{"id":795,"date":"2022-05-30T09:36:17","date_gmt":"2022-05-30T07:36:17","guid":{"rendered":"https:\/\/insightevents.dk\/isc-cph\/?p=795"},"modified":"2022-10-13T23:18:19","modified_gmt":"2022-10-13T21:18:19","slug":"doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms","status":"publish","type":"post","link":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/","title":{"rendered":"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs"},"content":{"rendered":"<p><strong>Ron Brash is the VP of technical research and integrations at <a href=\"https:\/\/adolus.com\/\" target=\"_blank\" rel=\"noopener\">aDolus Technology<\/a>, and he is one of the keynotes at the <a href=\"https:\/\/insightevents.dk\/isc-cph\/\" target=\"_blank\" rel=\"noopener\">international industrial security conference<\/a> the 14-15-16 November. At the conference he will be talking about SBOMs and how he manages security in the organization. <\/strong><\/p>\n<p><strong>\u00a0<\/strong>Read an interesting article from Ron her.<\/p>\n<h2><strong>\u00a0<\/strong><strong>How do we create accurate SBOMs?\u00a0 \u00a0<\/strong><\/h2>\n<p>One of the biggest challenges facing supply chain security is how to secure legacy products while identifying hidden cyber risks buried deep in their subcomponents. Creating accurate Software Bills of Materials (SBOMs) is the critical first step, but how do we do that when the OT legacy software market is a story of abandoned, unbuildable, or lost source code?<\/p>\n<p>Often all the OT industry has to work with, is binary images (hotfixes included). And that means working backwards from binaries using Binary Composition Analysis (BCA) and Metadata Composition Analysis (MCA). Using these techniques, the OT professional can address crucial challenges when identifying third-party\/supply chain flaws, work with a myriad of file format types, research undocumented\/proprietary designs, and execute real-world file-format sleuthing.<\/p>\n<h2><strong>Threat hunting <\/strong><\/h2>\n<p>Using samples from an anonymized vendor, this session will explore the challenges experienced when decomposing files to address supply chain transparency. We\u2019ll do this by identifying several types of files based on patterns (flash vs. bootloader vs. update package), distinguishing various attributes or markers of interest, spotting security problems with minimal effort, and exploring how to research a file format that is decades old. It&#8217;s not a trivial art, but rather a demonstrable skill that requires the combined experiences of people from differing backgrounds to achieve success. In other words, think of it as threat hunting but for OT\/ICS files.<\/p>\n<h2><strong>At the conference you will learn about: <\/strong><\/h2>\n<ul>\n<li>Introduced to why Software Composition Analysis (SCA) doesn\u2019t work to reduce the plethora of ICS issues today with regards to vulnerabilities and third-party components<\/li>\n<li>Provided an overview of the filetype bucket corpus that can be used when spelunking samples<\/li>\n<li>Walked through a few file system and embedded image formats to see how the patterns or details can slowly be taught as human-readable patterns<\/li>\n<li>Provided examples of key areas to look for that can hint to implementation vulnerabilities (particularly with respect to low-effort bricking attacks, such as Viasat modem attacks in 2022)<\/li>\n<li>Delighted to see that a legacy 20+ year old file format can still be deconstructed despite limited documentation<\/li>\n<\/ul>\n<h2><strong>Understand risk from both sides <\/strong><\/h2>\n<p>And we\u2019ll pull this all together to truly understand risk from both the community and product perspectives for the purpose of securing yesterday\u2019s, today\u2019s, and tomorrow&#8217;s critical infrastructure. Whether you are a security researcher, asset owner, or vendor, there will be something for everyone in this talk.<\/p>\n<h2><strong>Do you want to learn more about SBOMs from Ron? <\/strong><\/h2>\n<p>At the international industrial security conference the 14-15-16 November in Copenhagen, Ron will be giving an interesting keynote presentation about understanding risk from both sides, SBOMs. And much more!<\/p>\n<p>Join the international Industrial Security Conference. Read more <a href=\"https:\/\/insightevents.dk\/isc-cph\/\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>\u00a0and sign up\u00a0<a href=\"https:\/\/my.eventbuizz.com\/event\/industrial-security-conference-cph-2022-10303\/detail\/registration\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ron Brash is the VP of technical research and integrations at aDolus Technology, and he is one of the keynotes at the international industrial security conference the 14-15-16 November. At the conference he will be talking about SBOMs and how he manages security in the organization. \u00a0Read an interesting article from Ron her. \u00a0How do [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":796,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[3],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Doctor StrangeFormat: How I learned to be an archeologist for SBOMs<\/title>\n<meta name=\"description\" content=\"Ron Brash is one of the keynotes at the Industrial Security Conference, where he will talk about SBOMs and how he manages security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs\" \/>\n<meta property=\"og:description\" content=\"Ron Brash is one of the keynotes at the Industrial Security Conference, where he will talk about SBOMs and how he manages security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/\" \/>\n<meta property=\"og:site_name\" content=\"Industrial Security Conference Copenhagen\" \/>\n<meta property=\"article:published_time\" content=\"2022-05-30T07:36:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-10-13T21:18:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Line\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Line\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/\",\"url\":\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/\",\"name\":\"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs\",\"isPartOf\":{\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg\",\"datePublished\":\"2022-05-30T07:36:17+00:00\",\"dateModified\":\"2022-10-13T21:18:19+00:00\",\"author\":{\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/#\/schema\/person\/e1b949cdb7e6339b6ba34b36365c444c\"},\"description\":\"Ron Brash is one of the keynotes at the Industrial Security Conference, where he will talk about SBOMs and how he manages security.\",\"breadcrumb\":{\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#primaryimage\",\"url\":\"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg\",\"contentUrl\":\"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Ron Brash at the industrial security conference talking about sboms\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/insightevents.dk\/isc-cph\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/#website\",\"url\":\"https:\/\/insightevents.dk\/isc-cph\/\",\"name\":\"Industrial Security Conference Copenhagen\",\"description\":\"Industrial Security Conference Copenhagen\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/insightevents.dk\/isc-cph\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/#\/schema\/person\/e1b949cdb7e6339b6ba34b36365c444c\",\"name\":\"Line\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/insightevents.dk\/isc-cph\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7b77f339adf5c930d53d064e7fb88017?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7b77f339adf5c930d53d064e7fb88017?s=96&d=mm&r=g\",\"caption\":\"Line\"},\"url\":\"https:\/\/insightevents.dk\/isc-cph\/author\/line\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs","description":"Ron Brash is one of the keynotes at the Industrial Security Conference, where he will talk about SBOMs and how he manages security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/","og_locale":"en_GB","og_type":"article","og_title":"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs","og_description":"Ron Brash is one of the keynotes at the Industrial Security Conference, where he will talk about SBOMs and how he manages security.","og_url":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/","og_site_name":"Industrial Security Conference Copenhagen","article_published_time":"2022-05-30T07:36:17+00:00","article_modified_time":"2022-10-13T21:18:19+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg","type":"image\/jpeg"}],"author":"Line","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Line","Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/","url":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/","name":"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs","isPartOf":{"@id":"https:\/\/insightevents.dk\/isc-cph\/#website"},"primaryImageOfPage":{"@id":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#primaryimage"},"image":{"@id":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#primaryimage"},"thumbnailUrl":"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg","datePublished":"2022-05-30T07:36:17+00:00","dateModified":"2022-10-13T21:18:19+00:00","author":{"@id":"https:\/\/insightevents.dk\/isc-cph\/#\/schema\/person\/e1b949cdb7e6339b6ba34b36365c444c"},"description":"Ron Brash is one of the keynotes at the Industrial Security Conference, where he will talk about SBOMs and how he manages security.","breadcrumb":{"@id":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#primaryimage","url":"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg","contentUrl":"https:\/\/insightevents.dk\/isc-cph\/wp-content\/uploads\/sites\/4\/2022\/08\/ronbrash1200x630.jpg","width":1200,"height":630,"caption":"Ron Brash at the industrial security conference talking about sboms"},{"@type":"BreadcrumbList","@id":"https:\/\/insightevents.dk\/isc-cph\/2022\/05\/30\/doctor-strangeformat-how-i-learned-to-be-an-archeologist-for-sboms\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/insightevents.dk\/isc-cph\/"},{"@type":"ListItem","position":2,"name":"Doctor StrangeFormat: How I learned to be an archeologist for SBOMs"}]},{"@type":"WebSite","@id":"https:\/\/insightevents.dk\/isc-cph\/#website","url":"https:\/\/insightevents.dk\/isc-cph\/","name":"Industrial Security Conference Copenhagen","description":"Industrial Security Conference Copenhagen","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/insightevents.dk\/isc-cph\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/insightevents.dk\/isc-cph\/#\/schema\/person\/e1b949cdb7e6339b6ba34b36365c444c","name":"Line","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/insightevents.dk\/isc-cph\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7b77f339adf5c930d53d064e7fb88017?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7b77f339adf5c930d53d064e7fb88017?s=96&d=mm&r=g","caption":"Line"},"url":"https:\/\/insightevents.dk\/isc-cph\/author\/line\/"}]}},"_links":{"self":[{"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/posts\/795"}],"collection":[{"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/comments?post=795"}],"version-history":[{"count":0,"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/posts\/795\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/media\/796"}],"wp:attachment":[{"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/media?parent=795"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/categories?post=795"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/insightevents.dk\/isc-cph\/wp-json\/wp\/v2\/tags?post=795"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}