<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>2024s on SCORED &#39;26 Conference</title>
    <link>/2024/</link>
    <description>Recent content in 2024s on SCORED &#39;26 Conference</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <atom:link href="/2024/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title></title>
      <link>/2024/call_for_papers/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/call_for_papers/</guid>
      <description>Call for Papers/Talks The SCORED workshop invites academia, industry, and governmental entities to submit original research papers or security-in-practice talks concerning the security of software supply chains from both technical and policy perspectives.&#xA;Suggested topics include, but are not limited to:&#xA;Attacks on the software supply chain Securing source control Trustworthy builds Reproducible builds Secure CI/CD Code signing Integrity for container images Package management security Code dependency tracking and patch propagation Auditable storage for metadata Software updates Developer identity management Code vulnerability tracking and disclosure as well as vulnerable code-clone detection Static analysis Hardware-assisted software supply chain integrity Software bills of materials (SBOMs) Specification of supply chain security policies Tools for securing the SW supply chain Interfacing the hardware and software supply chains Surveys or Systemization of Knowledge (SoK) of the SW supply chain security landscape Public policy around SW supply chain security SW supply chain security best practices Standards Domain-specific software supply chains (voting, finance etc) Security economics Human behavioral and measurement studies, e.</description>
    </item>
    <item>
      <title></title>
      <link>/2024/committee/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/committee/</guid>
      <description>Committee Workshop Chairs Santiago Torres Arias, Purdue&#xA;Program Chairs Lorenzo De Carli, University of Calgary&#xA;Yuchen (Dennis) Zhang, NYU&#xA;Steering Committee Marcela Melara, Intel Labs&#xA;Program Committee Aditya Sirish A Yelgundhalli, New York University&#xA;Adriana Sejfia,&#x9;University of Edinburgh&#xA;Ahmad Abdellatif, University of Calgary&#xA;Behnaz Hassanshahi, Oracle Labs&#xA;Benoit Baudry, Université de Montréal&#xA;Dennis Roellke, Bloomberg&#xA;Dominik Wermke, NC State&#xA;Drew Davidson, University of Kansas&#xA;Elizabeth Wyss, University of Kansas</description>
    </item>
    <item>
      <title></title>
      <link>/2024/contact/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/contact/</guid>
      <description></description>
    </item>
    <item>
      <title></title>
      <link>/2024/home/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/home/</guid>
      <description></description>
    </item>
    <item>
      <title></title>
      <link>/2024/keynote/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/keynote/</guid>
      <description>Keynote Insane in the AI Supply Chain: Attacks, defenses and open questions Eoin Wickens, Director of Threat Intelligence, HiddenLayer&#xA;Abstract A supply chain attack can be incredibly damaging, far-reaching, and an all-around terrifying prospect that has been carved into the collective memory of security practitioners and executive leadership alike. Over the last three years since significant incidents like Solarwinds and Kaseya, the industry has made great strides in securing software supply chains, determined not to make the same mistakes again.</description>
    </item>
    <item>
      <title></title>
      <link>/2024/panel/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/panel/</guid>
      <description>Panel Discussion: ML (for) Supply Chain Security: Promises, Pitfalls and Opportunities Machine learning (ML) has become ubiquitous in assisting us in tasks as mundane as sending text messages and as critical as diagnosing cancer in patients. The emergence of generative AI (GenAI) over the past few years has opened further opportunities in other domains. For software development, in particular, there’s been a lot of recent talk about how GenAI shows promise for improving the security of tasks like coding, application testing and vulnerability analysis.</description>
    </item>
    <item>
      <title></title>
      <link>/2024/program/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/program/</guid>
      <description>2024 Workshop Agenda All times are in Mountain Daylight Time.&#xA;Opening Remarks and Awards (9:00 AM) PC Chairs&#xA;Keynote Talk (9:10 AM) Insane in the AI Supply Chain: Attacks, defenses and open questions Eoin Wickens, Director of Threat Intelligence, HiddenLayer&#xA;Break (10:00-10:15 AM) Technical Session 1: Building Trust in Software Supply Chains (10:15 AM) Session Chair: Martin Schwaighofer (Johannes Kepler University Linz)&#xA;Enhancing Transparency and Accountability of TPLs with PBOM: A Privacy Bill of Materials Yue Xiao (IBM), Adwait Nadkarni (William &amp;amp; Mary), Xiaojing Liao (Indiana University)</description>
    </item>
    <item>
      <title></title>
      <link>/2024/workshop_information/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/2024/workshop_information/</guid>
      <description>About SCORED Overview Every single piece of software running on every computing device today is produced through a complex supply chain that often involves a myriad of individuals and spans multiple organizations and administrative domains. Recent attacks on the software supply chain have shed light on the fragility and importance of ensuring the security and integrity of this vital ecosystem. Addressing the technical and social challenges to building trustworthy software for deployment in sensitive and/or large-scale enterprise or governmental settings requires innovative solutions and an interdisciplinary approach.</description>
    </item>
  </channel>
</rss>
