Loading…
December 5-6, 2022
Yokohama, Japan + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Japan 2022 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Japan Standard Time (UTC +9). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: The timing of sessions and room locations are subject to change.

Tuesday, December 6 • 16:50 - 17:30
Config Based CVE Matching for Linux Kernel - Takuma Kawai, Miraxia Edge Technology Corporation

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
In the embedded Linux industry, "CPE search" methods are widely selected to fix security issues in their products. They search for CVEs by each package-version pair in their SBOMs and apply the security patches. However, this approach often becomes problematic because of an unexpectedly large CVE list of an outdated kernel with many false positives. Typical reasons why false positives reported are: (1) CPE information in the CVE database is too rough; and (2) the product is not affected by a CVE because the vulnerable code is never compiled with a given configuration. In most cases, more than half of the false positives could be reduced with the help of data from Ubuntu CVE Tracker, which describes the proper commit range that contains vulnerable code. An additional ~10% false positives could be reduced by examining whether a commit with vulnerable code is compiled or not with consideration of ".config". Firstly, Takuma Kawai will describe a classic way to track security issues widely chosen in their industry and its problems. Then he explains a more accurate algorithm using commit ids to identify the vulnerable version range, replacing the classical method. Finally, he presents a new method, which reduces ~10% more false positives in combination with other methods.

Speakers
avatar for Takuma Kawai

Takuma Kawai

General Staff, Miraxia Edge Technology Corporation
Takuma Kawai is a embedded Linux BSP engineer working at Miraxia. He has experience in developing embedded linux kernel, bootloader, build system, device driver and userland tools. His recent work was creating embedded Linux BSP for a new Arm SoC from scratch, including TF-A plat... Read More →



Tuesday December 6, 2022 16:50 - 17:30 JST
416&417
  Critical Software Summit