Course by  Constanze Roedig

Bill of Behavior - vendor supplied runtime profile for tampering and anomaly detection

We ♥️ supply chain security, thus was created SBOM - the Bill of Materials- but, we also need BoB -the Bill of Behavior - This livelab proposes to standardize how to record a benign behavior profile, extract, sign and publish it, for users to consume, ingest, verify it and detect attacks and tampering. For software-vendors, a BoB creates trust and transparency, For users, it makes anomaly detection realistically achievable.

Bill of Behavior - vendor supplied runtime profile for tampering and anomaly detection (cover image)

About This Course

We ❤ supply chain security, thus people invented SBOM: the Bill of Materials. Now, here comes the Bill of Behaviour BoB...

This "course" is currently WIP by Constanze and it's to be understood as a public co-lab for creating a reference implementation (like a devcontainer but with instructions and text) and you are invited to try it out and give her feedback, you can also become a co-author. It is not a "course"

Please note, that feedback both on the idea of BoB as well as the implementation (in this lab) are welcome. It is still under development, at the moment we re focusing on the big ideas with the goal of this being acceptable as a standard (i.e. any tool choices should be optional), by as many vendors and users as possible.

You can contribute to the bobctl repo under the Kubernetes Stormcenter.

Get notified about new lessons straight to your inbox!