Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

IBM Software Fingerprinting for Supply Chain Security Presentation & Feedback #8

Closed
mrutkows opened this issue Nov 4, 2022 · 5 comments

Comments

@mrutkows
Copy link

mrutkows commented Nov 4, 2022

Attached to this issue is the PDF of the presentation given during the Wed. Nov. 2nd meeting (APAC friendly) for review and comment...

OpenSSF Repository WG Presentation.pdf

Screen Shot 2022-11-04 at 9 15 51 AM

@mrutkows
Copy link
Author

mrutkows commented Nov 4, 2022

For convenience, I copied the Q&A captured from the 11/2 meeting minutes:

Q: How are you consuming all the software that exists to compute genes?
A: Existing software repos, feeds. Provide a search engine for code, search by hash, go beyond.

Q: Have you considered how the fingerprint relates to dependencies? Connecting/mapping dependencies via a gene.
A: Actually building a large graph behind the scene, including relationships between binaries and dependencies.

Q: What is the granularity? What about reordering positioning?
A: Based on functionality. The hope is that it’s resilient to obfustication. File level could be too coarse, lines could be too fine.

Q: How are you handing obfustication generally? What’s the threat model?
A: (long answer omitted from Jiyong)

Q: This seems to apply to malware, have you explored that?
A: Main focus is SBOM and open source

@naveensrinivasan
Copy link
Member

Is this tool planning to be OSS?

@mrutkows
Copy link
Author

mrutkows commented Jun 30, 2023

Recording of the presentation at the 11/2/2022 WG meeting:
https://www.youtube.com/watch?v=LsshIbsD6oY&list=PLVl2hFL_zAh_VfsvGMCrkPSS1z2VFFy-r

@mrutkows
Copy link
Author

Demo at LF Member Summit 2022 (keynote) at the 52 minute mark "Code Genome" project by JR Rao:
https://www.youtube.com/watch?v=BltvpGfqz14

@steiza
Copy link
Member

steiza commented Oct 11, 2023

Thanks for posting this! I'm going to mark this issue as closed, but we can continue to refer to the content here.

@steiza steiza closed this as completed Oct 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants