Главная
Study mode:
on
1
Intro
2
CVE what?
3
How much does security mean to you?
4
CVE content
5
How to monitor CVES? Linux Distro model
6
DIY CVE monitoring
7
CVE monitoring in Yocto Bullin support for automatic checking CVES
8
I have a CVE list, now what?
9
DIY CVE Patching
10
Upgrade vs. Backport
11
Reasons to upgrade
12
CVE data quality (False positives and misses)
13
Yocto solutions
14
Yocto CVE report bugs' YMMV
15
Yocto CVE check improvements YMMV
16
Linux kernel CVES
17
Delays in CVE reporting / analysis
18
Fun stats on delays
19
Leveraging work done by others!
20
Secure boot and chain of trust
21
Layered approach
22
Tools wishlist
23
Take away
Description:
Explore the intricacies of open source CVE monitoring and management in this 40-minute Linux Foundation conference talk. Gain insights into the process of monitoring Common Vulnerabilities and Exposures (CVEs), determining their applicability, assessing severity, and finding fixes. Delve into the challenges of tracking CVEs due to inaccuracies in NVD/MITRE feeds and scanning tools. Learn techniques to mitigate issues and improve device security posture. Discover the DIY approach to CVE monitoring and patching, understand the pros and cons of upgrades versus backports, and examine CVE data quality issues. Investigate Yocto-specific solutions and improvements for CVE checking. Analyze delays in CVE reporting and explore strategies for leveraging work done by others. Gain knowledge about secure boot, chain of trust, and layered security approaches. Leave with valuable insights and a tools wishlist to enhance your open source security practices.

Open Source CVE Monitoring and Management - Cutting Through the Vulnerability Storm

Linux Foundation
Add to list