Welcome to the third annual Cybersecurity Across Disciplines (CyAD) Conferencehosted by the National Cybersecurity Training & Education Center (NCyTE)!
The schedule is tentative and subject to change. Please check back regularly for the most current version.
Important Notice: All sessions are first-come, first-served. While you can plan your schedule in Sched, it does not guarantee a seat in any session. CyAD registrants check your email inbox or junk folder for Sched invite.
Sign up or log in to add sessions to your schedule and sync them to your phone or calendar.
The automotive industry’s systems and over-the-air (OTA) updates have vulnerabilities in its software supply chain (SSC). Although frameworks like Uptane have improved OTA security, gaps remain in ensuring software integrity and provenance. In this paper, we examine challenges securing the automotive SSC and introduce a framework, GUIXCHAIN, that integrates version control, reproducible builds, blockchain technology, and software bills of materials (SBoMs) for transparency, auditability, and resilience. Reproducible builds guarantee identical resulting binaries when compiling the same source code in different environments, as any deviation in the final output indicates a potential compromise in the build process, such as malware injection.
Our preliminary study shows Guixchain’s use of reproducible builds ensures consistent and integrity-secured software across various build environments. The blockchain provides forensic capabilities, offering a history of the what, who and where of discrepancies within the SSC process. SBoMs provide an inventory of the software components used. Our preliminary study demonstrates that Guixchain effectively mitigates risks such as ransomware, unauthorized modifications, and build server compromises, reinforcing the systems integrity and resilience throughout the software life cycle.
Iwinosa Aideyan is a third-year Ph.D. student in Computer Engineering at the Virtual Prototyping of Autonomy-Enabled Ground Systems (VIPR-GS) Center in conjunction with the US Army at Clemson University, with a research focus on automotive cybersecurity. Her work aims to enhance... Read More →