Course Outline
Introduction to Secure C and C++ Development
- Exploring principles of secure software development
- Identifying prevalent security risks in C and C++ applications
- Understanding the link between programming errors and security vulnerabilities
- Reviewing secure coding standards and industry best practices
Common C and C++ Programming Vulnerabilities
- Recognising coding errors that introduce security risks
- Addressing memory safety issues specific to C and C++
- Evaluating vulnerability patterns and their potential impact
- Examining examples of insecure code
Secure Programming Principles
- Implementing defence-in-depth strategies
- Writing robust, maintainable code
- Reducing attack surfaces
- Adopting secure design principles for C and C++ applications
Input Validation and Data Handling
- Appreciating the critical role of input validation
- Thwarting exploitation via malicious inputs
- Employing data sanitisation methods
- Ensuring secure handling of user and external data
Error Handling and Exception Management
- Mitigating risks from inadequate error handling
- Designing secure error and exception mechanisms
- Preventing information leakage through error messages
- Building resilient applications
Memory Safety and Buffer Overflow Protection
- Understanding memory management vulnerabilities
- Addressing stack-based buffer overflows
- Addressing heap-based buffer overflows
- Detecting and preventing memory corruption
- Utilising safe memory handling techniques
Stack Protection and Runtime Security Features
- Understanding stack overflow vulnerabilities
- Leveraging compiler-based security protections
- Implementing stack canaries and related mechanisms
- Utilising Address Space Layout Randomization (ASLR)
- Exploiting modern operating system security features
Advanced C++ Security Considerations
- Managing secure object lifecycles
- Preventing use-after-free vulnerabilities
- Safe management of pointers and references
- Avoiding type confusion issues
- Secure utilisation of C++ language features
Secure Coding Tools and Techniques
- Using static analysis tools to pinpoint vulnerabilities
- Applying code review techniques for security assessment
- Implementing automated security testing approaches
- Integrating security checks into development workflows
Secure Coding Standards and Best Practices
- Reviewing industry-specific secure coding guidelines
- Applying defensive programming techniques
- Embedding security into the software development lifecycle
- Maintaining secure and reliable C/C++ applications
Practical Secure Coding Workshop
- Analysing vulnerable C/C++ code examples
- Applying security fixes and enhancements
- Testing code against common vulnerabilities
- Course review and recommendations for secure development
Requirements
Fundamentals of C/C++
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 3900 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (6)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the balance between lectures and practice, the rhythm, the trainer knowledge and pedagogic skill
Armando Pinto - EID
Course - C/C++ Secure Coding
The trainer provided up-to-date information and valuable references and tools.
Jose Vicente - EID
Course - C/C++ Secure Coding
to get a lot of good info about the course subject
Paulo Pereira - EID
Course - C/C++ Secure Coding
The coach solid knowledge and the experience, nice slides, good examples.
Celso Almeida - EID
Course - C/C++ Secure Coding
General course information