Loading…
Attending this event?
October 30, 2024
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for SOSS Community Day Japan 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Japan Standard time (JST/UTC+9). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

The schedule is subject to change.
Entry Level clear filter
Wednesday, October 30
 

10:15 JST

Future Use of SCAP and SBOM for Software Supply Chain Security - Yumi Tomita & Atsuya Misaki, Cybertrust Japan Co., Ltd. & Masaki Ishiguro, Mitsubishi Research Institute, Inc.
Wednesday October 30, 2024 10:15 - 10:35 JST
In recent years, supply chain security is strongly required as a mechanism to objectively and rationally ensure security concerning organizations, systems, products, services, and data with respect to trading partners and other stakeholders. Modern software development has become more complex due to the proliferation of multiple suppliers, vendors, and open source software (OSS), and this has increased the possibility of vulnerabilities being introduced by suppliers and the risk of attacks exploiting the supply chain in the software supply chain. This is the reason why the software supply chain is becoming more and more complex. Therefore, it is important to understand and manage security risks throughout the software supply chain. The presentation will compare SCAP, which has been used for a long time, and SBOM (Software Bill of Materials), which has been attracting attention in recent years, as a method for supply chain security, explaining the features of each, and discussing the possibilities of utilizing the tools in the future.
Speakers
avatar for Masaki Ishiguro

Masaki Ishiguro

Chief Manager and Mission Leader at Cybersecurity Strategy Group, Mitsubishi Research Institute, Inc.
Masaki Ishiguro, Ph.D., is a Chief Manager and Mission Leader at Cybersecurity Strategy Group, Mitsubishi Research Institute, Inc.His areas of expertise include Cybersecurity Technologies, Government policies, Risk Management, Cybersecurity Economics, Digital Engineering.He has completed... Read More →
avatar for Atsuya Misaki

Atsuya Misaki

Product Manager, Cybertrust Japan Co., Ltd.
Atsuya Misaki is a Product Manager in Cybertrust Japan. He works in product development related to SBOM and vulnerability management
avatar for Yumi Tomita

Yumi Tomita

Marketer, Cybertrust Japan Co., Ltd.
Yumi Tomita is a Marketer in Cybertrust Japan. She works to utilize SBOM for vulnerability management. She is a member of the OpenChain Project Japan Working Group.
Wednesday October 30, 2024 10:15 - 10:35 JST
Main Hall

11:55 JST

Let’s Join CNCF TAG Security APAC! - Yoshiyuki Tabata, Hitachi, Ltd.
Wednesday October 30, 2024 11:55 - 12:00 JST
The CNCF Security Technical Advisory Group (TAG Security) is a group of cloud-native security experts and anyone interested in cloud-native security, and we can come together to work on various issues in different security areas. We do this in various ways, including through white papers we produce as resources for the community, presentations on new security projects including CNCF projects, and security assessments we provide to CNCF projects and many other initiatives. Previously, TAG Security meetings were only held in the US and EMEA time zones for a long time. This made it difficult for security friends in the APAC time zone to contribute to TAG Security, but we have now managed to hold meetings in the APAC time zone starting in August of this year! In this presentation, Yoshiyuki Tabata, facilitator for TAG Security APAC, will provide an overview of TAG Security and its latest trends. Let's make TAG Security APAC even more exciting together!
Speakers
avatar for Yoshiyuki Tabata

Yoshiyuki Tabata

Senior OSS Consultant, Hitachi
Yoshiyuki Tabata is a Senior OSS Consultant at Hitachi, Ltd, responsible for IAM and API-related solutions. As an authentication and authorization expert, he has provided numerous consultations, for example, designing and building API/SSO systems in various fields such as finance... Read More →
Wednesday October 30, 2024 11:55 - 12:00 JST
Main Hall

12:05 JST

Rapid Handling of Vulnerabilities in the Supply Chain with SBOM and VEX - Akihiko Takahashi, Fujitsu Limited
Wednesday October 30, 2024 12:05 - 12:15 JST
Fujitsu supports SPDX evolution and the movement to an international standard that provides a common SBOM basis for software exploitation for companies throughout the supply chain. We have long provided multilateral support for SPDX, especially thorough activities in Yocto and SPDX-Lite. From 2016, we have been joining maintainers of meta-spdxscanner, enabling SPDX functionality for the Yocto Project. Also, we are the top contributors of patch submissions to the Yocto Project. In recent years, increasing interest in cybersecurity has led to the need to quickly determine whether a product is vulnerable or not. In the supply chain, vulnerability information can be handled in combination with SBOM and VEX. An SBOM should be generated for each build, and a VEX should be generated for each vulnerability detection. It is necessary to manage them separately because their life cycles are different. In addition, there is a problem in the accuracy of the vulnerability, and there are some measures to solve it. In this presentation, we describe the advantages and challenges of creating VEX in Yocto as a use case.
Speakers
avatar for Akihiko Takahashi

Akihiko Takahashi

Fujitsu
I am an Embedded Linux Developer. I joined Fujitsu Corporation in 2013. My primary role involves developing an in-house distribution for embedded systems.I have experience in IVI (In-Vehicle Infotainment) system development, DevOps, and infrastructure environment development. Currently... Read More →
Wednesday October 30, 2024 12:05 - 12:15 JST
Main Hall

14:30 JST

Learnings from Teaching Students Who Are Willing to Be Cyber Security Expert. - Masato Matsuoka, Black Duck Software G.K.
Wednesday October 30, 2024 14:30 - 14:40 JST
I have been chosen a lecturer of IoT cyber security for Security Camp, and I taught them IoT system risk analysis from outside of the systems, and software levels which system internal risks identifying with SBOM. Many of them are very good cyber security learner, but there are some findings from the series of lecture. They are knowing about risks of software in general, but they have not much experiences yet then it's always discussing about basic things after all. e.g. Their knowledge and experiences are very limited then identify the risks of the OSS components by evaluating Software BOMs is quite challenging. I don't give you any guidance, ideas or so, but I will share my experiences with students.
Speakers
avatar for ANI Matsuoka

ANI Matsuoka

Sr. Technical Marketing Manager, Black Duck Software G.K.
Graduated from the Department of Electrical Engineering, Nagaoka Technical High School, Niigata Prefecture. Former software developer and cyclist including embedded. After mainly experiencing control systems and embedded software development, he was involved in embedded development... Read More →
Wednesday October 30, 2024 14:30 - 14:40 JST
Main Hall

14:45 JST

Developers Meet Security: Lessons Learnt - Marta Rybczynska, Ygreky
Wednesday October 30, 2024 14:45 - 15:00 JST
Security training for developers has become more and more popular. However, do they bring the desired effect? In this talk, Marta will summarize the experience of communicating and training developers on security topics. She will share lessons learned and suggestions on topics like addressing previous bad experiences in communication between developers and security people, the existence of silos, developers being overwhelmed by methodologies and tools, lack of time and resources for security and quality work, and more. This session will be a call for a discussion on how to better explain security to people who are not security experts and do not want to be.
Speakers
avatar for Marta Rybczynska

Marta Rybczynska

Founder, Ygreky
Marta Rybczynska has a network security background, with 20 years of experience in Open Source. She has worked with embedded operating systems like Linux and various real-time OSes, and with system libraries and frameworks up to user interfaces. She has been involved in various Open... Read More →
Wednesday October 30, 2024 14:45 - 15:00 JST
Main Hall
 
  • Filter By Venue
  • Filter By Type
  • Content Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.