Loading…
Attending this event?
October 28-29, 2024 | Tokyo, Japan
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit + AI_dev Japan 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Japan Standard Time (UTC +9). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
SupplyChainSecurityCon clear filter
arrow_back View All Dates
Tuesday, October 29
 

11:10 JST

What's Happening in Japan? The Current Situation of SBOM - Ayumi Watanabe, Hitachi Solutions, Ltd.
Tuesday October 29, 2024 11:10 - 11:50 JST
This is an updated version of my previous CFP for OSS Summit EU. I will add deeper analysis of unique supply chain issues of Japan and SBOM best practice of Japanese companies. It would be a special insight of current SBOM practice of Japan. I believe this is a best topic to be discussed at OSS Summit Japan. Three years have passed since the issuance of the U.S. Executive Order (EO #14028), the adoption of SBOM in Japan has gradually progressed. Japanese companies are learning the minimum elements of SBOM which was published by NTIA, and are converting to a development process that takes automated SBOM generation into account. In July 2023, the Ministry of Economy, Trade, and Industry (METI) published a guide on the introduction of SBOM for software management, then the second version is scheduled to be released this summer. In this session, Ayumi Watanabe, a Japanese SBOM evangelist and an advisor to METI's SBOM PoC project, will discuss the status of SBOM in Japan, including the content of METI's guidelines, and the maturity and challenges of SBOM implementation in Japanese companies.
Speakers
avatar for Ayumi Watanabe

Ayumi Watanabe

SBOM Evangelist, Hitachi Solutions, Ltd.
Ayumi Watanabe is a Senior OSS Specialist of Hitachi Solutions, Ltd.. She is also a core member of OpenChain Japan and known as a SBOM evangelist appointed by the Linux Foundation Japan. Her strong point is a knowledge of many tools for SBOM generation and management, a wide range... Read More →
Tuesday October 29, 2024 11:10 - 11:50 JST
Main Hall

12:00 JST

Trials and Tribulations of Updating Dependencies for Vulnerability Remediation - Xueqin Cui & Michael Kedar, Google
Tuesday October 29, 2024 12:00 - 12:40 JST
Developers are often faced with an overwhelming number of vulnerabilities reported against their dependencies. The best way to deal with this is to keep all dependencies up to date, however, this is not possible for everyone. There is a lot of work to get all dependencies up to date for older projects, or to figure out what dependencies and versions to update in response to vulnerabilities. The open source OSV project built a feature called “guided remediation” to automatically update dependencies while minimising breakages. Upgrades with greater number of vulnerabilities fixed at once are prioritised. Mechanisms such as vulnerability dependency depth are also developed to further help prioritise the work. While developing these functionality to tackle these problems, we discovered that this is not as easy as it sounds. There are complexities in every step of the whole process - from scanning project files, to resolving dependencies in ecosystems with complicated rules, to determining possible updates, to writing back to the files. This talk explores the many challenges faced within npm and Maven, their complicated rules, and potential solutions for wider ecosystem support.
Speakers
avatar for Xueqin Cui

Xueqin Cui

Software Engineer, Google
Xueqin is a Software Engineer working on Google's Open Source Security team.
avatar for Michael Kedar

Michael Kedar

Software Engineer, Google
Michael is a Software Engineer working on Google's Open Source Security Team.
Tuesday October 29, 2024 12:00 - 12:40 JST
Main Hall

14:00 JST

Analysis of and Lessons from the Xz-Utils Vulnerability – What Might Come Next? - Taku Shimosawa & Atsuya Kato, Hitachi, Ltd.
Tuesday October 29, 2024 14:00 - 14:40 JST
The xz-utils vulnerability has attracted attentions from every person who are involved in not only open-source software but also any form of software that is built with a collaboration of developers. The vulnerability, or rather the social engineering attack has combined multiple attack techniques: maintainer takeover, obfuscated trigger code, and binary files pretending sample archives, and targeted Linux distributions, which are fundamental in the current software supply chain. In this session, Taku aggregates multiple existing analyses about the vulnerability, and explains how the attack was performed with a progress of the incident as well as technology details of the malicious source code and binary. Taku also presents a potential risk of similar incidents in open-source repositories by using some utilities including OpenSSF’s Scorecard and Criticality Score. This session would suggest what kind of attacks would come next for the software industry and would be mitigated or coped with.
Speakers
avatar for Atsuya Kato

Atsuya Kato

Researcher, Hitachi, Ltd.
avatar for Taku Shimosawa

Taku Shimosawa

Chief Researcher, Hitachi, Ltd.
Taku Shimosawa is a chief research at Hitachi, Ltd. He has contributed to the Hyperledger community, and has recently joined OpenSSF.
Tuesday October 29, 2024 14:00 - 14:40 JST
Main Hall

14:50 JST

Revolutionizing Container Security: Automated Vulnerability Patching with Copa - Anubhav Gupta, Akuity
Tuesday October 29, 2024 14:50 - 15:30 JST
Container image vulnerabilities pose significant security challenges. While tools like Grype and Trivy identify issues, efficient remediation remains a hurdle. Enter Copa, a groundbreaking CNCF project designed to automatically patch vulnerabilities within container images. Copa enables swift OS-level vulnerability remediation without upstream rebuilds, crucial for complex supply chains and third-party sources with delayed updates. It works with existing vulnerability scanners to streamline patching processes, reducing complexity and turnaround time. In this session, we’ll explore Copa’s integration with current workflows, its ability to patch images without requiring specific customizations, and support for containers without package managers, including distroless containers. Attendees will learn how Copa empowers DevSecOps teams to deploy secure containers faster and with greater confidence, minimizing exposure to potential threats. Join us to discover how Copa transforms container security, making automated patching accessible and effective for all practitioners.
Speakers
avatar for Anubhav Gupta

Anubhav Gupta

Software Engineer, Akuity
Anubhav works as a Software Engineer at Akuity. He is a graduated Summer 2023 batch LFX Mentee with the CNCF, where he worked on the Kubescape project. He is an active contributor to various CNCF projects including Kubescape and Copa. Anubhav has previously spoken at the Open Source... Read More →
Tuesday October 29, 2024 14:50 - 15:30 JST
Main Hall

15:50 JST

The Dark Side of AI: The Hidden Risks in Open-Source AI Models - Tal Folkman, Checkmarx
Tuesday October 29, 2024 15:50 - 16:30 JST
Explore the dark side of powerful AI tools and the burning question: Are they truly secure? Join me as we unravel the construction of AI models, focusing on their weak spots. Through multiple demos, witness how AI models can be manipulated to become malicious. This session offers a deep dive into a case study on the "Malicious Copilot" IDE plugin will showcase how a code-completion model can be trained to target specific victims, embedding malicious code within models, and more. Additionally, we'll tackle practical takeaways for companies utilizing generative AI and LLMs.
Speakers
avatar for Tal Folkman

Tal Folkman

Security Research Team Lead, Checkmarx
Tal Folkman is a seasoned senior malware researcher and accomplished expert in cybersecurity with over 8 years of experience in the field. Tal possesses exceptional skills in detecting and analyzing malicious code present in open-source software supply chains.In 2021, Tal joined Dustico... Read More →
Tuesday October 29, 2024 15:50 - 16:30 JST
Main Hall

16:40 JST

The Telemetry of Trust, Using Attestations to Secure Your SDLC with Open Source Tools - Jesse Sanford & Jagadish Ramidi, Autodesk
Tuesday October 29, 2024 16:40 - 17:20 JST
Let’s be honest, delivering software can be a dirty business. Especially if you are in the critical path of delivering legacy software, or software born from mergers and acquisitions. How can we secure so many differences at scale? How can we build trust into everything we do so that we can delay evaluation until we have enough trust later? In this talk, Jagadish and Jesse show you how Autodesk is thinking about solving both of these problems simultaneously. Through the use of “attestations”. Simple, cryptographically verifiable bits of telemetry that when combined, equal a whole lot more than the sum of their parts. Get enough of them and they build a story of trust. By weaving a software lifecycle tale through a series of verifiable inputs, actions and outcomes we can decide for example, when to allow a build be deployed. Or better, decide when it’s to be deployed to a secure and compliant location. Autodesk is starting to tell those software lifecycle stories using open source software weaved into our platform, making the software we build safer for all, despite our diversity.
Speakers
avatar for Jagadish Ramidi

Jagadish Ramidi

Software Engineer, Autodesk
Works as a security software engineer at Autodesk focusing on software composition analysis and supply chain security.
avatar for Jesse Sanford

Jesse Sanford

Software Architect, Autodesk
Jesse is a lifelong software engineer focused on site reliability and Infosec. Currently architecting the juncture of platform engineering and security/compliance for Autodesk's Developer Enablement team. He regularly contributes to open source and frequently speaks about his work... Read More →
Tuesday October 29, 2024 16:40 - 17:20 JST
Main Hall
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -