Attacking through the Software Supply Chain - Felix Leder - NDC Security 2023

  Рет қаралды 785

NDC Conferences

NDC Conferences

Күн бұрын

As organizations try to increase their frontline securities, attackers are shifting to more subtle ways to break in. They exploit the dependencies and use of third-party software, which gives them more reach with less effort.
The presentation consists of two parts.
In the first part, we will present a 360-degree view of the attack surface. There will be plenty of real-world examples, including exploit details, to illustrate the different angles that attackers can exploit. Some in commercial applications, like SolarWinds or the MeDoc accounting software that led to the infamous NotPetya spread. Other examples are from open-source components, like UAParser.js or PHP. Dormant vulnerabilities like Log4j or Python’s tarfile illustrate how we can be unknowingly exposed for years. In addition to the real-world examples, we will cover categories of attacks like Dependency Confusion, Typo Squatting, and Brandjacking.
The message of the first part is that the full breadth of Supply Chain Attacks can seem overwhelming. By engaging with the audience, we will show that Supply Chain Attacks are a problem that concerns all of us.
In the second part, we present solutions. How can organizations handle the complexity and minimize the attack surface? We will discuss different frameworks and guidelines. Some of these are very hands-on while others approach the challenge from a compliance angle. Everyone from a down-in-the-dirt developer to a compliance oriented CISO will find their set of tools.
Check out our new channel:
NDC Clips:
‪@ndcclips‬
Check out more of our featured speakers and talks at
ndcconferences...
ndc-security.com/

Пікірлер: 1
@concretetoy54
@concretetoy54 Жыл бұрын
it is "Ukraine", not "the Ukraine"
"The Secure Software Supply Chain" by Kelsey Hightower (Strange Loop 2022)
49:26
Strange Loop Conference
Рет қаралды 14 М.
Players vs Corner Flags 🤯
00:28
LE FOOT EN VIDÉO
Рет қаралды 74 МЛН
escape in roblox in real life
00:13
Kan Andrey
Рет қаралды 93 МЛН
The day of the sea 😂 #shorts by Leisi Crazy
00:22
Leisi Crazy
Рет қаралды 2,3 МЛН
eBPF: Unlocking the Kernel [OFFICIAL DOCUMENTARY]
30:00
Speakeasy Productions
Рет қаралды 98 М.
Clean Architecture with NET 8
54:38
NimblePros
Рет қаралды 3,5 М.
Programming's Greatest Mistakes • Mark Rendle • GOTO 2023
51:24
GOTO Conferences
Рет қаралды 93 М.
Modernizing OpenStack with Kubernetes, Cluster API, Keycloak (..and Rust?)
35:47
The Art of Code - Dylan Beattie
1:00:49
NDC Conferences
Рет қаралды 4,7 МЛН