Laurie Williams Keynote: What We’ve Learned By Actually Talking to Practitioners about Software Supply Chain Security (and How we Do it)
Software organizations largely did not anticipate how the software supply chain would become a deliberate attack vector. Software supply chain attacks are launched through components in ecosystems, such as npm; through build infrastructure, such as GitHub Actions; and through humans involved in producing software, such as project maintainers. Supply chain attacks have been increasing almost exponentially since 2020, affecting governments, software organizations, and citizens worldwide. Software practitioners can’t stand still. They have no choice but to take action to avoid exploitation, often using existing technology because their real focus is on delivering products. Researchers can innovate and create novel, holistic solutions that have an impact when their research is informed by direct knowledge of practical problems. In this talk, I will share the specific methods we use to interact with industry and government. I will share what we have learned about software supply chain security through this interaction and how this knowledge has informed the research of the 25 faculty and students in the Secure Software Supply Chain Center (S3C2). My goal is not only to share about software supply chain security but to provide you with a framework for interacting with practitioners so you can have as much impact as possible on the software industry. Bio: Laurie Williams is the Goodnight Distinguished University Professor of Security Sciences in the Computer Science Department of the College of Engineering at North Carolina State University (NCSU). Laurie is the director of the National Science Foundation-sponsored Secure Software Supply Chain Center (S3C2), and co-director of the NSA-sponsored North Carolina Partnership for Cybersecurity Excellence (NC-PaCE) and the NCSU Secure Computing Institute. Laurie is an IEEE Fellow and an ACM Fellow. Laurie’s research focuses on software security, software processes, and empirical software engineering.
Thu 16 AprDisplayed time zone: Brasilia, Distrito Federal, Brazil change
08:45 - 10:40 | Thursday Morning PlenaryMain Plenaries at Plenary (Asia II + III + Hall) This will be the fourth plenary session of the main conference ( Second part of the Awards session).
| ||
08:45 45mAwards | ICSE Distinguished Paper Main Plenaries | ||
09:30 35mKeynote | Laurie Williams Keynote: What We’ve Learned By Actually Talking to Practitioners about Software Supply Chain Security (and How we Do it) Main Plenaries Laurie Williams North Carolina State University | ||
10:05 35mKeynote | Silvio Meira Keynote: Adaptive Interventionist Method (AIM): Rethinking Research Methodologies for Software Engineering and Interventionist Sciences in the Phygital Age Main Plenaries Silvio Meira TDS.company | ||