Loading…
October 30, 2024
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for SOSS Community Day Japan 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Japan Standard time (JST/UTC+9). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

The schedule is subject to change.
strong>Breakout Sessions [clear filter]
Wednesday, October 30
 

11:00 JST

Linux Distributor’s Role for Supply Chain Security - Muuhh Ikeda & Takanori Suzuki, Cybertrust Japan Co., Ltd.
Wednesday October 30, 2024 11:00 - 11:15 JST
Linux distributions provide users with great convenience by centralized access to multiple independent OSS into a single location. This has been an essential function that OSS can be popularized and rule the world. The nature of distributions that provide convenience to users by consolidating multiple means of access can be expected to play an important role in OSS supply chain security enhancement. For example, SBOM, provenance, and vulnerability information can be provided with trust. Currently, however, it is difficult to provide a unified means of providing these in a convenient manner while guaranteeing their authenticity and integrity. In this session, the speaker will share the current issues as a developer of multiple Linux distributions and will propose the role that distributions and distributors should play in the enhancement of supply chain security. Then he will propose necessary mechanisms to achieve it and discuss them with the attendees.
Speakers
avatar for Takanori Suzuki

Takanori Suzuki

Chief Open Source Officer, Expert Software Engineer, Cybertrust Japan Co., Ltd.
Takanori Suzuki is leading OSPO as a Chief Open Source Officer (COSO) and also a Linux OSS Developer. He also worked on LINUX distro development, PKI system, open source monitoring software, MIRACLE ZBX and had a presentation about a mruby extension for it at the Ruby World Confe... Read More →
avatar for Munehiro Ikeda

Munehiro Ikeda

Lead Architect, Cybertrust Japan Co., Ltd.
Muuhh IKEDA has been an OSS lover and believer since his first compiling by gcc in the 90s. He got involved in the Linux kernel development mainly for embedded and IoT usecases. He is working at Cybertrust Japan as a Lead Architect for IoT products and services, and a member of OSPO... Read More →
Wednesday October 30, 2024 11:00 - 11:15 JST
Main Hall

12:05 JST

Rapid Handling of Vulnerabilities in the Supply Chain with SBOM and VEX - Akihiko Takahashi, Fujitsu Limited
Wednesday October 30, 2024 12:05 - 12:15 JST
Fujitsu supports SPDX evolution and the movement to an international standard that provides a common SBOM basis for software exploitation for companies throughout the supply chain. We have long provided multilateral support for SPDX, especially thorough activities in Yocto and SPDX-Lite. From 2016, we have been joining maintainers of meta-spdxscanner, enabling SPDX functionality for the Yocto Project. Also, we are the top contributors of patch submissions to the Yocto Project. In recent years, increasing interest in cybersecurity has led to the need to quickly determine whether a product is vulnerable or not. In the supply chain, vulnerability information can be handled in combination with SBOM and VEX. An SBOM should be generated for each build, and a VEX should be generated for each vulnerability detection. It is necessary to manage them separately because their life cycles are different. In addition, there is a problem in the accuracy of the vulnerability, and there are some measures to solve it. In this presentation, we describe the advantages and challenges of creating VEX in Yocto as a use case.
Speakers
avatar for Akihiko Takahashi

Akihiko Takahashi

Fujitsu
I am an Embedded Linux Developer. I joined Fujitsu Corporation in 2013. My primary role involves developing an in-house distribution for embedded systems.I have experience in IVI (In-Vehicle Infotainment) system development, DevOps, and infrastructure environment development. Currently... Read More →
Wednesday October 30, 2024 12:05 - 12:15 JST
Main Hall

15:05 JST

Head First Reporting of Linux Kernel CVEs: Practical Use of the Kernel Fuzzer - Yunseong Kim, Ericsson LG
Wednesday October 30, 2024 15:05 - 15:25 JST
This session will delve into the practical experience of discovering and reporting Linux kernel vulnerabilities using the powerful kernel fuzzer, e.g. syzkaller. We will walk through the step-by-step process of conducting fuzzing tests, identifying potential vulnerabilities, and ultimately submitting them to the Linux kernel Security community. Beyond the technical aspects of vulnerability discovery, we'll also discuss the broader implications of this work on the open source ecosystem. By sharing insights into the benefits of using kernel fuzzers, we aim to encourage more developers to contribute to the security of Linux and other open source projects. Topics will include: Introduction to syzkaller and Real-world case studies: Practical examples of vulnerabilities discovered using syzkaller The vulnerability reporting process: practices for submitting vulnerabilities to the Linux kernel Security community with PoC
Speakers
avatar for Yunseong Kim

Yunseong Kim

Open Source Contributor, Ericsson LG
"perf In Action" on DebConf24 https://debconf24.debconf.org/talks/43-perf-in-action-real-world-applications/Finding vulnerability on IBM Z architecture memory subsystem in the Linux KernelCVE-2024-41021: https://lore.kernel.org/linux-cve-announce/2024072929-CVE-2024-41021-f857@gr... Read More →
Wednesday October 30, 2024 15:05 - 15:25 JST
Main Hall
 
  • Filter By Venue
  • Filter By Type
  • Content Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.