Loading…
SOSS Fusion 2024 has ended
October 22-23, 2024 | Atlanta, Georgia USA
View More Details & Registration

The Sched app allows you to build your schedule but is separate from your event registration. You must be registered for SOSS Fusion 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Saving Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
strong>Security Education [clear filter]
Tuesday, October 22
 

11:30am EDT

Building Developer Confidence in Software Security with the DevRel Community - Katherine Druckman, Intel Corporation; Lori Lorusso, Percona; Tabatha DiDomenico, G-Research
Tuesday October 22, 2024 11:30am - 12:10pm EDT
Software is a complex system of tooling, processes, and, ultimately, humans. Ensuring the system's integrity and hardening our software supply chain requires careful configuration at countless steps along the pipeline. The OpenSSF is leading the open source security community to establish tools and best practices. Still, their discovery can be overwhelming and confusing to the developers and open source maintainers who stand to benefit. Join this panel of OpenSSF DevRel Community Volunteers to learn how to navigate the complex waters of the OpenSSF landscape as we work to connect projects and tools with the community. Walk away with a clearer understanding of developer relations and how to get involved.
Speakers
avatar for Tabatha DiDomenico

Tabatha DiDomenico

Open Source DevRel Engineer, G-Research
Tabatha is an OSS DevRel Engineer at G-Research bringing over two decades of experience in community development, IT, and cybersecurity to the role. She holds an MS in Cybersecurity from the University of South Florida and a BA in Interdisciplinary Studies from the University of Central... Read More →
avatar for Katherine Druckman

Katherine Druckman

Open Source Evangelist, Intel
Katherine Druckman is an Open Source Evangelist at Intel where she enjoys sharing her passion for a variety of open source topics. She is a long-time open source advocate, developer, and podcaster, and is currently the host of Open at Intel and co-host of the FLOSS Weekly and Reality... Read More →
avatar for Lori Lorusso

Lori Lorusso

Head of Community, Percona
Lori has a passion and enthusiasm for working with the developer and open source community. She is a CNCF Ambassador, former CNCF Marketing Committee Chair, former Chair of the CDF Outreach Marketing Committee, program chair of cdCon 2023, and is active in the OpenSSF devrel committee... Read More →
Tuesday October 22, 2024 11:30am - 12:10pm EDT
Salon 4-6

12:15pm EDT

Innovate Fast, Operate Securely: AI-Powered Protection for Containerized Workloads - Rick Bosworth, SentinelOne
Tuesday October 22, 2024 12:15pm - 12:45pm EDT
Vulnerabilities hidden within open source libs raises risk for containerized workloads. Runtime protection is needed, even for ephemeral applications, because automated attacks spread in seconds. Join SentinelOne as we demonstrate AI-powered threat protection and discuss its place in a CNAPP strategy. By combining agentless insights spanning asset discovery, CSPM, vulnerability management, and more, with the stopping power of a runtime agent, multi-cloud organizations are best equipped to accelerate and secure innovation at scale.
Speakers
avatar for Rick Bosworth

Rick Bosworth

Innovative Cloud Security Leader, SentinelOne
As a former product manager, Rick Bosworth brings an uncommon technical perspective to enterprise GTM strategy and execution. At SentinelOne, his cloud security focus spans cloud workload protection, CSPM, KSPM, and CNAPP. When he is not launching new products or working with customers... Read More →
Tuesday October 22, 2024 12:15pm - 12:45pm EDT
Salon 2-3

2:15pm EDT

Open & Secure: Novel Sandboxing Technique for Any Open Source Library - Gal Elbaz, Oligo Security
Tuesday October 22, 2024 2:15pm - 2:45pm EDT
Security teams from Google to Firefox have taught the security industry a lot about isolating running programs from the broader system through sandboxing, which fundamentally changed the way hackers need to operate to inflict damage on systems. Threat actors today need to be significantly more sophisticated and build a chain of vulnerabilities to escape sandboxes & access critical system resources for exploitation. The consistently growing number of vulnerabilities in OSS packages, imposes an impossible pace of remediation & patching to stay ahead of zero-day threats evolving daily. Enter Open Source Sandboxing. In this talk we’ll present a first of its kind approach, built upon the powerful eBPF and KRSI technologies, that enables you to derive the very same security benefits of browser and web-based, as well as mobile - iOS & Android sandboxing - for any open source library you are running in your stacks. We’ll walk through a code example for how to identify and block exploits.
Speakers
avatar for Gal Elbaz

Gal Elbaz

CTO & Co-Founder, Oligo Security
Co-founder & CTO at Oligo Security with 10+ years of experience in vulnerability research and practical hacking. He previously worked as a Security Researcher at CheckPoint and served in the IDF Intelligence. In his free time, he enjoys playing CTFs.
Tuesday October 22, 2024 2:15pm - 2:45pm EDT
Salon 4-6
  Security Education
  • Session Slides Attached yes

2:50pm EDT

What Is Going On In Your Source Code? Understanding SCA In Plain Language - Dwayne McDaniel, GitGuardian
Tuesday October 22, 2024 2:50pm - 3:20pm EDT
Over the last few years, terms like SBOM, VEX, SLSA, and GUAC have crept into our supply chain security discussions. While we all agree from the surface that knowing what is in our code is likely a good idea, for a lot of teams, this feels like another set of boxes to check when filing security compliance paperwork. But what is really going on here, and what is driving us into this acronym soup?

In this session, we will explore multiple terms and the deeper questions of what they are trying to answer. You will walk away with a more holistic understanding of where we need to go as an industry to protect ourselves from the current and future waves of threats on the horizon. Before you throw another security tool at the problem or throw your hand up in despair, let's explore why better understanding these ideas means being able to better protect your organization.
Speakers
avatar for Dwayne McDaniel

Dwayne McDaniel

Senior Developer Advocate, GitGuardian
Dwayne has been working as a Developer Relations professional since 2015 and has been involved in tech communities since 2005. He loves sharing his knowledge, and he has done so by giving talks at over a hundred events worldwide. Dwayne currently lives in Chicago. Outside of tech... Read More →
Tuesday October 22, 2024 2:50pm - 3:20pm EDT
Salon 1
  Security Education
  • Session Slides Attached yes

4:40pm EDT

The Power of Confidential Computing: Exploring Open Source Projects - Sal Kimmich, Confidential Computing Consortium, Linux Foundation
Tuesday October 22, 2024 4:40pm - 4:55pm EDT
Explore how confidential computing is revolutionizing data security through Open Source projects within the Confidential Computing Consortium (CCC) at the Linux Foundation. This session will delve into the value that confidential computing brings to businesses by ensuring data protection even during processing. Highlighting key projects like COCONUT-SVM, Occlum, Islet, and others, we will showcase how these Open Source initiatives enhance privacy and security. Learn how integrating these projects can mitigate risks, improve compliance, and foster innovation. This talk is designed for decision-makers in compute security and compliance, particularly those interested in secure federated compute. We will cover real-world examples from finance to human trafficking to demonstrate the power and versatility of Confidential Computing. Join us to understand the future of secure data processing and the pivotal role of Confidential Computing in advancing Open Source solutions.
Speakers
avatar for Sal Kimmich

Sal Kimmich

Technical Community Architect, Confidential Computing Consortium, Linux Foundation
Sal is an advocate for open source, passionate about helping engineers, ethical hackers, and digital enthusiasts navigate modern software development. With over a decade of experience building cloud-native machine learning pipelines in healthcare and tech for good sectors, Sal now... Read More →
Tuesday October 22, 2024 4:40pm - 4:55pm EDT
Salon 4-6
 
Wednesday, October 23
 

3:40pm EDT

Navigating the Quantum Readiness Journey: Hands-on Guidance for Starting Your Migration - Eric Mizell, Keyfactor
Wednesday October 23, 2024 3:40pm - 4:10pm EDT
Cryptography is a fundamental cornerstone of cybersecurity, omnipresent for every engineer. As quantum computing advances rapidly and NIST standardizes new algorithms, the urgency of preparing for its impact on cybersecurity grows. Join our educational journey into Crypto Agility and Quantum Readiness. This presentation empowers engineers and security experts with tools to understand and navigate quantum-resistant cryptography, and conduct hands-on experiments tailored to your use cases. Our talk addresses: "What is the quantum computing threat, and what can I do about it?" We will explore the landscape of quantum-ready security and different migration scenarios, emphasizing the need for crypto agility. This includes reassessing and updating standard protocols and security mechanisms such as mTLS and x.509 certificates. We will provide an overview of current standardization efforts, including European and American initiatives. Emphasizing the importance of community collaboration, we aim to achieve high-quality, interoperable cryptographic implementations.
Speakers
avatar for Eric Mizell

Eric Mizell

Field CTO, Keyfactor
Eric Mizell is a developer turned security expert. Beginning his career in engineering and leadership roles at Hortonworks and OverOps, Eric then shifted his focus to security, having seen first-hand the security gaps in many DevOps environments. As Field CTO at Keyfactor, Eric works... Read More →
Wednesday October 23, 2024 3:40pm - 4:10pm EDT
Salon 1
  Security Education
  • Session Slides Attached yes
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Session Slides Attached
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.