October 3, 2018
Keck Center of the National Academies of Sciences, Engineering, and Medicine
Washington, D.C.
| 8:30 a.m. | Welcome and Context-Setting—Fred Schneider, Chair, Forum on Cyber Resilience |
| 9:00 | Keynote—Paul Kocher, Forum Member |
| 10:00 | Break |
| 10:30 | Hardware and Software Engineering Assumptions at Risk |
| Session Goal: Explore future chip design and performance trade-offs with security, implications of decreasing performance, effects on software engineering and compiler design assumptions, possible responses to Spectre, and similar vulnerabilities. | |
| Moderator: John Manferdelli, Forum Member Ernie Brickell, Independent Security Researcher Galen Hunt, Microsoft Research Andrew Myers, Cornell University |
|
| 12:15 p.m. | Lunch |
| 1:15 | Implications for Cloud Services and Isolation |
| Session Goal: Explore challenges of current cloud architecture and isolation assumptions post-Spectre; importance of hardware isolation capabilities on shared |
| infrastructure; practical implications of emerging side-channel risks and comparisons/trade-offs with other known vulnerabilities. | |
| Moderator: Eric Grosse, Forum Member Brandon Baker, Google Mark Ryland, Amazon Web Services |
|
| 2:30 | Break |
| 3:00 | International Implications, National Security, and Vulnerability Disclosure |
| Session Goal: Explore complicated global landscape regarding vulnerability disclosure—how, when, who, why; examine complex space of trade-offs; provide rich picture of future challenges. | |
| Moderator: Steven Lipner, Forum Member Ari Schwartz, Center for Cybersecurity Policy and Law, Venable LLP Katie Moussouris, Luta Security Audrey L. Plonk, Intel Corporation Paul Waller, U.K. National Cyber Security Centre |
|
| 4:45 | Plenary Wrap-up and Q&A |
| Moderator: Fred Schneider, Forum Chair |
Please note: Affiliations are for identification purposes only; unless noted, speakers are speaking for themselves and not for any institutions with which they may be affiliated.