
2020-028-Shlomi Oberman, RIPPLE20, supply chain security discussion, software bill of materials
Mrs_Marong💞
Description
<p>Whitepaper: <a href= "https://www.jsof-tech.com/ripple20/">https://www.jsof-tech.com/ripple20/</a></p> <p>[blog] Build your own custom TCP/IP stack: <a href= "https://www.saminiir.com/lets-code-tcp-ip-stack-1-ethernet-arp/">https://www.saminiir.com/lets-code-tcp-ip-stack-1-ethernet-arp/</a></p> <p>Another custom TCP/IP stack: <a href= "https://github.com/tass-belgium/picotcp">https://github.com/tass-belgium/picotcp</a></p> <p>RIPPLE 20 Whitepaper: <a href= "https://drive.google.com/file/d/1d3NNVCRPVFk0-V0HUO5CxWWVn9pYIvmF/view?usp=sharing">https://drive.google.com/file/d/1d3NNVCRPVFk0-V0HUO5CxWWVn9pYIvmF/view?usp=sharing</a> </p> <p>Agenda:</p> <p>Part 1:</p> <p>Background on the report</p> <p>Why is it called RIPPLE20? What’s the RIPPLE about? </p> <p>Communications with Treck (and it’s Japanese counterpart)</p> <p>Were you surprised about the reaction? Positive or negative?</p> <p>Types of systems affected?</p> <p>IoT</p> <p>Embedded systems</p> <p>SCADA</p> <p>What precipitated the research?</p> <p>What difficulties did you face in finding these vulns? Deadlines? </p> <p>What tools were used for analysis? (I think you mentioned Forescout --brbr)</p> <p>What kind of extensibility are we talking about? TCP sizes? </p> <p>What did JSOF gain by doing this? </p> <p>What were the initial benefits of using the TCP/IP stack?</p> <p>Speed? Size?<br /> Do these vulns affect other TCP/IP stacks? </p> <p>Did Treck give you access to source? Any specific requirements set by Treck? Any items that were off-limits? </p> <p>Updates since the report was released?</p> <p>Are your vulns such that they can be detected online?</p> <p>Part 2:</p> <p>Supply chain issues</p> <p>What should companies do when they don’t know what’s in their own tech stack?</p> <p><a href= "https://csrc.nist.gov/CSRC/media/Projects/Supply-Chain-Risk-Management/documents/briefings/Workshop-Brief-on-Cyber-Supply-Chain-Best-Practices.pdf"> https://csrc.nist.gov/CSRC/media/Projects/Supply-Chain-Risk-Management/documents/briefings/Workshop-Brief-on-Cyber-S
Uploader
Episodes
2020-028-Shlomi Oberman, RIPPLE20, supply chain security discussion, software bill of materials
Mrs_Marong💞