Course Outline
Foundations of Secure C and C++ Development
- Core principles of secure software development
- Prevalent security risks in C and C++ applications
- The connection between coding errors and security vulnerabilities
- Industry standards and best practices for secure coding
Identifying Common C and C++ Vulnerabilities
- Recognizing coding mistakes that introduce security risks
- Addressing memory safety challenges in C and C++
- Understanding vulnerability patterns and their potential impact
- Reviewing examples of insecure code
Core Principles of Secure Programming
- Implementing defense-in-depth strategies
- Writing code that is both robust and maintainable
- Reducing the attack surface of applications
- Applying secure design principles to C and C++ projects
Input Validation and Data Management
- The critical role of input validation in security
- Preventing the exploitation of malicious input
- Techniques for effective data sanitization
- Secure methods for handling user and external data
Error Handling and Exception Management
- Security risks stemming from inadequate error handling
- Designing secure mechanisms for error and exception management
- Preventing information leakage via error messages
- Building fault-tolerant and resilient applications
Memory Safety and Buffer Overflow Mitigation
- Understanding vulnerabilities in memory management
- Stack-based buffer overflow attacks
- Heap-based buffer overflow attacks
- Methods for detecting and preventing memory corruption
- Techniques for safe memory handling
Stack Protection and Runtime Security Features
- Addressing stack overflow vulnerabilities
- Leveraging compiler-based security protections
- Using stack canaries and other protection mechanisms
- Implementing Address Space Layout Randomization (ASLR)
- Utilizing modern operating system security features
Advanced C++ Security Considerations
- Secure management of object lifecycles
- Preventing use-after-free vulnerabilities
- Safe handling of pointers and references
- Mitigating type confusion issues
- Secure utilization of advanced C++ language features
Tools and Techniques for Secure Coding
- Employing static analysis tools to uncover vulnerabilities
- Conducting security-focused code reviews
- Implementing automated security testing approaches
- Integrating security checks into the development workflow
Secure Coding Standards and Best Practices
- Reviewing industry-standard secure coding guidelines
- Applying defensive programming techniques in practice
- Embedding security throughout the software development lifecycle
- Maintaining the security and reliability of C/C++ applications
Practical Secure Coding Workshop
- Analyzing examples of vulnerable C/C++ code
- Implementing security fixes and improvements
- Testing code against known vulnerability classes
- Course summary and recommendations for secure development
Requirements
Foundational knowledge of C/C++
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 4800 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (6)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the balance between lectures and practice, the rhythm, the trainer knowledge and pedagogic skill
Armando Pinto - EID
Course - C/C++ Secure Coding
The trainer provided up-to-date information and valuable references and tools.
Jose Vicente - EID
Course - C/C++ Secure Coding
to get a lot of good info about the course subject
Paulo Pereira - EID
Course - C/C++ Secure Coding
The coach solid knowledge and the experience, nice slides, good examples.
Celso Almeida - EID
Course - C/C++ Secure Coding
General course information