meta-freescale.lists.yoctoproject.org archive mirror
 help / color / mirror / Atom feed
* Re: [meta-xilinx] addressing security in Yocto
       [not found] <3f190ec8540544b6a694b5f2cd089c30@XCGC3023.northgrum.com>
@ 2020-02-04 23:29 ` Mark Hatle
  0 siblings, 0 replies; only message in thread
From: Mark Hatle @ 2020-02-04 23:29 UTC (permalink / raw)
  To: Minelik, Ben [US] (MS), meta-freescale, meta-xilinx, meta-ti
  Cc: yocto-security

Security requires a holistic approach.  This can be divided into design and
defect response.

The design aspect of this is left to the implementer of the device.  However, as
a project we need to do a better job at defining defaults, and looking for items
like SCAP that can be used to help people design/implement more secure devices.

On the defect (security) response side, work is in progress on this.

Currently there is a script that will pull down CVE information and attempt to
determine if a recipe may be affected based on specific CPE information.  But in
the end, this is a reactive approach that relies on other people to do initial
triage and assign the CPEs (and other information).

This means we really need more proactive, response approach.  The tooling for
this is nearly ready to go.  We have the security response tool (which is part
of the Yocto Project) designed to help us perform triage, and a small group of
us has been working on a process around to perform the triage.

In the near future, I will be trying to post to the yocto-security list triage
status and other issues we find.  When I begin posting, I will be inviting
people to help contribute to our triage, and response process.  (Currently we're
running proof of concept triage behavior with a small group of people.)

--Mark

On 1/13/20 11:13 AM, Minelik, Ben [US] (MS) wrote:
> Good Morning,
> 
>  
> 
> I was wondering if there is a more holistic way we can address security in Yocto
> where we don’t have to create scripts for each vulnerability?  Is there anything
> in Yocto meta-security and buck-security that can assist with the hardening of
> Yocto?
> 
>  
> 
>  
> 
>  
> 
> Thank you,
> 
>  
> 
> Ben
> 
> Cybersecurity Engineer
> 
> 720-975-5665
> 
> 
> 
> 

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2020-02-04 23:43 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <3f190ec8540544b6a694b5f2cd089c30@XCGC3023.northgrum.com>
2020-02-04 23:29 ` [meta-xilinx] addressing security in Yocto Mark Hatle

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).