Loading…
Attending this event?
THE MUST ATTEND EVENT FOR CYBERSECURITY PROFESSIONALS
Room: Seacliff CD clear filter
arrow_back View All Dates
Friday, September 27
 

10:30am PDT

Automatic application hardening by leveraging container runtime behavior analysis during CI processes
Friday September 27, 2024 10:30am - 11:15am PDT
In this presentation, we will explore an innovative approach to improve the security of containerized applications using behavior analysis during continuous integration testing and generating native policies based on behavior. By leveraging behavioral analysis, we can replace tedious manual policy definitions which take long to define and can break easily. We will also discuss the importance of native policies, which allow us to enforce security policies directly within container orchestration tools like Kubernetes without relying on third-party tools.


We will focus on policies like seccomp profiles, network policies, AppArmor, and security context. We will cover hands-on practices for implementing this approach, including how to do behavioral analysis using eBPF-based tools, how to integrate this analysis into CI testing, and how to use native policies to enforce security policies.


By the end of this presentation, attendees will have a deeper understanding of how to leverage innovative approaches to security in Kubernetes clusters (and in containerized orchestration in general), and how to use behavioral analysis and native policies to protect their environments against the multiple threats.

Speakers
avatar for Amit Schendel

Amit Schendel

Sr. Security Researcher, ARMO
Passionate about security research and low-level programming with a focus on kernel drivers (Windows & Linux). Proficient in C++, Python, and Go. Excited about tackling complex challenges at the intersection of cybersecurity, system-level development and cloud technologies.
Friday September 27, 2024 10:30am - 11:15am PDT
Room: Seacliff CD

11:30am PDT

Practical Software Supply Chain Security Solutions
Friday September 27, 2024 11:30am - 12:15pm PDT
The frequency of Software Supply Chain attacks has been increasing over the last several years. This is, in part, due to the fact that the term “Software Supply Chain Attack” actually refers to a set of attacks that include: Repo Jacking, Repo Poisoning, Typo Squatting, and Dependency Confusion. Threat actors, such as Nation states, select high value targets that can be extremely disruptive. They weaponize the software supply chain against their enemies (real or perceived) to wreak physical infrastructure damage or engage in commercial and governmental espionage. Attackers who are motivated by money have been able to demand huge ransoms, which would have been impractical in the past but have been made easy by cryptocurrencies. Frequently, they seek soft targets. Hospitals, municipalities and schools can be notoriously lax in their software security efforts. Often, they lack the capital and expertise to enable a successful defense against ransomware gangs. 


Governments and the private sector are investing in defensive measures. Europe has responded with the Cyber Resilience Act. The US has mandated SBOMs as a countermeasure against supply chain attacks. If you know what is in your code then such an attack is unlikely. Right? Not exactly. In the commercial sector, a huge software security industry has arisen. In 2023 it was estimated to be valued at approximately 172 billion USD and it is a growing market. Yet this has not resulted in a diminishing threat.


In this presentation, I am going to describe practical strategies for improving your organization’s ability to defend against software supply chain attacks.

Speakers
avatar for Robert Marion

Robert Marion

Software Product Security Architect, Baxter Healthcare
Robert Marion is the Product Security Architect at Baxter Healthcare. He has a background in software engineering and has worked on robots, and machine communication. Robert designs and builds processes for making software products more secure. He is a member of the OmniBOR open source... Read More →
Friday September 27, 2024 11:30am - 12:15pm PDT
Room: Seacliff CD

1:15pm PDT

AI Under the Hood: Unmasking Hidden Threats
Friday September 27, 2024 1:15pm - 2:00pm PDT
Much like cars, AI technologies must undergo rigorous testing to ensure their safety and reliability. However, just as a 16-wheel truck’s brakes are different from that of a standard hatchback, AI models too may need distinct analyses based on their risk, size, application domain, and other factors. Prior research has attempted to do this, by identifying areas of concern for AI/ML applications and tools needed to simulate the effect of adversarial actors. However, currently, a variety of frameworks exist which poses challenges due to inconsistent terminology, focus, complexity, and interoperability issues, hindering effective threat discovery. In this talk, we discuss initial findings from our meta-analysis of 14 AI threat modeling frameworks, providing a streamlined set of questions for AI/ML threat analysis. We will also discuss how we refined this library through expert review to simplify questions and allow seamless integration to the manual analysis of AI/ML applications.
Speakers
avatar for Dr. Nitish M. Uplavikar

Dr. Nitish M. Uplavikar

Cybersecurity Researcher, Comcast
Dr. Nitish Milind Uplavikar is a cybersecurity researcher at Comcast’s Security Privacy Innovation Development Engineering and Research (SPIDER) team. As part of his daily duties, Nitish conducts research to address security and privacy-based real-world problems within threat modeling... Read More →
Friday September 27, 2024 1:15pm - 2:00pm PDT
Room: Seacliff CD

2:15pm PDT

Learning from Past Security Breaches: Strengthening AppSec Efforts and Focus
Friday September 27, 2024 2:15pm - 3:00pm PDT
In today’s rapidly evolving digital landscape, security breaches have become an inevitable reality for many organizations. This talk will provide valuable insights into the world of AppSec by examining both pre- and post-breach scenarios. We will delve into real-world examples of security incidents to identify what we wish we had done differently in terms of AppSec efforts prior to a breach.


This discussion will offer practical steps for achieving full remediation following a security incident. By understanding the importance of proactive measures and effective response strategies, attendees can learn how to bolster their AppSec practices to minimize potential damages and improve overall resilience against future attacks.

Speakers
avatar for Jon McCoy

Jon McCoy

Security Architect, DigitalBodyGuard
Friday September 27, 2024 2:15pm - 3:00pm PDT
Room: Seacliff CD

3:30pm PDT

Threat Modeling Large Scale K8s Based Platform
Friday September 27, 2024 3:30pm - 4:15pm PDT
Developers and security practitioners face challenges in securing their K8s applications. With more and larger scale applications moving to cloud-native technologies, new threat vectors are introduced that change the application's attack surface. As a result, threat modeling becomes a critical step in the software development process. A comprehensive threat model will help teams to identify, manage, and communicate potential risks of their cloud applications, regardless of exploitability.  Creating a comprehensive threat model for a large-scale k8s cluster is difficult if you want it also to be useful for developers and security practitioners.  


The talk will cover the fundamentals of threat modeling, a framework for using large-scale clusters, and the challenges of efficient threat modeling ona large-scale Kubernetes Platform. 

Speakers
avatar for Anurag Dwivedy

Anurag Dwivedy

Senior Manager, Product Security, AppDynamics - Cisco
Anurag leads the Product Security Team at AppD. With more than ten years of experience in secure software development, he is interested in web application and mobile application security. Anurag holds a Master of Science in Information Security from Northeastern University, Bosto... Read More →
BM

Brian "Mello" Kirouac

Lead Security Architect for Cisco AppDynamics, AppDynamics - Cisco
Friday September 27, 2024 3:30pm - 4:15pm PDT
Room: Seacliff CD