Feeds

Leeds Uni, MS teach undergrads to write secure code

Course work

  • alert
  • submit to reddit

Secure remote control for conventional and virtual desktops

Microsoft has teamed up with the University of Leeds to develop the UK's first undergraduate computer security module to focus on the skills which developers need write secure code.

The course kicks off in January 2004. Students will get hands-on experience of writing secure code and will learn to appreciate the fundamental role of security in software engineering. In addition to standard security topics, the module will cover threat modelling and basic security analysis of code, teaching students to identify potential weaknesses within their programs that could be exploited by unscrupulous crackers or virus writers.

Microsoft UK Chief Security Officer Stuart Okin said: "We are working with the University of Leeds because until now Computer Science graduates in this country were not obtaining adequate theoretical or practical experience. For instance, the module will educate students about buffer over-runs and how to avoid the pitfalls such as those exposed in the recent Slammer virus outbreak."

Professor Tony Cohn, Head of the School of Computing at the University of Leeds said he hoped the module help students to write better code while helping to give them an edge in the employment market on graduation.

John Harrison, an executive committee member of SAINT (Security Alliance for the Internet and New Technologies), has been working closely with the University of Leeds to promote information security within the curriculum.

"This is a very important step towards introducing security engineering into mainstream computer science and software engineering," said Harrison. "It is a serious omission that we have been training the next generation of software developers without this emphasis on security design principles and I hope other universities will follow this lead."
Microsoft is partly funding a Fellowship at the University. It is also working with the University of Leeds to develop the curriculum's content, which will "highlight the lessons learned from Microsoft's Trustworthy Computing initiative".

The company hopes to team up with other colleges and universities to offer similar courses worldwide.

Microsoft's recently announced a deal with Hull University to develop the UK's first postgraduate course in .NET. ®

Related Stories

Win a computer science bursary at Queen Mary
Cost of securing Windows Server 2003? Nearly $200m
Trustworthy Computing does Moon Walk (but not yet)
Microsoft outlines 3D progress to Trustworthiness
Open and closed security are roughly equivalent

Secure remote control for conventional and virtual desktops

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.