C/C++ Secure Coding Training

C/C++ Secure Coding Training

C/C++ Secure Coding Training

Certificate: N/A
Duration: 2 days
Course Delivery: Classroom
Accreditor: None
Language: English
Credits: N/A

Course Description:
This course explains in details the mechanisms underlying typical C/C++ security relevant programming bugs – the common security vulnerabilities. The root causes of the problems are explained through a number of easy-to-understand source code examples, which at the same time make clear how to find and correct these problems in practice. The real strength of the course lays in numerous hands-on exercises, which help the participants understand how easy it is to exploit these vulnerabilities by the attackers.
The course also gives an overview of practical protection methods that can be applied at different levels (hardware components, the operating system, programming languages, the compiler, the source code or in production) to prevent the occurrence of the various bugs, to detect them during development and before market launch, or to prevent their exploitation during system operation. Through exercises specially tailored to these mitigation techniques participants can learn how simple – and moreover cheap – it is to get rid of various security problems.

Learning Objectives:
Individuals certified at this level will have demonstrated:
● Understand basic concepts of security, IT security and secure coding
● Realize the severe consequences of non-secure buffer handling
● Understand the architectural protection techniques and their weaknesses
● Learn about typical coding mistakes and how to avoid them
● Be informed about recent vulnerabilities in various platforms, frameworks and libraries
● Get sources and further reading on secure coding practices

I liked the way the subject was explained with exercises. I liked the way all the course support material was presented to us. I also liked the course content and I think it would be helpful for my near future.
Lisbon, Portugal

Prerequisites:
None
Course Materials:
You will receive the following as part of this course:
● A participant handbook with reference materials
● Virtual machine with the exercises (to be distributed by the instructor on a USB drive)

Course Outline:
IT security and secure coding
● Nature of security
● IT security related terms
● Definition of risk
● IT security vs. secure coding
● From vulnerabilities to botnets and cyber crime
● Classification of security flaws
Security relevant C/C++ programming bugs and flaws
● Exploitable security flaws
● Protection principles
● x86 machine code, memory layout, stack operations
Buffer overflow
● Buffer overflow
● Stack overflow
● Protection against stack overflow
● Stack smashing protection
● Address Space Layout Randomization (ASLR)
● Non executable memory areas – the NX bit
● Return-to-libc attack – Circumventing the NX bit
● Return oriented programming (ROP)
● Heap overflow
Common coding errors and vulnerabilities
● Input validation
● Improper use of security features
● Improper error and exception handling
● Time and state problems
● Code quality problems
Advices and principles
● Matt Bishop’s principles of robust programming
● The security principles of Saltzer and Schroeder
Knowledge sources
● Secure coding sources – a starter kit
● Vulnerability databases

Audience:
C/C++ developers, software architects and testers

Examination:
There are no exams associated with this course

You may also like

Değer Mühendisliği Programı

DEĞER MÜHENDİSLİĞİ PROGRAMI Certified Value Engineer – CVE