Loading…
March 10-12, 2020
Lake Tahoe, California
View more event information

Certifying Open Source Projects & Compliance [clear filter]
Tuesday, March 10
 

11:40am PDT

Code Reuse Attacks and How to Find Them - Edward Schwartz, Carnegie Mellon University
Finding code reuse attacks is a mandatory step for exploiting software vulnerabilities in the real world. In this talk, Ed will explain the history of defenses that led to the creation of code reuse attacks, and a gentle introduction to one of the most well-known examples, Return-Oriented Programming (ROP). He will briefly introduce some of his own research, which measures how much code an attacker needs access to in order to perform such attacks. (Short answer: very little.) Finally, he will explain some of the concrete actions that developers can take to harden their software against code reuse attacks on a variety of platforms.

Tuesday March 10, 2020 11:40am - 12:10pm PDT
Grand Sierra A/B

12:20pm PDT

10 Million Packages Later: Open Source Licensing Clarity Solved at Scale - Philippe Ombredanne, Scancode Toolkit and nexB Inc.
Because open source licensing clarity should be not be an issue, ClearlyDefined is solving license clarity and compliance issues at scale and for everyone by scanning and reviewing every FOSS project licenses. 10 million package scans later, learn the license ways and issues of key FOSS package ecosystems and discover in depth the state of open source licensing clarity with ClearlyDefined open data.

What if every the licensing of every open source package were clearly defined? The mission of the ClearlyDefined project is exactly that: help free and open source software projects be more successful through clarity in licensing.

How? by massively scanning for license and origin all the packages and then reviewing these scans one by one for accuracy in the open with a community of license curators (and with a bit of machine assistance too).

Join me to survey the licensing approach of FOSS package ecosystems (both for system/Linux distro and application packages) and review in depth the state of open source licensing clarity and quality using the ClearlyDefined open data set.

Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

ScanCode maintainer, AboutCode.org and nexB Inc.
Philippe Ombredanne is a passionate FOSS hacker, lead maintainer of the ScanCode toolkit and on a mission to enable easier and safer to reuse FOSS code with best in class open source Software Composition Analysis tools for open source discovery, license & security compliance at https://aboutcode.org... Read More →


Tuesday March 10, 2020 12:20pm - 12:50pm PDT
Grand Sierra A/B

2:25pm PDT

The Common Configuration Scoring System for Kubernetes Security - Julien Sobrier, Octarine Labs Inc.
The Common Vulnerability Scoring System (CVSS) is widely used to score vulnerabilities found in docker images. But how do you score the risk level of an entire workload, with its runtime configurations, network configurations, Pod Security Policy, privileges and capabilities added, etc.?

Julien will explore the Kubernetes Common Configuration Scoring System (KCCSS), an open-source framework to calculate risk scores for Kubernetes workloads, and kube-scan, an open-source scanner that implements the KCCSS. Based on CVSS, it categorizes risks associated with each runtime setting while considering how settings affect one another, and offers a global risk score for each workload—not just for individual settings. Attendees will learn how the KCCSS works, how it’s being used by end users for DevSecOps, and best practices for bullet proofing their own K8s applications.

Speakers
avatar for Julien Sobrier

Julien Sobrier

Product Line Manager, VMWare
Julien Sobrier has spent 15+ years in the Security industry, as a Security Researcher at Netscreen/Juniper and Zscaler, then Product Manager at Zscaler, Salesforce and now Octarine (Kubernetes Security). He has co-authored Power Security Tools (O'Reilly) and released many browser... Read More →



Tuesday March 10, 2020 2:25pm - 2:55pm PDT
Grand Sierra A/B

3:05pm PDT

Leveraging Data Science to Quantify Open Source Project Health & Security - Alyssa Miller & Geva Solomonovich, Snyk
Understanding the health and security posture of open source projects can be a challenge for software development organizations. These challenges can make utilizing open source resources a high-risk proposition for enterprise environments. However, researchers are leveraging new metrics and machine learning models, to develop unique ways to quantify the health and relative security posture of open source projects.

In this discussion, we'll discuss work that is being done in both academics and private business to establish tangible measures of open source project health. We'll share some of the initial results of this ongoing research as well as lessons learned and a vision of where this research is headed.

The session will discuss how these new measures of project health can be put to practical use. Attendees will leave with a better understanding of how quantifying the trustworthiness of projects can enable developers. We'll demonstrate how this enablement can improve both development efficiency and overall security posture of applications.

Speakers
avatar for Geva Solomonovich

Geva Solomonovich

CTO, Global Alliances, Snyk
A Business-focused Technology Executive, with vast experience in Fin-tech, Payments, Fraud and Risk Management. My experience spans from Fortune 500 companies, to building startups from scratch, to being acquired by PayPal and featured as the headline story in the book "Start-Up Nation... Read More →
avatar for Alyssa Miller

Alyssa Miller

Application Security Advocate, Snyk
Alyssa Miller is a hacker, security evangelist, cybersecurity professional and public speaker with almost 15 years of experience in the security industry. A former developer, her background is application security, not only conducting technical assessments, but also helping develop... Read More →


Tuesday March 10, 2020 3:05pm - 3:35pm PDT
Grand Sierra A/B

4:05pm PDT

More than Just Licenses: Compliance and Conformance for Linux Foundation Projects - Steve Winslow, The Linux Foundation
More than Just Licenses: Compliance and Conformance for Linux Foundation Projects

In open source projects, the topic of “compliance” is often seen as primarily referring to open source license compliance. It’s understandable why this is the case, as license compliance is an extremely important issue and is relevant to all projects. But “compliance” encompasses a broader set of considerations where FOSS projects can help themselves, and their communities, by taking steps to comply with legal and regulatory obligations and to support community members’ related expectations.

In this talk, we will walk through different aspects of the compliance support activities that the LF provides to its projects. We will discuss license compliance and scanning, but will also go beyond it to discuss other compliance topics such as export controls and data privacy. We will also briefly discuss project trademarks and the related role that conformance programs can play in enabling a diverse yet interoperable ecosystem of downstream solutions.

Speakers
avatar for Steve Winslow

Steve Winslow

VP of Compliance & Legal, The Linux Foundation
Steve Winslow is Vice President of Compliance and Legal at The Linux Foundation. He runs The Linux Foundation’s license scanning and analysis support program, advising projects about licenses identified in their source code and dependencies. Steve is also involved with projects... Read More →


Tuesday March 10, 2020 4:05pm - 4:35pm PDT
Grand Sierra A/B

4:45pm PDT

SPDX and Software Bill of Materials: Past, Present, and Future - Kate Stewart, The Linux Foundation
This is the 9th year of the Software Package Data Exchange (SPDX) project and in this session Kate Stewart and William Bartholomew will provide a brief overview of the history of the SPDX project, dive into the upcoming 2,2 release of the specification, and walk through the proposed changes for the 3.0 major release.

The 3.0 release of SPDX is being built in conjunction with the Object Management Group (OMG) Software Bill of Materials working group and aims to enable SPDX to be used for more software bill of materials scenarios beyond licensing.

Speakers
avatar for Kate Stewart

Kate Stewart

Senior Director of Strategic Programs, Linux Foundation
Kate Stewart is a Senior Director of Strategic Programs, responsible for Embedded and Open Compliance programs. Since joining The Linux Foundation, she has launched Real-Time Linux, Zephyr Project, CHAOSS, and ELISA.


Tuesday March 10, 2020 4:45pm - 5:15pm PDT
Grand Sierra A/B
 
Thursday, March 12
 

9:00am PDT

OpenChain as an ISO Standard - Codifying Compliance Globally - Mark Gisi, Wind River
The OpenChain Specification is an increasingly adopted standard that outlines the key requirements of a quality open source compliance program. Available as a de-facto standard since late 2016, it is now positioned to be the first ISO standard produced via the Joint Development Foundation fast-track submission process. This talk will outline how the Linux Foundation has created a fast-track process in collaboration with Joint Development Foundation, how the OpenChain Project has engaged, and what lessons we have learned. It will also give a brief picture of what is coming next for both the OpenChain Project and broader standardization efforts in the Linux Foundation.

Speakers
avatar for Mark Gisi

Mark Gisi

Director, Open Source, Wind River
Mark Gisi, Director of Open Source Programs at Wind River Systems, is manager of the open source program office responsible for open source adoption; risk mitigation; community engagement and innovation acceleration. Mark is also a lead contributor to the Hyperledger Software Parts... Read More →


Thursday March 12, 2020 9:00am - 9:30am PDT
Grand Sierra D

9:40am PDT

Source Code to Cloud-deployment: Metadata Framework for Transparency, Compliance and Trust - Santiago Torres-Arias, New York University & Kate Stewart, The Linux Foundation
Software supply chains today are vulnerable to a wide set of compromises, mostly due to the fact that parts are opaque. We’re missing effective ways to express the elements transparently and accurately. By pulling open source software efforts together we would like to create a framework of tools and formats that can provide insight, and enable verification of the elements used to create products, from the version control systems, though to deployment on embedded devices, and into cloud images. Building on the starting points from the In-toto and SPDX ecosystems we can extend them to solve this challenge and provide a fully-transparent pipeline that covers from development and into deployment. This approach will be demo’d in the talk.

Speakers
avatar for Kate Stewart

Kate Stewart

Senior Director of Strategic Programs, Linux Foundation
Kate Stewart is a Senior Director of Strategic Programs, responsible for Embedded and Open Compliance programs. Since joining The Linux Foundation, she has launched Real-Time Linux, Zephyr Project, CHAOSS, and ELISA.
avatar for Santiago Torres

Santiago Torres

PhD Student, New York University


Thursday March 12, 2020 9:40am - 10:10am PDT
Grand Sierra D
 
Filter sessions
Apply filters to sessions.