Loading…
Thursday April 10, 2025 3:00pm - 3:45pm ADT
202
Modern software is complex and developers heavily rely upon third party code. Securing the software supply chain gained a lot of attention following the Solar Winds compromise. However in the years following this compromise, very little has effectively moved the needle to reduce risk related to third party code and the software supply chain.

This talk will walk through the following problems with securing the software supply chain and propose some solutions to help companies:
  1. Walk through example tech stack
  2. Break down each of the compoennts of the stack
  3. Highlight the scope of third party software and services used
  4. Discuss the academic vs reality in approching securing the supply chain
  5. Talk about how companies are approaching the problem
  6. Understanding software composition analysis and problems with these tools
  7. Vulnerability reporting is broken and the state of NVD
  8. Problems with software bill of materials (SBOMs)
  9. Walk through of ecosystems for third party code - Homebrew, Operating systems package managers, PyPI, NPM, etc
  10. Examples of attackers abusing these ecosystems to compromise organizations
  11. Walk through containers and Kubernetes
  12. Walk through AI supply chain and new Chinese AI models
  13. Examples of how security professionals are being targetted
  14. Approaches for securing the software supply chain that are working
  15. Descriptions of the challenges
  16. Open source options - OpenSSF Scorecard
  17. Startups and commercial solutions with unique solutions
  18. Options to cache or proxy third party code
  19. How ecosystem maintainers are trying to protect against attackers
  20. Options to secure the CI/CD and developer endpoints
Speakers
avatar for Jared Perry

Jared Perry

Cloud Security Practice Lead, Stratum Security
Jared Perry is the Cloud Security Practice Lead at Stratum Security where he focuses on helping improve cloud security and security programs for start-ups to Fortune 500 companies. Prior to joining Stratum Security, Jared was an IT Security Administrator at Memorial University where... Read More →
Thursday April 10, 2025 3:00pm - 3:45pm ADT
202

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link