Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Uncovering Supply Chain Attack with Code Genome Framework

Black Hat via YouTube

Overview

Coursera Plus Monthly Sale: All Certificates & Courses 40% Off!
This conference talk explores how the Code Genome Framework can detect supply chain attacks by generating semantic code fingerprints that bridge the gap between binary code behavior and metadata. Learn how software supply chain security faces challenges when attackers compromise the chain to manipulate binary packages, making it difficult for end users to verify code integrity beyond trusting supplier metadata. Discover the open-source Code Genome Framework that extracts "genes" capturing computational semantics from binaries without source code, enabling gene-level binary diffing and knowledge graph-based gene searching. See practical demonstrations of how this framework can automatically detect attacks like the "XZ backdoor," validate reproducible builds, ensure cross-platform equivalent builds in CI/CD, and examine version differences. The presentation also showcases how to build a large knowledge graph of open source software to identify components in unknown binaries for SBOM generation and verification. Presented by Dhilung Kirat and Jiyong Jang from IBM Research at Black Hat.

Syllabus

Uncovering Supply Chain Attack with Code Genome Framework

Taught by

Black Hat

Reviews

Start your review of Uncovering Supply Chain Attack with Code Genome Framework

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.