Loading…
Company: Enterprise clear filter
arrow_back View All Dates
Tuesday, February 11
 

3:00pm PST

PRO WORKSHOP: Bolster Your Bug Bounty – Code Search & Variant Analysis Techniques
Tuesday February 11, 2025 3:00pm - 3:50pm PST
Milan Williams, Semgrep, Senior Product Manager
Austin Theriault, Semgrep, Software Engineer


With so many repositories, organizations can struggle to locate and remediate recurring insecure code patterns. In this talk, you will understand the fundamentals of bug bounty programs, their importance, and common inefficiencies. Attendees will learn how to perform variant analysis, refine searches to reduce false positives and find vulnerabilities quickly. By leveraging these techniques, security teams can identify and reuse previous findings, extending the impact of their bug bounty program and significantly reducing costs. This technical session also provides a detailed architectural overview of building an in-house code search engine, drawing from our own experience. We'll share our wins & woes through multiple iterations, lessons learned, and preferred technologies. Our session concludes with a practical end-to-end walkthrough of a sanitized bug bounty report. Join us to gain knowledge to implement these strategies and technologies in your own engineering practice. 
Speakers
avatar for Austin Theriault

Austin Theriault

Software Engineer, Semgrep
avatar for Milan Williams

Milan Williams

Senior Product Manager, Semgrep
Milan Williams is a Senior Product Manager at Semgrep, where she helps security engineers and developers work together to ship secure software. She recently graduated from Harvard University with degrees in Computer Science and Physics. In her free time, you can find her running in... Read More →
Tuesday February 11, 2025 3:00pm - 3:50pm PST
DeveloperWeek PRO Stage
  OpsWorld

4:00pm PST

PRO WORKSHOP: The Dark Side of Open Source Productivity LIMITED
Tuesday February 11, 2025 4:00pm - 4:50pm PST
Derek Francour, Endor Labs, Solutions

There is a dark side to productivity with open source. In modern applications, the majority of code on which an application is built isn’t code written by your team. Modern applications are built on the backs of volunteer communities and open-source software. These volunteers and their software delivery practices all become potential attack vectors. The truth is that most organizations do not factor open-source supply chain attacks into their organization’s threat models today. Security incidents such as the CodeCov bash uploader script, the npm colors, and faker intentionally introduced malicious commits, and the recent PyPi backdoors targeting AWS credentials highlight the impact of supply chain attacks as a scalable attack pattern. To spread awareness on supply chain attacks so that organizations can scalably handle them we propose baking supply chain attacks into existing threat modeling procedures and software development culture so that organizations can champion supply chain management of open source in the places where they are most impactful, at development time. We will present a comprehensive, comprehensible, and technology-agnostic taxonomy of attack vectors, created on the basis of hundreds of real-world incidents and validated by experts in the domain. Following, we will discuss the types of defenses you can put in place to detect and respond to such modern day attacks and how you can work these defenses in based on your program’s maturity. 
Speakers
avatar for Derek Francour

Derek Francour

Solutions, Endor Labs
As a Solutions Architect at Endor Labs, Derek Francour helps teams implement application security programs that don't slow down developers and make upgrading open source dependencies easier. Previously, Derek worked in Healthcare IT as a full-stack web developer and solutions engineer... Read More →
Tuesday February 11, 2025 4:00pm - 4:50pm PST
DeveloperWeek PRO Stage
  Cloud Native World

5:00pm PST

PRO WORKSHOP: Crypto-secure Data Management with In-Database Blockchain LIMITED
Tuesday February 11, 2025 5:00pm - 5:25pm PST
Mark Rakhmilevich, Oracle, Vice President, Product Management, Mission-Critical and Blockchain Technologies

Existing security mechanisms are designed to keep hackers out. However, they have unavoidable vulnerabilities - chiefly due to human weaknesses (e.g., phishing attacks). We cannot prevent these break-in's, but we can minimize their impact by making critical data tamper-proof by using blockchain technologies.

Conventional blockchain systems, however, have been very difficult to use because of the requirement for new programming languages, tools, and workflow processes. This is changing as blockchain features are being incorporated in general-purpose databases. This makes it possible to implement blockchain in mainstream enterprise and government applications with minimal application changes.

This talk will begin by introducing the threats posed by hackers and compromised insiders. Then we will describe an implementation of in-database blockchain and how it can protect your data against these threats. We will compare this against conventional blockchains as well as share use cases from customers who have adopted this technology.
Speakers
avatar for Mark Rakhmilevich

Mark Rakhmilevich

Vice President, Product Management, Mission-Critical and Blockchain Technologies, Oracle
Tuesday February 11, 2025 5:00pm - 5:25pm PST
DeveloperWeek PRO Stage
  Cloud Native World
 

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date - 
  • Tracks & Topics
  • AI & ML Certificate
  • API Certificate
  • APIs & Microservices
  • Blockchain & Web3
  • Cloud Management Certificate
  • Data Engineering
  • Data Management and Engineering Certificate
  • Dev Career
  • Dev Leadership Certificate
  • Developer Experience (DX)
  • Developer Tools
  • DevOps
  • DevOps Certificate
  • Enterprise
  • Frontend Certificate
  • Gen AI / LLMs
  • Open Source Strategy
  • Platform Engineering
  • Product Certificate
  • Security Certificate
  • Technical Leadership & Management
  • Session Type
  • OPEN Session
  • PRO Session
  • PRO Workshop Day (Tues)
  • Conferences
  • AI & Organizational Change Management (AI DevWorld)
  • AI DevWorld
  • AI DevWorld: AI Strategy Conference
  • AI DevWorld: AI/ML Engineering Conference
  • AI DevWorld: Industry AI Conference
  • AI Ethics (AI DevWorld)
  • AI for the Enterprise (AI DevWorld)
  • AI Security & Governance & Compliance (AI DevWorld)
  • Applied AI Innovation (AI DevWorld)
  • Applied Machine Learning (AI DevWorld)
  • Bots & Language Processing (AI DevWorld)
  • Cloud Native World
  • Data Science & Predictive Models (AI DevWorld)
  • Deep AI Learning & Neural Networks (AI DevWorld)
  • Dev Exec World
  • Dev Innovation World
  • Dev Security World
  • Finance/FinTech AI (AI DevWorld)
  • Frontend World
  • Generative AI & LLMs (AI DevWorld)
  • Healthcare & HealthTech AI (AI DevWorld)
  • Marketing & Advertising AI (AI DevWorld)
  • Methodology: Agile and Rapid Prototyping and SCRUM and Beyond (ProductWorld)
  • MLOps & AIOps (AI DevWorld)
  • OPEN Session
  • OpenAPI Summit
  • OpsWorld
  • OWASP Certified
  • Product Lead / Product Manager Roundtables (ProductWorld)
  • Product Lifecycle & Case Studies (ProductWorld)
  • Product Management Tools & Software (ProductWorld)
  • Product Roadmap Strategy & Innovation (ProductWorld)
  • Product Team Management & Structure (ProductWorld)
  • ProductWorld
  • Retail & E-commerce AI (AI DevWorld)
  • Roundtables
  • Sponsor Spotlight
  • Tensorflow & PyTorch & Open Source Frameworks (AI DevWorld)
  • Virtual
  • In-Person/Virtual
  • In Person
  • Virtual
  • Virtual Exclusive