Session
Meet BOB: the supply chain provided “bill of behaviour” for anomaly-based runtime security
Currently, SBOM (“Software Bill of Materials”) includes only static build-time information. We propose to strengthen supply security by allowing vendors to also supply known benign runtime-behaviour information alongside the OCI artefacts as “Bill of Behaviour” (BoB).
BoB allows users to detect anomalies from the provided baseline at runtime and thus infer malicious behaviour or tampering using well-known cloud native tools.
We demonstrate a PoC reference implementation and discuss early user feedback and known limitations.
Vadim Bauer
Cloud Native builder in the Clouds with Kubernetes. CNCF Project Harbor maintainer.
Zürich, Switzerland
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top