Untrusted Execution: Attacking the Cloud Native Supply Chain

QCon San Francisco 2022

Session

Untrusted Execution: Attacking the Cloud Native Supply Chain

Tuesday Oct 25 / 04:10PM PDT, Pacific DEKJ

Abstract

Should we trust the code we run in production? Not if a motivated attacker can compromise our system’s complex supply chains. While hardened runtimes and detection can mitigate some zero day attacks, malicious internal threat actors and software implants are much harder to detect. Supply chain security looks to address some of these concerns, but with so many signing options available to us, what do we really care about? Our source code, open source dependencies, CI/CD, built containers, vendor software — or the hardware and operating systems we run on? Securing the whole supply chain is a non-trivial task, and requires consideration at all of these levels.In this talk we:

  • Undertake a risk-based threat model of supply chain attacks against our systems
  • Compare the open source supply chain security controls available to us
  • Examine trusted execution environments and their security properties
  • Propose an open source solution for end to end supply chain security
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon San Francisco 2022 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 25 October

10:35 Seacliff D Session Unconference: Microservices Shane Hastie Global Delivery Lead for SoftEd and Lead Editor for Culture & Methods at InfoQ.com 11:50 Ballroom A Session Microservices Dark Energy, Dark Matter and the Microservices Patterns?! Chris Richardson Creator of microservices.io, Java Champion, & Core Microservices Thoughtleader 13:40 Ballroom A Session Microservices Orchestration vs Choreography, A Guide To Composing Your Monolith Ian Thomas Software Engineer @Meta, QCon London 2024 PC Chair, Previously Technology Leader @Genesis Global 14:55 Seacliff ABC Session Microservices [Recording] Overcomplicated Architecture: Scaling Bottleneck Cassandra Shum Technologist | Architect | Ex-Thoughtworks 16:10 Pacific DEKJ Session Untrusted Execution: Attacking the Cloud Native Supply Chain Francesco Beltramini Security Engineering Manager @controlplaneio 17:25 Ballroom A Session Panel: Building Performant Microservice Architectures Chris Richardson, Ian Thomas, Todd Montgomery