Web and Mobile Systems Security
A.Y. 2026/2027
Learning objectives
The course provides the theoretical and methodological foundations for the design, analysis, and evaluation of the security of Web and mobile applications. Through the study of the most common application vulnerabilities, attack techniques, and corresponding mitigation strategies, the course develops students' ability to critically assess the security of modern application systems and to design secure applications according to the principles of Secure by Design and the Secure Software Development Lifecycle (SSDLC).
Expected learning outcomes
At the end of the course, students will be able to:
· analyze the attack surface of a Web or mobile application by identifying its assets, trust boundaries, and main threats;
· describe and evaluate the main vulnerabilities affecting Web and mobile applications, understanding their causes and their potential impact on the security requirements of the system;
· analyze authentication, authorization, and session management mechanisms, evaluating their effectiveness against common attack scenarios;
· apply methodologies and tools for identifying and analyzing vulnerabilities in Web and mobile applications;
· design appropriate countermeasures to mitigate the main application security vulnerabilities by applying the principles of Security by Design and the Secure Software Development Lifecycle (SSDLC);
· critically evaluate the architectural and design choices of an application with respect to confidentiality, integrity, availability, and authenticity requirements;
· interpret a security vulnerability both from the attacker's perspective, by understanding how it can be exploited, and from the security engineer's perspective, by identifying the most effective prevention and mitigation strategies.
· analyze the attack surface of a Web or mobile application by identifying its assets, trust boundaries, and main threats;
· describe and evaluate the main vulnerabilities affecting Web and mobile applications, understanding their causes and their potential impact on the security requirements of the system;
· analyze authentication, authorization, and session management mechanisms, evaluating their effectiveness against common attack scenarios;
· apply methodologies and tools for identifying and analyzing vulnerabilities in Web and mobile applications;
· design appropriate countermeasures to mitigate the main application security vulnerabilities by applying the principles of Security by Design and the Secure Software Development Lifecycle (SSDLC);
· critically evaluate the architectural and design choices of an application with respect to confidentiality, integrity, availability, and authenticity requirements;
· interpret a security vulnerability both from the attacker's perspective, by understanding how it can be exploited, and from the security engineer's perspective, by identifying the most effective prevention and mitigation strategies.
Lesson period: Second semester
Assessment methods: Esame
Assessment result: voto verbalizzato in trentesimi
Single course
This course cannot be attended as a single course. Please check our list of single courses to find the ones available for enrolment.
Course syllabus and organization
Single session
Course currently not available
INFO-01/A - Informatics - University credits: 6
Laboratories: 24 hours
Lessons: 36 hours
Lessons: 36 hours