the digital world. They explore application and file vulnerabilities, then learn to set access controls that limit who can access data, including configuring access control settings on a Linux system. Students use both symmetric and asymmetric cryptography to protect the confidentiality and integrity of data in storage and in transit. They also study secure design principles and input sanitization, and learn to detect attacks by verifying file hashes and analyzing log files for indicators of compromise.

Lessons

5.1 The Access Problem (Application and Data Vulnerabilities and Attacks)

  • The Three Access Gaps
  • Access Control Simulator
  • The Hospital Case
  • File and Access Vulnerabilities
  • Read the Message

5.2 When Input Becomes an Attack (Application and Data Vulnerabilities and Attacks)

  • The Input Problem
  • Eight Characters That Break a Database
  • Trace the Attack
  • When Websites Execute Your Code
  • The Samy Worm
  • +5 more

5.3 When the Boundaries Break (Application and Data Vulnerabilities and Attacks)

  • When Boundaries Fail
  • Boundary Failure Lab
  • Attack Surface Audit
  • Boundary Attacks

5.4 How Do You Measure Risk? (Application and Data Vulnerabilities and Attacks)

  • CIA and the Risk Scale
  • Risk Level Classifier
  • Prioritize Findings
  • Risk Assessment

5.5 Data in the Wrong Hands: Classification, Regulation & Policy (Protecting Applications and Data)

  • Where Is Your Data Right Now?
  • Spot the Data State
  • PII, PHI & PCI: What the Law Requires
  • Clearwater Breach Analysis
  • The Rules Behind the Encryption
  • +3 more

5.6 Who Gets In? Access Control Models (Protecting Applications and Data)

  • Roles, Rules & Who Gets Access
  • RBAC in a Hospital Records System
  • Owners vs. Admins: DAC, MAC & Bell-LaPadula
  • Bell-LaPadula Simulator
  • Why Less Access Is More Secure
  • +4 more

5.7 Locking Down Files: Linux Permissions (Protecting Applications and Data)

  • How Linux Controls File Access
  • Decoding Permission Strings
  • chmod: Numeric & Symbolic Methods
  • chmod: Forward and Reverse
  • Misconfigured Permissions in the Wild
  • +5 more

5.8 Capstone: Defending a Real System (Protecting Applications and Data)

  • Putting It All Together
  • Capstone: Securing the Meridian Health App
  • Data & Application Security
  • The Permission Puzzle
  • Chmod Workshop

5.9 Keys, Blocks, and Streams (Protecting Stored Data with Cryptography)

  • Symmetric Encryption
  • Enhanced Caesar Cipher
  • Mixed Alphabet Cipher
  • Encryption Mechanics
  • AI in the Security Workflow
  • +2 more

5.10 The Advanced Encryption Standard (Protecting Stored Data with Cryptography)

  • Breaking News: NIST Picks a Winner
  • AES Is Everywhere
  • The Breach That Couldn't Be Read
  • Pick a Key
  • Inside the Block
  • +2 more

5.11 Tools for AES (Protecting Stored Data with Cryptography)

  • Know Your Environment
  • Tool 1: AES Web-Based Encryption
  • Tool 2: AES Crypt
  • Encryption Has Limits
  • Tool 3: AES and OpenSSL
  • +3 more

5.12 Two Keys Are Better Than One (Asymmetric Cryptography)

  • Breaking News: Two Keys Are Better Than One
  • Public Key Cryptography
  • Key Pairs Demo
  • Protecting the Private Key
  • Find the Flaw
  • +3 more

5.13 More Keys Than Stars (Asymmetric Cryptography)

  • Mission Briefing: Keys and Keyspaces
  • Field Exercise: Crack the Vault
  • Intel Report: The Math of Guessing
  • Keyspace Checkpoint
  • Your Own Locks
  • +2 more

5.14 Tools for RSA (Asymmetric Cryptography)

  • Breaking News: The Internet Learns to Trust
  • Right Encryption for the Job: AES, RSA, and ECC
  • RSA, ECC, and Asymmetric Encryption
  • Tool 1: RSA Web-Based Encryption
  • Tool 2: Desktop RSA Encryption
  • +3 more

5.15 Capstone: The VitalLink Security Consult (Asymmetric Cryptography)

  • The VitalLink Security Consult
  • Part 1: Match the Encryption to the Data
  • Part 2: Solve the Key-Sharing Problem
  • Part 3: Recommend a Key Length

5.16 Secure by Design & Secure by Default (Protecting Applications)

  • Two Cameras, Two Outcomes
  • Secure by Design
  • Secure by Design
  • Secure by Default: Out of the Box
  • Secure-by Consultation

5.17 User Input Sanitization (Protecting Applications)

  • When Text Attacks
  • Sanitizing Inputs
  • Control Characters and Input Sanitization
  • SQL Injection in Action
  • SQL Injection in Action
  • +4 more

5.18 Catching the Intruder: How Systems Detect Attacks (Detecting Attacks on Data and Applications)

  • Something Doesn't Add Up
  • Log Detective
  • Honeypot Traps and Hash Tripwires
  • Match the Trap to the Threat
  • Real-Time or Too Late?

5.19 Choosing the Right Controls (Detecting Attacks on Data and Applications)

  • Cost, Sensitivity, and Classification
  • Detection Budget Simulator
  • The Right Controls for the Right Data
  • Detective Control Criteria

5.20 Verifying File Integrity with Hashes (Detecting Attacks on Data and Applications)

  • Cryptographic Hashes as File Tripwires
  • Hash It Out
  • Find the Tampered Files
  • When the Baseline Is Not Trustworthy
  • Reflection: When the Baseline Is Not Trustworthy
  • +1 more

5.21 Reading the Attack: Log Analysis for Application Attacks (Detecting Attacks on Data and Applications)

  • SQL Injection Signatures in the Logs
  • SQL Injection Log Detector
  • Spotting XSS, Buffer Overflows, and Directory Traversal
  • Multi-Attack Log Classifier
  • Hunting for Attacks in the Meridian Portal
  • +3 more

5.22 Securing Applications and Data Quiz

  • Securing Applications and Data Quiz

Courses that include this module