Loading…
SOSS Fusion 2024 has ended
October 22-23, 2024 | Atlanta, Georgia USA
View More Details & Registration

The Sched app allows you to build your schedule but is separate from your event registration. You must be registered for SOSS Fusion 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Saving Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
strong>Salon 2-3 [clear filter]
Tuesday, October 22
 

11:30am EDT

CANCELED: The Power Duo: How Maintainers and Contributors Enhance Open Source - Aishat Muibudeen, AsyncAPI Initiative
Tuesday October 22, 2024 11:30am - 11:42am EDT
My presentation aims to explain the crucial roles of maintainers and contributors in securing open-source software. The primary objective is to highlight how effective collaboration between these roles ensures open-source projects' quality, usability, and sustainability. The ultimate goal is to empower newcomers and seasoned contributors to take active roles in maintaining and improving the sustainability of open-source software. Drawing from my experiences within various open-source communities, I will emphasize the profound impact of collaborative efforts on project success.
Tuesday October 22, 2024 11:30am - 11:42am EDT
Salon 2-3

11:43am EDT

Continuous Assurance of Supply Chain Security Levels of Open Source Artifacts using SLSA 0.1 - Krithika Venugopal & Raj Krishnamurthy, ComplianceCow
Tuesday October 22, 2024 11:43am - 11:55am EDT
How end users can do a reasonable verification of the SLSA provenance produced by trusted build systems to protect against threats like build from modified source, compromised build process and downloading modified packages
Speakers
avatar for Raj Krishnamurthy

Raj Krishnamurthy

Product Architect, ContiNube LLC
27+ years in software development, product engineering and product management building distributed, enterprise software at cloud scale.
avatar for Krithika Venugopal

Krithika Venugopal

Software Engineer, ComplianceCow
Software Engineer with 17 years of experience in .NET, Java, Go Python and security GRC middleware
Tuesday October 22, 2024 11:43am - 11:55am EDT
Salon 2-3
  OSS Consumption + End Users
  • Session Slides Attached yes

11:58am EDT

QEMU-Native Hooking Bridge for Binary Fuzzing - Subhojeet Mukherjee, Hitachi India Pvt. Ltd.
Tuesday October 22, 2024 11:58am - 12:10pm EDT
Fuzz testing of compiled binary code is imperative when source code is not available. AFLplusplus is a popular fuzzer, responsible for discovering several vulnerabilities in open/closed source software. While fuzzing, AFLplusplus acquires code coverage feedback by emulating the target binary in QEMU usermode, thereby supporting architecture neutral fuzzing as well. There is however no native instruction hooking and memory control support in QEMU. Albeit, having such ability can greatly benefit binary fuzz testing by patching/fixing roadblock locations that lead to long-running fuzzing campaigns. The current solution is a pythonic wrapper, UNICORN, on QEMU that is understandably slow and, more importantly, requires significant configuration to avail features that are enabled by default in AFLplusplus's raw QEMU mode. In this lightning talk, we will touch upon the QEMU native hooking bridge [https://github.com/AFLplusplus/AFLplusplus/tree/stable/qemu_mode/hooking_bridge]. We will briefly go over its design and implementation. We will then describe its usage with one or more examples. Furthermore, we will demonstrate its superiority over AFLplusplus's UNICORN mode.
Speakers
avatar for Subhojeet Mukherjee

Subhojeet Mukherjee

Researcher, Hitachi India Pvt. Ltd.
Dr. Subhojeet Mukherjee is a researcher in embedded systems security. He received his PhD from Colorado State University, researching on security aspects of in-vehicle networks in medium and heavy-duty vehicles. Currently, at Hitachi India Pvt. Ltd., he researches efficient testing... Read More →
Tuesday October 22, 2024 11:58am - 12:10pm EDT
Salon 2-3
  SW Development + OSS
  • Session Slides Attached yes

12:15pm EDT

Innovate Fast, Operate Securely: AI-Powered Protection for Containerized Workloads - Rick Bosworth, SentinelOne
Tuesday October 22, 2024 12:15pm - 12:45pm EDT
Vulnerabilities hidden within open source libs raises risk for containerized workloads. Runtime protection is needed, even for ephemeral applications, because automated attacks spread in seconds. Join SentinelOne as we demonstrate AI-powered threat protection and discuss its place in a CNAPP strategy. By combining agentless insights spanning asset discovery, CSPM, vulnerability management, and more, with the stopping power of a runtime agent, multi-cloud organizations are best equipped to accelerate and secure innovation at scale.
Speakers
avatar for Rick Bosworth

Rick Bosworth

Innovative Cloud Security Leader, SentinelOne
As a former product manager, Rick Bosworth brings an uncommon technical perspective to enterprise GTM strategy and execution. At SentinelOne, his cloud security focus spans cloud workload protection, CSPM, KSPM, and CNAPP. When he is not launching new products or working with customers... Read More →
Tuesday October 22, 2024 12:15pm - 12:45pm EDT
Salon 2-3

2:15pm EDT

Crash Course on AI Risk Management Framework - Andrew Staton, Dell Technologies
Tuesday October 22, 2024 2:15pm - 2:45pm EDT
Over the past year, AI has been talk of the town in terms of emerging technology. There is a lot of discussion around how AI technology and capabilities will be utilized both for the betterment and the detriment of our world and those around us. One of the first attempts to manage these risks from a regulatory perspective is the AI Risk Management Framework from NIST. This session will be a crash course on that standard and some preliminary analysis/dialogue around how effective the standard will be.
Speakers
avatar for Andrew Staton

Andrew Staton

Cyber Security Advisor, Dell Technologies
Andrew Staton works as a Cybersecurity Advisor at Dell Technologies. His background entails working with and for companies of all shapes and sizes to implement and stand up a Secure CyberSecurity program and enhance their existing practices. He is active within the North Alabama Chapter... Read More →
Tuesday October 22, 2024 2:15pm - 2:45pm EDT
Salon 2-3
  Public Policy
  • Session Slides Attached yes

2:50pm EDT

Save the Elephants - Secure Your PostgreSQL Databases with TDE - Lori Lorusso, Percona
Tuesday October 22, 2024 2:50pm - 3:20pm EDT
Slonik, is PostgreSQL’s mascot. Sadly elephants are an endangered species due to poaching and threats to their natural habitat but thankfully conservationists have stepped in to provide safety and security so the species can survive. While this may seem like a stretch, using an open source database like PostgreSQL, the most popular open source database in the world, is also in need of protection from bad and malicious actors, the poachers of data! Join me as we safari into PostgreSQL Database land and discuss the history of database attacks and how Percona is acting as a conservationist creating TDE to give your data one more level of protection.
Speakers
avatar for Lori Lorusso

Lori Lorusso

Head of Community, Percona
Lori has a passion and enthusiasm for working with the developer and open source community. She is a CNCF Ambassador, former CNCF Marketing Committee Chair, former Chair of the CDF Outreach Marketing Committee, program chair of cdCon 2023, and is active in the OpenSSF devrel committee... Read More →
Tuesday October 22, 2024 2:50pm - 3:20pm EDT
Salon 2-3

3:25pm EDT

Living with and Leveraging GCC - James Lowden & Bob Dubner, Symas Corporation
Tuesday October 22, 2024 3:25pm - 3:55pm EDT
The GCC steering committee has accepted our project to add COBOL to GCC. This is our story of learning how to interact with a hoary, established project and (we hope) make a significant contribution.
Speakers
avatar for James Lowden

James Lowden

Senior Architect, Cobolworx
James spent the first 30 years of his career on Wall Street in application programming, database design, and quantitative research. Now he's in pure technology, building compilers and systems for other programmers. After decades in Manhattan, his work life is now fully virtual, and... Read More →
Tuesday October 22, 2024 3:25pm - 3:55pm EDT
Salon 2-3
  Maintainer / Contributor
  • Session Slides Attached yes

4:25pm EDT

Validating Validations - Who's Watching the Watcher? - Megan Wolf, Defense Unicorns
Tuesday October 22, 2024 4:25pm - 4:55pm EDT
This session will focus on the validation of kubernetes webhook controllers. Currently, testing of these types of controllers is largely the onus of the developers. While the standard unit and end-to-end tests may be sufficient for rolling out a product, the other half of the responsibility lays on the user to independently validate these controllers in their environment. The intent is to lay out a framework that supports how end-users may interrogate these controllers to validate their behaviors, particularly with respect to how that behavior satisfies various controls, e.g., regulated standards or best practices. Our framework looks at using an open source tool, Lula, to add cluster resources, measure the response of the controller, and output a validation of the controller's behavior. The result is a repeatable and scalable evaluation of webhook controllers. This evaluation becomes more critical as environments scale and more complex admission/mutation is introduced. These controllers are often performing critical security functions in the environment and should be continually monitored and evaluated for their efficacy, particularly as the system they exist in evolves.
Speakers
avatar for Megan Wolf

Megan Wolf

Software Engineer, Defense Unicorns
Megan is a software engineer at Defense Unicorns, focused on helping solve software challenges for the DoD. Her primary role is a developer on the Lula open source tool which enables faster and more robust evaluation of system compliance to various controls and standards.
Tuesday October 22, 2024 4:25pm - 4:55pm EDT
Salon 2-3
  SW Development + OSS
  • Session Slides Attached yes

5:00pm EDT

Secure AI Orchestration: Mitigate Model-centric Attacks with Flyte - Niels Bantilan, Union.ai
Tuesday October 22, 2024 5:00pm - 5:30pm EDT
In recent years, major progress in machine learning (ML) has led to a corresponding boom in the broader artificial intelligence (AI) space, opening up commercial applications in text, image, audio, and video generation. However, data scientists and ML engineers still face many security issues that may lead to arbitrary code execution even in the space of "classical" ML, which often involves classification or regression on tabular data.

This talk will outline some of the model-centric attacks that you should be aware of and hone in on two types of attacks: malicious code injection on pickled model files, and malicious code written and executed by an LLM. We'll create a basic setup for these two attacks and see how Flyte, an open source ML orchestrator, can help mitigate some of the risks associated with these two attacks.

Finally, we'll analyze the limitations of the solutions provided by Flyte, abstract some of the ideas out in an orchestrator-agnostic way, and cover other open source tools, like `safetensors` and `onnx`, which we can leverage on top of Flyte to reduce these risks even further.
Speakers
avatar for Niels Bantilan

Niels Bantilan

Chief Machine Learning Engineer, union.ai
Niels is the Chief Machine Learning Engineer at Union.ai, and core maintainer of Flyte, an open source workflow orchestration tool, author of UnionML, an MLOps framework for machine learning microservices, and creator of Pandera, a statistical typing and data testing tool for scientific... Read More →
Tuesday October 22, 2024 5:00pm - 5:30pm EDT
Salon 2-3
  AI + Security
  • Session Slides Attached yes
 
Wednesday, October 23
 

10:55am EDT

Assessing Open Source Software Projects in the Software Supply Chain - Scott Hissam, Carnegie Mellon Software Engineering Institute & Joshua "CoCo" Crisp, Unified Platform (USCYBERCOM)
Wednesday October 23, 2024 10:55am - 11:25am EDT
The US Department of Defense, like many industrial, academic, and government institutions across the world, are intricately dependent on open source software and seek concrete means to objectively assess the trustworthiness of not only the products of the OSS ecosystem but also the processes enacted by projects to produce that software. One such DoD project, Unified Platform, is developing techniques to evaluate publicly available information from OSS projects to determine the risk levels associated with using the open source software, both now and in the future. Current efforts are concentrating on evaluating a project’s processes, policies, and practices. This includes leveraging tools such as MITRE’s Hipcheck, the Open Source Security Foundation’s Scorecard, and other sources to support Unified Platform's Software Approval Process and Software Supply Chain Practices. This presentation will cover how these techniques are providing the insight needed by this DoD project to address emerging DoD guidance in the use of open source software.
Speakers
avatar for Joshua Crisp

Joshua Crisp

Chief Information Security Officer, Unified Platform (USCYBERCOM)
Unified Platform Chief Information Security Officer supporting USCYBERCOM and JCWA. I've spent a little over 5 years supporting Unified Platform capabilities for cybersecurity, cloud infrastructure, cybersecurity for Air Force's Platform One program (IronBank, BigBang, PartyBus... Read More →
avatar for Scott Hissam

Scott Hissam

Senior Member of the Technical Staff, Software Engineering Institute | Carnegie Mellon University
Based in San Antonio, TX where I manage and coordinate local staff and technical activities in support of and DoD organizations. I am also a technical lead/program manager, leading research to practice in software engineer and software technology for acquisition and sustainment of... Read More →
Wednesday October 23, 2024 10:55am - 11:25am EDT
Salon 2-3
  OSS Consumption + End Users
  • Session Slides Attached yes

11:30am EDT

ClearlyDefined: A Crowdsourced Database of Licensing Metadata - Nick Vidal, Open Source Initiative; Lynette Rayle, GitHub & Qing Tomlilnson, SAP
Wednesday October 23, 2024 11:30am - 12:00pm EDT
ClearlyDefined is a free service and open source project from the Open Source Initiative (OSI) that helps organizations ensure supply chain compliance and security. Generating SBOMs at scale for each stage on the supply chain, for every build or release, has proven to be a real challenge. And fixing the same missing or wrongly identified licensing metadata over and over again has been a redundant pain for everyone. This is where ClearlyDefined shines, as it makes it really easy for organizations to fetch a cached copy of licensing metadata for each component through a simple API and fix any issues, which is always up-to-date thanks to its crowdsourced database. In this session, we'll provide an introduction to ClearlyDefined and discuss the latest developments. We'll provide case studies of how organizations like GitHub, SAP, Microsoft, and Bloomberg are leveraging ClearlyDefined not only for their own needs internally, but for the benefit of all.
Speakers
avatar for Qing Tomlinson

Qing Tomlinson

Senior Software Developer, SAP Canada
Qing Tomlinson, a Senior Software Developer at SAP, has been actively involved in the ClearlyDefined Project since 2022, and currently holds a position on the Technical Steering Committee for the project.
avatar for Lynette Rayle

Lynette Rayle

Senior Software Engineer, GitHub
Lynette Rayle is a Senior Software Engineer at GitHub working on license compliance solutions.  She is the technical lead for internal work to accurately identify licenses and attributions for dependencies and has worked on all systems related to the license compliance process.  She... Read More →
avatar for Nick Vidal

Nick Vidal

Community Manager, Open Source Initiative
Nick Vidal is Community Manager at the Open Source Inititiave and Outreach Chair at the Confidential Computing Consortium from the Linux Foundation. Previously, he was the Director of Community and Business Development at the Open Source Initiative and Director of Americas at the... Read More →
Wednesday October 23, 2024 11:30am - 12:00pm EDT
Salon 2-3

12:05pm EDT

Project Copacetic: Directly Patch Container Image Vulnerabilities - Ashna Mehrotra, Microsoft
Wednesday October 23, 2024 12:05pm - 12:35pm EDT
Software supply chain security is more important than ever. Yet maintaining secure container images is challenging, because patch options can be limited: wait impatiently for third-party image updates to be released, especially for images with multi-publisher dependencies, or perform your own full image rebuild, a time and resource-intensive process. Project Copacetic (Copa) reduces turnaround time and complexity for image patching. Copa integrates into existing build infrastructure, giving users greater control over their patching timeline while reducing costs. Using image scanners like Trivy, Copa generates a vulnerability report and identifies necessary OS-level package updates. Copa then updates your target image using Buildkit (Docker’s default builder) by creating a new patch layer on the original image. Copa can even patch distroless images. We’ll demo Copa, including how to integrate it into pipelines, extend its functionality with scanner formats, and exclude scanners to update all outdated packages. You’ll leave ready to keep your images secure. As a newly accepted CNCF sandbox project, Copa invites you to join the community and advance your software security!
Speakers
avatar for Ashna Mehrotra

Ashna Mehrotra

Software Engineer, Microsoft
Ashna Mehrotra is a software engineer on the Upstream Security team, working on cloud-native open source security projects at Microsoft.
Wednesday October 23, 2024 12:05pm - 12:35pm EDT
Salon 2-3
  OSS Consumption + End Users
  • Session Slides Attached yes

2:05pm EDT

Why Is My Software on Fire? - Laurent Goderre, Docker
Wednesday October 23, 2024 2:05pm - 2:20pm EDT
Product recalls and Supply Chain Management have been used for decades with great success to help identify the source of unexpected hazards in products (from exploding batteries to spider attracting fuel lines) and protect consumers from these hazards. While developing software can be considerably different than developing and manufacturing physical products, there are lessons to be learned about the importance of properly identifying all the components that are included in a product. In this session, we will cover the importance of versioning both as a consumer and a producer of open source software and its impact on security.
Speakers
avatar for Laurent Goderre

Laurent Goderre

Software Engineer, Docker
Laurent is a software engineer with over 20 years of experience in software development in the private and public sectors with extensive experience contributing to open source software. Since 2016, he has built and maintained Docker Official Images before joining Docker in 2023 to... Read More →
Wednesday October 23, 2024 2:05pm - 2:20pm EDT
Salon 2-3

2:20pm EDT

How to Use CNCF’s Falco to Protect Yourself from the New SCARLETEEL Attack! - Parthi Srinivasan, Sysdig
Wednesday October 23, 2024 2:20pm - 2:35pm EDT
Recently found SCARLETEEL, a new attack pattern starts from a compromised Kubernetes container and spreads to the victim’s AWS account. Let us see how OSS Falco and new plug-in approach can detect this kind of threat in cloud runtime!
Speakers
avatar for Parthiban Srinivasan

Parthiban Srinivasan

Senior customer success solution architect, Sysdig
I specialize in runtime threat detection, delivering impactful strategies and solutions that fortify Fortune 500 companies against evolving security challenges
Wednesday October 23, 2024 2:20pm - 2:35pm EDT
Salon 2-3
  OSS Consumption + End Users
  • Session Slides Attached yes

2:40pm EDT

The Simple, Yet Lethal, Anatomy of a Software Supply Chain Attack - Erez Yalon, Checkmarx
Wednesday October 23, 2024 2:40pm - 3:10pm EDT
While commercial supply chain attacks are becoming more manageable, security teams have a much harder time with open-source software supply chains. This session will provide an attacker's perspective of open-source flows and flaws and dive into several unique supply chain weaknesses. Demos will show the ease of conducting different attacks and provide a perspective on defeating them as defenders.
Speakers
avatar for Erez Yalon

Erez Yalon

VP of Security Research, Checkmarx
Erez Yalon is the VP of Security Research at Checkmarx, the Founder of the DEF CON's AppSec Village, and the founder and co-leader of the OWASP API Security Project. Over the years, Erez has been invited to speak at prominent events, including RSAC, Black Hat, DEF CON, and OWASP’s... Read More →
Wednesday October 23, 2024 2:40pm - 3:10pm EDT
Salon 2-3

3:40pm EDT

The Simple, Yet Lethal, Anatomy of an AI Attack - Erez Yalon, Chechmarx
Wednesday October 23, 2024 3:40pm - 4:10pm EDT
It surprises no one that attack surfaces expand as swiftly as AI and ML technologies advance, yet the security landscape lags behind. Join us for an eye-opening session where we dive deep into the dark world of AI security through the lens of attackers.

We'll tread carefully between different attacks, accompanied by demos, revealing the strategies and techniques used to compromise AI and LLMs. From reconnaissance and spoofing via supply chain attacks all the way to LLM poisoning, jailbreaking, and compromise—AI attacks are far from just prompt injection. Witness firsthand how attackers exploit vulnerabilities, manipulate AI systems, and leverage AI for malicious purposes.

You will gain a fundamental understanding of AI security and the nature of AI attacks, offering a rare glimpse into the adversarial mindset. By understanding the attacker’s perspective, you will be better prepared for a new era where threats are evolving and attackers are feeling increasingly comfortable in the AI domain.
Speakers
avatar for Erez Yalon

Erez Yalon

VP of Security Research, Checkmarx
Erez Yalon is the VP of Security Research at Checkmarx, the Founder of the DEF CON's AppSec Village, and the founder and co-leader of the OWASP API Security Project. Over the years, Erez has been invited to speak at prominent events, including RSAC, Black Hat, DEF CON, and OWASP’s... Read More →
Wednesday October 23, 2024 3:40pm - 4:10pm EDT
Salon 2-3
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Session Slides Attached
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.