Skip to main content
  • Create account
  • Log in
EclipseCon - Eclipse Foundation
Register Now
  • Conference
    • Program Schedule
    • Program List
    • Keynotes
    • Registration
  • Community Activities
    • Community Day Overview
    • Automotive & SDV Community Day
    • Community Day for Java Developers
    • OSGi Summit
    • eSAAM 2023 on Cloud-to-Edge Continuum
    • Call for BoFs
    • Dinner Meetups
    • EMO Office Hours
  • Sponsors
    • Be a Sponsor
    • Information for Exhibitors
    • Our Sponsors
    • Sponsor Testimonials
  • Resources
    • Code of Conduct
    • Meet the Speakers
    • Information for Speakers
    • Information for Tutorial Presenters
    • Press
    • Share Your Participation
    • Convince Your Manager
    • Onsite Information for Attendees
  • About Us
    • EclipseCon 2023
    • Program Committee
    • The Eclipse Foundation
    • Past Conferences
  • Venue
    • Conference Venues
    • Hotels
    • Ludwigsburg
  1. Home
  2. EclipseCon
  3. EclipseCon 2023
  4. Sessions
  5. Choosing Wisely: a look at new ways to evaluate open source for the supply chain

Choosing Wisely: a look at new ways to evaluate open source for the supply chain

Session details
Status: 
Backup
Speaker(s): 
Steve Poole (Employed)
Experience level: 
Beginner
Tags: 
cncf
Linux
Session Track: 
Open Source Best Practices
Session Type: 
Standard

This session assumes no prior knowledge though some basic technical background would help.

The level of cyber-attacks across the world has reached pandemic status. Governments are creating legislation in an attempt to limit the damage by placing responsibility on software suppliers for the security posture of their products and services.

Regardless of this effort, the cost of remediation in patching a vulnerability, is expensive. Cybercriminals are attacking open-source projects directly, so the sheer number of vulnerabilities is rising enormously, making reactive patching even more challenging and  costly.

In this session, we'll look at what is happening to move to a more proactive stance.  Can we figure out how to predict vulnerabilities?  Can we find ways to root out compromised projects?   Can we create ways for developers to make better choices at the beginning and reduce the load on the business in patching?

The answer is a qualified yes - it's early days but there are heuristics emerging and hard data too to show that we can make a difference.

This talk will give you an introduction to the thinking happening across the industry and show how you can benefit already from this work.

 

 

 

 

Objective of the presentation: 
The level of cyber-attacks has reached the point where being reactive is becoming too costly and ineffectual. Running fire drills every time a zero-day vulnerability appears is not tenable, so we need new ways to reduce the load. This session looks at Industry efforts to shift left elements of this load by providing developers with better data (and education) when choosing open-source components 90% of modern applications are open-source components, almost exclusively selected for their features. There is sufficient evidence to show that it is possible to predict the likelihood of a component having a future vulnerability based on a set of behavioural indicators. The industry is working out how to formalise these indicators into scores and heuristics that could reduce the load simply by allowing developers to knowing pick components with a lower likelihood of having vulnerabilities. By teaching developers how to assess and select components for their security posture and capabilities, it's hoped that the remediation load will reduce and developers will begin to assess their code similarly.
Attendee pre-requisites - If none, enter "N/A": 
N/A
  • Sign in to post comments.

Elite

  • Huawei
  • ZettaScale Technologies

Premium

  • Eurotech
  • Yatta Solutions GmbH
  • Gradle

Basic

  • EclipseSource
  • Equo Tech, Inc.
  • MicroStream Software GmbH
  • SOTEC GmbH & Co KG
  • Obeo
  • CEA List
  • SCANOSS
  • ETAS GmbH
  • TypeFox GmbH
  • Mercedes-Benz Tech Innovation GmbH

Supporter

  • Open Elements

Media

  • GermanTechJobs
  •  IT-Schulungen.com

Become a Sponsor

Eclipse Foundation

  • About Us
  • Contact Us
  • Sponsor
  • Members
  • Governance
  • Code of Conduct
  • Logo and Artwork
  • Board of Directors
  • Careers

Legal

  • Privacy Policy
  • Terms of Use
  • Copyright Agent
  • Eclipse Public License
  • Legal Resources

Useful Links

  • Report a Bug
  • Documentation
  • How to Contribute
  • Mailing Lists
  • Forums
  • Marketplace
EclipseCon is brought to you by The Eclipse Foundation with the support of our sponsors.
Powered by Drupal and built on COD.

Copyright © Eclipse Foundation. All Rights Reserved.

Back to the top