Application Security Advanced / Professional

Advanced Software Protection Engineering

15 min 10 weeks 8 places left
Advanced Software Protection Engineering
Programme Overview

Programme Modules

  • Module 1 - Protection Architecture Principles: Layered defence design, threat modelling for software products
  • Module 2 - Virtualisation-Based Obfuscation: Custom VM design, bytecode translation, performance trade-offs
  • Module 3 - Anti-Tamper Systems: Code signing, runtime integrity verification, checksum strategies
  • Module 4 - Licence Server Architecture: Cryptographic licence generation, offline grace periods, revocation
  • Module 5 - Supply Chain and Embedded Components: Verifying third-party binaries, update pipeline security, embedded utility risks
  • Module 6 - Evasion and Counter-Evasion: Anti-debug, anti-VM, timing attacks and their detection
  • Module 7 - Capstone Project: Design, implement, and document a full protection system for a provided application
Prerequisites
Completion of a foundational application security course or equivalent professional experience
Tools used
IDA Free, x64dbg, Ghidra, custom lab VMs provided on enrolment

About This Programme

Software application protection is a technical discipline that rewards patience over shortcuts. Whether you are exploring pdf24 desktop download options or tracing how pdf24 windows download packages handle licence validation, the mechanics are consistent - and worth understanding properly.

There is a significant gap between knowing that obfuscation exists and being able to design a protection system that survives a determined analyst for more than an afternoon.

This programme is built for people who already understand the basics and want to go further. The focus is on protection architecture: how to combine multiple layers so that removing one does not collapse the whole system. Topics include VM-based code protection, self-modifying code techniques, cryptographic integrity checks, and the design of licence servers that remain functional under partial network failure.

A realistic picture of what protection achieves

No protection system is permanent. The goal is to make analysis expensive enough that the economics stop making sense for most attackers. This course teaches you to think in those terms - cost of attack versus value of target - rather than chasing impossible guarantees.

The programme also covers supply chain considerations. Developers who distribute software bundles, including components similar to pdf24 desktop download integrations or embedded document utilities, face specific risks around binary verification and update integrity. These scenarios are worked through in dedicated sessions.

Lab environment

Each participant receives access to a sandboxed analysis environment pre-loaded with industry-standard tools. You will both attack and defend sample applications, which is the only way to build genuine intuition for where defences break.

Designing protection without ever attacking it is like writing tests you know will pass. The adversarial perspective changes everything.

Expect to spend roughly eight to ten hours per week on this programme. The material is dense and the labs require patience. Participants who complete all seven modules and the capstone project receive a verified completion certificate.

Back to Programme List Get in Touch