תוכן מסופק על ידי Carnegie Mellon University Software Engineering Institute and Members of Technical Staff at the Software Engineering Institute. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Carnegie Mellon University Software Engineering Institute and Members of Technical Staff at the Software Engineering Institute או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
Player FM - אפליקציית פודקאסט
התחל במצב לא מקוון עם האפליקציה Player FM !
התחל במצב לא מקוון עם האפליקציה Player FM !
פודקאסטים ששווה להאזין
בחסות
F
Fixable


When negative feedback shakes your confidence, it can be difficult to get back to feeling like yourself at work. In this episode, Anne and Frances help a struggling listener who has spent years toning herself down in the workplace after being told that she was too assertive — now, she feels that her modest approach is holding her back. Together, they use Anne and Frances’s “trust triangle” framework to explore how empathy, authenticity, and logic can help you rebuild confidence and trust with your colleagues, and share helpful confidence hacks for getting comfy with discomfort. What problems are you dealing with at work? Text or call 234-FIXABLE or email fixable@ted.com to be featured on the show. For the full text transcript, visit ted.com/podcasts/fixable-transcripts Want to help shape TED’s shows going forward? Fill out our survey ! Hosted on Acast. See acast.com/privacy for more information.…
Improving Machine Learning Test and Evaluation with MLTE
Manage episode 469437385 series 2487640
תוכן מסופק על ידי Carnegie Mellon University Software Engineering Institute and Members of Technical Staff at the Software Engineering Institute. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Carnegie Mellon University Software Engineering Institute and Members of Technical Staff at the Software Engineering Institute או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
Machine learning (ML) models commonly experience issues when integrated into production systems. In this podcast, researchers from the Carnegie Mellon University Software Engineering Institute and the U.S. Army AI Integration Center (AI2C) discuss Machine Learning Test and Evaluation (MLTE), a new tool that provides a process and infrastructure for ML test and evaluation. MLTE can aid organizations across the DoD in more effectively negotiating, documenting, and evaluating model and system qualities.
…
continue reading
416 פרקים
Manage episode 469437385 series 2487640
תוכן מסופק על ידי Carnegie Mellon University Software Engineering Institute and Members of Technical Staff at the Software Engineering Institute. כל תוכן הפודקאסטים כולל פרקים, גרפיקה ותיאורי פודקאסטים מועלים ומסופקים ישירות על ידי Carnegie Mellon University Software Engineering Institute and Members of Technical Staff at the Software Engineering Institute או שותף פלטפורמת הפודקאסט שלהם. אם אתה מאמין שמישהו משתמש ביצירה שלך המוגנת בזכויות יוצרים ללא רשותך, אתה יכול לעקוב אחר התהליך המתואר כאן https://he.player.fm/legal.
Machine learning (ML) models commonly experience issues when integrated into production systems. In this podcast, researchers from the Carnegie Mellon University Software Engineering Institute and the U.S. Army AI Integration Center (AI2C) discuss Machine Learning Test and Evaluation (MLTE), a new tool that provides a process and infrastructure for ML test and evaluation. MLTE can aid organizations across the DoD in more effectively negotiating, documenting, and evaluating model and system qualities.
…
continue reading
416 פרקים
כל הפרקים
×
1 The Magic in the Middle: Evolving Scaled Software Solutions for National Defense 21:25
21:25
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי21:25
A January 2025 Defense Innovation Board study on scaling nontraditional defense innovation stated, “We must act swiftly to ensure the DoD leads in global innovation and competition over AI and autonomous systems – and is a trendsetter for their responsible use in modern warfare." In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), chief technical officer Tom Longstaff discusses the SEI’s long-standing work to help the DoD rapidly scale technology including artificial intelligence (AI) and autonomous systems.…

1 Making Process Respectable Again: Advancing DevSecOps in the DoD Mission Space 44:26
44:26
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי44:26
Warfighters in the Department of Defense (DoD) operate in high-stakes environments where security, efficiency, and speed are critical. In such environments DevSecOps has become crucial in the drive toward modernization and overall mission success. A recent study led by researchers at the Carnegie Mellon University Software Engineering Institute (SEI) examined the state of DevSecOps within the Department of Defense. In this podcast, Eileen Wrubel, the SEI’s Transforming Software Acquisition Policy and Practice technical director, sits down with George Lamb, director for DoD Cloud and Software Modernization in the Information Enterprise Office of the DoD CIO, which is responsible for the DoD Software Modernization Strategy and its associated implementation plan, and Bill Nichols, lead of the SEI’s Software Engineering Measurement and Analysis work. They discuss DevSecOps successes in the DoD and opportunities for scaling its impact.…
Deploying cloud-centric technologies such as Kubernetes in edge environments poses challenges, especially for mission-critical defense systems. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Patrick Earl, Doug Reynolds, and Jeffrey Hamed, all DevOps engineers in the SEI's Software Solutions Division, sit down with senior reesearcher Jose Morales to discuss a recent case study involving the deployment of a hypervisor onto edge devices in a resource-constrained environment.…

1 The Best and Brightest: 6 Years of Supporting the President’s Cup Cybersecurity Competition 21:40
21:40
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי21:40
A strong cyber defense is vital to public- and private-sector activities in the United States. In 2019, in response to an executive order to strengthen America’s cybersecurity workforce, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) partnered with the SEI to develop and run the President’s Cup Cybersecurity Competition, a national cyber competition that identifies and rewards the best cybersecurity talent in the federal workforce. In six years, more than 8,000 people have taken part in the President’s Cup. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Jarrett Booz, technical lead for the President’s Cup, and John DiRicco, a training specialist in the SEI’s CERT Division, sit down with Matthew Butkovic, the CERT technical director of cyber risk and resilience, to reflect on six years of hosting the cup, including challenges, lessons learned, the path forward, and publicly available resources.…

1 Updating Risk Assessment in the CERT Secure Coding Standard 26:04
26:04
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי26:04
Evaluating source code to ensure secure coding qualities costs time and effort and often involves static analysis. But those who are familiar with static analysis tools know that the alerts are not always reliable and produce false positives that must be detected and disregarded. This year, we plan on making some exciting updates to the SEI CERT C Coding Standard to better harmonize with the current state of the art for static analysis tools as well as simplify the process of source code security auditing. In this SEI podcast, David Svobodaand Joseph Sible, both engineers in CERT’s Applied Systems Group and primary developers and maintainers of the standard, sit down with Robert Schiela, deputy technical director of the Cybersecurity Foundations Directorate in CERT, to discuss the proposed changes, specifically in the area of risk assessment.…

1 Delivering Next Generation Cyber Capabilities to the DoD Warfighter 27:16
27:16
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי27:16
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Gregory Touhill, director of the SEI CERT Division, sits down with Matthew Butkovic, technical director of Cyber Risk and Resilience at CERT, to discuss ways in which CERT researchers and technologists are working to deliver rapid capability to warfighters in the Department of Defense.…

1 Getting the Most Out of Your Insider Risk Data with IIDES 39:14
39:14
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:14
Insider incidents cause around 35 percent of data breaches, creating financial and security risks for organizations. In this podcast from the Carnegie Mellon University Software Engineering Institute, Austin Whisnant and Dan Costa discuss the Insider Incident Data Expression Standard (IIDES), a new schema for collecting and sharing data about insider incidents. IIDES facilitates insider incident information handling to help organizations better protect themselves against the compromise of sensitive information and mission-critical systems, which is essential to maintaining national security and defense.…

1 Grace Lewis Outlines Vision for IEEE Computer Society Presidency 18:14
18:14
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי18:14
Grace Lewis , a principal researcher at the Carnegie Mellon University Software Engineering Institute (SEI) and lead of the SEI’s Tactical and AI-Enabled Systems Initiative, was elected the 2026 president of the IEEE Computer Society (CS), the largest community of computer scientists and engineers, with more than 370,000 members around the world. In this SEI podcast, Lewis sits down with Ipek Ozkaya, technical director of Engineering Intelligent Software Systems, to discuss her vision and plans for the IEEE CS presidency.…

1 Improving Machine Learning Test and Evaluation with MLTE 29:06
29:06
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי29:06
Machine learning (ML) models commonly experience issues when integrated into production systems. In this podcast, researchers from the Carnegie Mellon University Software Engineering Institute and the U.S. Army AI Integration Center (AI2C) discuss Machine Learning Test and Evaluation (MLTE), a new tool that provides a process and infrastructure for ML test and evaluation. MLTE can aid organizations across the DoD in more effectively negotiating, documenting, and evaluating model and system qualities.…

1 DOD Software Modernization: SEI Impact and Innovation 27:12
27:12
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי27:12
As software size, complexity, and interconnectedness has grown, software modernization within the Department of Defense (DoD) has become more important than ever. In this discussion moderated by Matthew Butkovic, technical director of risk and resilience in the SEI CERT Division, SEI director Paul Nielsen outlines the SEI’s work with the DoD on software modernization, including controlling the attack surface, incorporating industry practices such as DevSecOps, and the interplay between software, cybersecurity, and AI.…

1 Securing Docker Containers: Techniques, Challenges, and Tools 39:09
39:09
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:09
Containerization allows developers to run individual software applications in an isolated, controlled, repeatable way. With the increasing prevalence of cloud computing environments, containers are providing more and more of their underlying architecture. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Sasank Venkata Vishnubhatla and Maxwell Trdina, both engineers in the SEI CERT Division, sit down with Tim Chick, technical manager of the Applied Systems Group, to explore issues surrounding containerization, including recent vulnerabilities.…

1 An Introduction to Software Cost Estimation 22:55
22:55
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי22:55
Software cost estimation is an important first step when beginning a project. It addresses important questions regarding budget, staffing, scheduling, and determining if the current environment will support the project. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Anandi Hira, a data scientist on the SEI’s Software Engineering Measurement and Analysis team sits down with Bill Nichols, principal engineer and SEI data science team lead, to discuss software cost estimation including various metrics, best practices, and common challenges when developing or building a model.…

1 Cybersecurity Metrics: Protecting Data and Understanding Threats 27:00
27:00
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי27:00
One of the biggest challenges in collecting cybersecurity metrics is scoping down objectives and determining what kinds of data to gather. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Bill Nichols, who leads the SEI’s Software Engineering Measurements and Analysis Group, discusses the importance of cybersecurity measurement, what kinds of measurements are used in cybersecurity, and what those metrics can tell us about cyber systems.…

1 3 Key Elements for Designing Secure Systems 36:28
36:28
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי36:28
To make secure software by design a reality, engineers must intentionally build security throughout the software development lifecycle. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Timothy A. Chick, technical manager of the Applied Systems Group in the SEI’s CERT Division, discusses building, designing, and operating secure systems.…

1 Using Role-Playing Scenarios to Identify Bias in LLMs 45:07
45:07
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי45:07
Harmful biases in large language models (LLMs) make AI less trustworthy and secure. Auditing for biases can help identify potential solutions and develop better guardrails to make AI safer. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Katie Robinson and Violet Turri, researchers in the SEI’s AI Division, discuss their recent work using role-playing game scenarios to identify biases in LLMs.…
S
Software Engineering Institute (SEI) Podcast Series

1 The Product Manager’s Evolving Role in Software and Systems Development 24:19
24:19
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי24:19
In working with software and systems teams developing technical products, Judy Hwang, a senior software engineer in the SEI CERT Division, observed that teams were not investing the time, resources and effort required to manage the product lifecycle of a successful product. These activities include thoroughly exploring the problem space by talking to users, assessing existing solutions, understanding the competition, and positioning the product to create value for customers. In this podcast from the Carnegie Mellon University Software Engineering Institute, Hwang talks with principal researcher Suzanne Miller about the importance of implementing foundational product management principles in software and systems development and offers resources for audience members who looking to strengthen their Agile product delivery practices.…
S
Software Engineering Institute (SEI) Podcast Series

1 Measuring the Trustworthiness of AI Systems 19:27
19:27
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי19:27
The ability of artificial intelligence (AI) to partner with the software engineer, doctor, or warfighter depends on whether these end users trust the AI system to partner effectively with them and deliver the outcome promised. To build appropriate levels of trust, expectations must be managed for what AI can realistically deliver. In this podcast from the SEI’s AI Division, Carol Smith, a senior research scientist specializing in human-machine interaction, joins design researchers Katherine-Marie Robinson and Alex Steiner, to discuss how to measure the trustworthiness of an AI system as well as questions that organizations should ask before determining if it wants to employ a new AI technology.…
S
Software Engineering Institute (SEI) Podcast Series

1 Actionable Data in the DevSecOps Pipeline 31:58
31:58
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:58
In this podcast from the Carnegie Mellon University Software Engineering Institute, Bill Nichols and Julie Cohen talk with Suzanne Miller about how automation within DevSecOps product-development pipelines provides new opportunities for program managers (PMs) to confidently make decisions with the help of readily available data. As in commercial companies, DoD PMs are accountable for the overall cost, schedule, and performance of a program. The PM’s job is even more complex in large programs with multiple software-development pipelines where cost, schedule, performance, and risk for the products of each pipeline must be considered when making decisions, as well as the interrelationships among products developed on different pipelines. Nichols and Cohen discuss how PMs can collect and transform unprocessed DevSecOps development data into useful program-management information that can guide decisions they must make during program execution. The ability to continuously monitor, analyze, and provide actionable data to the PM from tools in multiple interconnected pipelines of pipelines can help keep the overall program on track.…
S
Software Engineering Institute (SEI) Podcast Series

1 Insider Risk Management in the Post-Pandemic Workplace 47:34
47:34
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי47:34
In the wake of the COVID pandemic, the workforce decentralized and shifted toward remote and hybrid environments. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Dan Costa, technical manager of enterprise threat and vulnerability management, and Randy Trzeciak, deputy director of Cyber Risk and Resilience, both with the SEI’s CERT Division, discuss how remote work in the post-pandemic world is changing expectations about employee behavior monitoring and insider risk detection.…
S
Software Engineering Institute (SEI) Podcast Series

1 An Agile Approach to Independent Verification and Validation 31:57
31:57
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:57
Independent verification and validation (IV&V) is a significant step in the process of deploying systems for mission-critical applications in the Department of Defense (DoD). In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Justin Smith, senior Agile transformation leader in the SEI Software Solutions Division, talks with principal researcher Suzanne Miller about how to bring concepts from Lean and Agile software development into the practice of IV&V. Smith describes his experiences at NASA’s Katherine Johnson IV&V Facility as a project manager for the Orion IV&V team. On that project, the developer employed Scaled Agile Framework (SAFe) as their development process, which had challenging consequences for established IV&V practices within NASA IV&V. Smith also discusses the ways in which NASA adapted to this change and describes strategies and tactics for reconciling Agile and IV&V.…
S
Software Engineering Institute (SEI) Podcast Series

1 Zero Trust Architecture: Best Practices Observed in Industry 27:53
27:53
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי27:53
Zero trust architecture has the potential to improve an enterprise’s security posture. There is still considerable uncertainty about the zero trust transformation process, however, as well as how zero trust architecture will ultimately appear in practice. Recent executive orders have accelerated the timeline for zero trust adoption in the federal sector, and many private-sector organizations are following suit. Researchers in the CERT Division at the Carnegie Mellon University Software Engineering Institute (SEI) hosted Zero Trust Industry Days to enable industry stakeholders to share information about implementing zero trust. In this SEI podcast, CERT researchers Matthew Nicolai and Nathaniel Richmond discuss five zero trust best practices identified during the two-day event, explain their significance, and provide commentary and analysis on ways to empower your organization’s zero trust transformation.…
S
Software Engineering Institute (SEI) Podcast Series

1 Automating Infrastructure as Code with Ansible and Molecule 39:38
39:38
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:38
In Ansible, roles allow system administrators to automate the loading of certain variables, tasks, files, templates, and handlers based on a known file structure. Grouping content by roles allows for easy sharing and reuse. When developing roles, users must deal with various concerns, including what operating system(s) and version(s) will be supported and whether a single node or a cluster of machines is needed. In this podcast from the Carnegie Mellon University Software Engineering Institute, Matthew Heckathorn, an integration engineer with the SEI’s CERT Division, offers guidance for systems engineers, system administrators, and others on developing Ansible roles and automating infrastructure as code.…
S
Software Engineering Institute (SEI) Podcast Series

1 Identifying and Preventing the Next SolarWinds 46:04
46:04
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי46:04
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Gregory J. Touhill, director of the SEI CERT Division, talks with principal researcher Suzanne Miller about the 2020 attack on Solar Winds software and how to prevent a recurrence of another major attack on key systems that are in widespread use. Solar Winds is the name of a company that provided software to the U.S. federal government. In late 2020, news surfaced about a cyberattack that had already been underway for several months and that had reportedly compromised 250 government agencies, including the Treasury Department, the State Department, and nuclear research labs. In addition to compromising data, the attack resulted in financial losses of more than $90 million and was probably one of the most dangerous modern attacks on software and software-based businesses and government agencies in the recent past. The SolarWinds incident demonstrated the challenges of securing systems when they are the product of complex supply chains. In this podcast, Touhill discusses topics including the need for systems to be secure by design and secure by default, the importance of transparency in the reporting of vulnerabilities and anomalous system behavior, the CERT Acquisition Security Framework, the need to secure data across a wide range of disparate devices and systems, and tactics and strategies for individuals and organizations to safeguard their data and the systems they rely on daily.…
S
Software Engineering Institute (SEI) Podcast Series

1 A Penetration Testing Findings Repository 25:47
25:47
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי25:47
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI) Marisa Midler and Samantha Chaves, penetration testers with the SEI’s CERT Division, talk with Suzanne Miller about a penetration-testing repository that they helped to build. The repository is a source of information for active directory, phishing, mobile technology, systems and services, web applications, and mobile- and wireless-technology weaknesses that could be discovered during a penetration test. The repository is intended to help assessors provide reports to organizations using standardized language and standardized names for findings, and to save assessors time on report generation by having descriptions, standard remediations, and other resources available in the repository for their use. The repository is available at https://github.com/cisagov/pen-testing-findings…
S
Software Engineering Institute (SEI) Podcast Series

1 Understanding Vulnerabilities in the Rust Programming Language 36:45
36:45
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי36:45
While the memory safety and security features of the Rust programming language can be effective in many situations, Rust’s compiler is very particular on what constitutes good software design practices. Whenever design assumptions disagree with real-world data and assumptions, there is the possibility of security vulnerabilities–and malicious software that can take advantage of those vulnerabilities. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), David Svoboda and Garret Wassermann, researchers with the SEI's CERT Division, explore tools for understanding vulnerabilities in Rust whether the original source code is available or not. These tools are important for understanding malicious software where source code is often unavailable, as well as commenting on possible directions in which tools and automated code analysis can improve.…
S
Software Engineering Institute (SEI) Podcast Series

1 We Live in Software: Engineering Societal-Scale Systems 39:31
39:31
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:31
Societal-scale software systems, such as today’s commercial social media platforms, are among the most widely used software systems in the world, with some platforms reporting billions of daily active users. These systems have created new mechanisms for global communication and connect people with unprecedented speed. Despite the numerous benefits of societal-scale systems, these systems are designed to optimize user engagement and scale by using psychology (such as gaming and reward mechanisms) to influence users. Individual users struggle with privacy of their data and bias in these systems, while governments face new threats of misinformation. In this podcast from the Carnegie Mellon University Software Engineering Institute, John Robert and Forrest Shull discuss issues that must be considered when engineering societal-scale systems.…
S
Software Engineering Institute (SEI) Podcast Series

1 Secure by Design, Secure by Default 54:05
54:05
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי54:05
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI) Gregory J. Touhill, director of the SEI CERT Division, talks with Suzanne Miller about secure by design, secure by default, a longstanding tenet of the work of the SEI and CERT in particular. The SEI has been in the forefront of secure software development, promoting an approach where security weaknesses are addressed, prevented, or eliminated earlier in the software development lifecycle, which not only helps to ensure secure systems, but also saves time and money. Touhill also discusses the CERT strategy in support of SEI sponsors in the U.S. Department of Defense (DoD), the Department of Homeland Security (DHS), and the Cybersecurity Infrastructure Security Agency (CISA) and his vision for the future of cybersecurity and the role of the CERT Division.…
S
Software Engineering Institute (SEI) Podcast Series

1 Key Steps to Integrate Secure by Design into Acquisition and Development 48:50
48:50
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי48:50
Secure by design means performing more security and assurance activities earlier in the product and system lifecycles. A secure-by-design mindset addresses the security of systems during the requirements, design, and development phases of lifecycles rather than waiting until the system is ready for implementation. The need for a secure-by-design mindset is exacerbated by the amount of interconnectedness of today’s systems and the increasing amount of automation that characterizes system development. These trends have led to increased levels of risk and made implementation of security controls during test and patching systems after deployment increasingly unsustainable. In this podcast from the Carnegie Mellon University Software Engineering Institute, Robert Schiela, technical manager of the Secure Coding group, and Carol Woody, a principal researcher in the SEI’s CERT Division, talk with Suzanne Miller about the importance of integrating the practices and mindset of secure by design into the acquisition and development of software-reliant systems.…
S
Software Engineering Institute (SEI) Podcast Series

1 An Exploration of Enterprise Technical Debt 25:56
25:56
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי25:56
Like all technical debt, enterprise technical debt consists of choices expedient in the short term, but often problematic over the long term. In enterprise technical debt, the impact reaches beyond the scope of a single system or project. Because ignoring enterprise technical debt can have significant consequences, software and systems architects should be alert for it, and they should not let it get overlooked or ignored when they come across it. Enterprise technical debt often results in multi-project or organization-wide risks that increase the organization’s cost, efficiency, or security risks. Remediation of enterprise technical debt requires intervention by governance structures whose scope is broader than that of individual teams or projects. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Stephany Bellomo, a principal engineer in the SEI’s Software Solutions Division, talks with principal researcher Suzanne Miller about identifying and remediating enterprise technical debt.…
S
Software Engineering Institute (SEI) Podcast Series

1 The Messy Middle of Large Language Models 33:46
33:46
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי33:46
The recent growth of applications that leverage large language models, including ChatGPT and Copilot, has spurred reactions ranging from fear and uncertainty to adoration and lofty expectations. In this podcast from the Carnegie Mellon University Software Engineering Institute, Jay Palat, senior engineer and technical director of AI for mission, and Dr. Rachel Dzombak, senior advisor to the director of the SEI’s AI Division, discuss the current landscape of large language models (LLMs), common misconceptions about LLMs, how to leverage tools built on top of LLMs, and the need for critical thinking around both the outputs of the tools and the trends in their use.…
S
Software Engineering Institute (SEI) Podcast Series

1 Best Practices and Lessons Learned in Standing Up an AISIRT 38:29
38:29
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי38:29
In the wake of widespread adoption of artificial intelligence (AI) in critical infrastructure, education, government, and national security entities, adversaries are working to disrupt these systems and attack AI-enabled assets. With nearly four decades in vulnerability management, the Carnegie Mellon University Software Engineering Institute (SEI) recognized a need to create an entity that would identify, research, and identify mitigation strategies for AI vulnerabilities to protect national assets against traditional cybersecurity, adversarial machine learning, and joint cyber-AI attacks. In this SEI podcast, Lauren McIlvenny, director of threat analysis in the SEI’s CERT Division, discusses best practices and lessons learned in standing up an AI Security Incident Response Team (AISIRT).…
S
Software Engineering Institute (SEI) Podcast Series

1 3 API Security Risks (and How to Protect Against Them) 19:28
19:28
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי19:28
The exposed and public nature of application programming interfaces (APIs) come with risks including the increased network attack surface. Zero trust principles are helpful for mitigating these risks and making APIs more secure. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), McKinley Sconiers-Hasan, a solutions engineer in the SEI CERT Division, discusses three API risks and how to address them through the lens of zero trust.…
S
Software Engineering Institute (SEI) Podcast Series

1 Evaluating Large Language Models for Cybersecurity Tasks: Challenges and Best Practices 43:05
43:05
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי43:05
How can we effectively use large language models (LLMs) for cybersecurity tasks? In this Carnegie Mellon University Software Engineering Institute podcast, Jeff Gennari and Sam Perl discuss applications for LLMs in cybersecurity, potential challenges, and recommendations for evaluating LLMs.
S
Software Engineering Institute (SEI) Podcast Series

1 Capability-based Planning for Early-Stage Software Development 33:55
33:55
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי33:55
Capability-Based Planning (CBP) defines a framework that has an all-encompassing view of existing abilities and future needs for strategically deciding what is needed and how to effectively achieve it. Both business and government acquisition domains use CBP for financial success or to design a well-balanced defense system. The definitions understandably vary across these domains. In this SEI podcast, Anandi Hira, a data scientist, and William R. Nichols, an initiative lead for Software Engineering Measurement and Analysis, introduce CBP and its use and application in software acquisition.…
S
Software Engineering Institute (SEI) Podcast Series

1 Safeguarding Against Recent Vulnerabilities Related to Rust 26:25
26:25
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי26:25
What can the recently discovered vulnerabilities related to Rust tell us about the security of the language? In this podcast from the Carnegie Mellon University Software Engineering Institute, David Svoboda discusses two vulnerabilities, their sources, and how to mitigate them.
S
Software Engineering Institute (SEI) Podcast Series

1 Developing a Global Network of Computer Security Incident Response Teams (CSIRTs) 30:51
30:51
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי30:51
Cybersecurity risks aren’t just a national concern. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), the CERT division’s Tracy Bills, senior cybersecurity operations researcher and team lead, and James Lord, security operations technical manager, discuss the SEI’s work developing Computer Security Incident Response Teams (CSIRTs) across the globe.…
S
Software Engineering Institute (SEI) Podcast Series

1 Automated Repair of Static Analysis Alerts 27:05
27:05
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי27:05
Developers know that static analysis helps make code more secure. However, static analysis tools often produce a large number of false positives, hindering their usefulness. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), David Svoboda, a software security engineer in the SEI’s CERT Division, discusses Redemption, a new open source tool from the SEI that automatically repairs common errors in C/C++ code generated from static analysis alerts, making code safer and static analysis less overwhelming.…
S
Software Engineering Institute (SEI) Podcast Series

1 Developing and Using a Software Bill of Materials Framework 37:37
37:37
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי37:37
With the increasing complexity of software systems, the use of third-party components has become a widespread practice. Cyber disruptions, such as SolarWinds and Log4j, demonstrate the harm that can occur when organizations fail to manage third-party components in their software systems. In this podcast from the Carnegie Mellon University Software Engineering Institute, Carol Woody, principal researcher, and Michael Bandor, a senior software engineer, discuss a Software Bill of Materials (SBOMs) framework to help promote the use of SBOMs and establish a more comprehensive set of practices and processes that organizations can leverage as they build their programs. They also offer guidance for government agencies who are interested in incorporating SBOMs into their work.…
S
Software Engineering Institute (SEI) Podcast Series

1 Using Large Language Models in the National Security Realm 34:45
34:45
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי34:45
At the request of the White House, the Office of the Director of National Intelligence (ODNI) began exploring use cases for large language models (LLMs) within the Intelligence Community (IC). As part of this effort, ODNI sponsored the Mayflower Project at Carnegie Mellon University’s Software Engineering Institute (SEI) from May 2023 through September 2023. The Mayflower Project attempted to answer the following questions: How might the IC set up a baseline, stand-alone LLM? How might the IC customize LLMs for specific intelligence use cases? How might the IC evaluate the trustworthiness of LLMs across use cases? In this SEI Podcast, Shannon Gallagher, AI engineering team lead, and Rachel Dzombak, special advisor to the director of the SEI’s AI Division, discuss the findings and recommendations from the Mayflower Project and provides additional background information about LLMs and how they can be engineered for national security use cases.…
S
Software Engineering Institute (SEI) Podcast Series

1 Atypical Applications of Agile and DevSecOps Principles 33:41
33:41
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי33:41
Modern software engineering practices of Agile and DevSecOps have provided a foundation for producing working software products faster and more reliably than ever before. Far too often, however, these practices do not address the non-software concerns of business mission and capability delivery even though these concerns are critical to the successful delivery of a software product. Through our work with government organizations, we have found that expanding DevSecOps beyond product development enables other teams to increase their capabilities and improve their processes. Agile methodologies are also being used for complex system and hardware developments. In this podcast from the Carnegie Mellon University Software Engineering Institute, Lyndsi Hughes, a senior systems engineer and David Sweeney, an associate software developer, both with the SEI CERT Division, share their experiences leveraging DevSecOps pipelines in atypical situations in support of teams focused on the capability delivery and business mission for their organizations.…
S
Software Engineering Institute (SEI) Podcast Series

1 When Agile and Earned Value Management Collide: 7 Considerations for Successful Interaction 35:21
35:21
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:21
Increasingly in government acquisition of software-intensive systems, we are seeing programs using Agile development methodology and earned value management. While there are many benefits to using both Agile and EVM, there are important considerations that software program managers must first address. In this podcast, Patrick Place, a senior engineer, and Stephen Wilson, a test engineer, both with the SEI Agile Transformation Team, discuss seven considerations for successful use of Agile and EVM.…
S
Software Engineering Institute (SEI) Podcast Series

1 The Impact of Architecture on Cyber-Physical Systems Safety 34:05
34:05
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי34:05
As developers continue to build greater autonomy into cyber-physical systems (CPSs), such as unmanned aerial vehicles (UAVs) and automobiles, these systems aggregate data from an increasing number of sensors. However, more sensors not only create more data and more precise data, but they require a complex architecture to correctly transfer and process multiple data streams. This increase in complexity comes with additional challenges for functional verification and validation, a greater potential for faults, and a larger attack surface. What’s more, CPSs often cannot distinguish faults from attacks. To address these challenges, researchers from the SEI and Georgia Tech collaborated on an effort to map the problem space and develop proposals for solving the challenges of increasing sensor data in CPSs. In this podcast from the Carnegie Mellon University Software Engineering Institute, Jerome Hugues, a principal researcher in the SEI Software Solutions Division, discusses this collaboration and its larger body of work, Safety Analysis and Fault Detection Isolation and Recovery (SAFIR) Synthesis for Time-Sensitive Cyber-Physical Systems.…
S
Software Engineering Institute (SEI) Podcast Series

1 ChatGPT and the Evolution of Large Language Models: A Deep Dive into 4 Transformative Case Studies 46:22
46:22
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי46:22
To better understand the potential uses of large language models (LLMs) and their impact, a team of researchers at the Carnegie Mellon University Software Engineering Institute CERT Division conducted four in-depth case studies. The case studies span multiple domains and call for vastly different capabilities. In this podcast, Matthew Walsh, a senior data scientist in CERT, and Dominic Ross, Multi-Media Design Team lead, discuss their work in developing the four case studies as well as limitations and future uses of ChatGPT.…
S
Software Engineering Institute (SEI) Podcast Series

1 The Cybersecurity of Quantum Computing: 6 Areas of Research 23:01
23:01
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי23:01
Research and development of quantum computers continues to grow at a rapid pace. The U.S. government alone spent more than $800 million on quantum information science research in 2022. Thomas Scanlon, who leads the data science group in the SEI CERT Division, was recently invited to be a participant in the Workshop on Cybersecurity of Quantum Computing , co-sponsored by the National Science Foundation (NSF) and the White House Office of Science and Technology Policy, to examine the emerging field of cybersecurity for quantum computing. In this podcast from the Carnegie Mellon University Software Engineering Institute, Scanlon discusses how to create the discipline of cyber protection of quantum computing and outlines six areas of future research in quantum cybersecurity.…
S
Software Engineering Institute (SEI) Podcast Series

Far too often software programs continue to collect metrics for no other reason than that is how it has always been done. This leads to situations where, for any given environment, a metrics program is defined by a list of metrics that must be collected. A top-down, deterministic specification of graphs or other depictions of data required by the metrics program can distract participants from the potentially useful information that the metrics reveal and illuminate. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Will Hayes, who leads the Agile Transformation Team, and Patrick Place, a principal engineer on that team, discuss with principal researcher Suzanne Miller, how user stories can help put development in the context of who is using the system and lead to a conversation about why a specific metric is being collected.…
S
Software Engineering Institute (SEI) Podcast Series

1 A Discussion on Automation with Watts Humphrey Award Winner Rajendra Prasad 37:17
37:17
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי37:17
In this SEI Podcast, Mike Konrad, a principal researcher in the SEI's Software Solutions Division, talks with 2020 IEEE Computer Society SEI Watts Humphrey Software Quality Award winner Rajendra Prasad of Accenture about automation and how SEI-developed process improvement methods and tools provided the foundation for his leadership role.…
S
Software Engineering Institute (SEI) Podcast Series

1 Enabling Transition From Sustainment to Engineering Within the DoD 31:22
31:22
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:22
Organic software sustainment organizations within the Department of Defense are expanding beyond their traditional purview of software maintenance into software engineering and development. Instead of repairing and maintaining legacy software in already deployed systems, software sustainment teams must now shift to designing and implementing new software architectures and code. Unfortunately, many of these sustainment teams are taking on these new responsibilities without proper guidance and an understanding of the people, process, and technology issues that must first be addressed in these new roles. In this podcast, Thomas Evans, a senior software architect at the SEI, and Douglas C. Schmidt, associate provost of research at Vanderbilt University and former chief technical officer at the SEI, discuss the challenges that software sustainment teams face while making this transition and strategies for success.…
S
Software Engineering Institute (SEI) Podcast Series

1 The Silver Thread of Cyber in the Global Supply Chain 26:56
26:56
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי26:56
The global supply chain touches every aspect of our lives, from fuel prices to the availability of computer chips and supermarket products. In out latest podcast, Matt Butkovic, technical director of risk and resilience at Carnegie Mellon University’s Software Engineering Institute , discusses with Suzanne Miller the supply chain's silver thread of cyber, specifically how cyber both underpins the cyber supply chain and the broader supply chain. Butkovic’s team recently engaged with the World Economic Forum to create an online transformation map, a set of connected topics defining a specific domain of interest. In this episode, Butkovic also discusses work on this map, the importance of cyber resilience, and how to determine the resilience your organization needs and the resilience it currently possesses.…
S
Software Engineering Institute (SEI) Podcast Series

1 Measuring DevSecOps: The Way Forward 39:32
39:32
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:32
In this SEI Podcast, Bill Nichols and Hasan Yasar, both with the Carnegie Mellon University Software Engineering Institute, discuss DevSecOps metrics with Suzanne Miller. DevSecOps practices, made possible by improvements in underlying technology that automate the development-to-production pipeline, can generate more information about development and operational performance than has ever been readily available before. Nichols and Yasar discuss the ways in which DevSecOps practices yield valuable information about software performance that is likely to lead to innovations in software engineering metrics.…
S
Software Engineering Institute (SEI) Podcast Series

1 Bias in AI: Impact, Challenges, and Opportunities 24:58
24:58
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי24:58
In this podcast from the Carnegie Mellon University Software Engineering Institute, Carol Smith, a senior research scientist in human-machine interaction, and Jonathan Spring, a senior vulnerability researcher, discuss the hidden sources of bias in artificial intelligence (AI) systems and how systems developers can raise their awareness of bias, mitigate consequences, and reduce risks.…
S
Software Engineering Institute (SEI) Podcast Series

1 Agile Strategic Planning: Concepts and Methods for Success 29:50
29:50
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי29:50
The rapid pace of change in software development, in business, and in the world has many organizations struggling to execute daily operations, wrangle big projects, and feel confident that there is a long-term strategy at play. Incorporating agile principles into strategic planning and execution is a highly effective way to drive strategy development, strategy execution, data-driven decision making, and results. In this SEI Podcast, Linda Parker Gates, initiative lead, Software Acquisition Pathways, and Suzanne Miller, principal researcher in the SEI’s Software Solutions Division, discuss the principles of Agile Strategic Planning and methods for success.…
S
Software Engineering Institute (SEI) Podcast Series

1 Applying Scientific Methods in Cybersecurity 39:49
39:49
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי39:49
In this SEI Podcast, Dr. Leigh Metcalf and Dr. Jonathan Spring, both researchers with the Carnegie Mellon University Software Engineering Institute’s CERT Division, discuss the application of scientific methods to cybersecurity. As described in their recently published book, Using Science in Cybersecurity , Metcalf and Spring describe a common-sense approach and practical tools for applying scientific rigor to the field of cybersecurity.…
S
Software Engineering Institute (SEI) Podcast Series

1 Zero Trust Adoption: Benefits, Applications, and Resources 30:25
30:25
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי30:25
Zero trust adoption is a security initiative that an enterprise must understand, interpret, and implement. Enterprise security initiatives are never simple, and their goal to improve cybersecurity posture requires the alignment of multiple stakeholders, systems, acquisitions, and exponentially changing technology. This alignment is always a complex undertaking and requires cybersecurity strategy and engineering to succeed. In this SEI Podcast, Geoff Sanders, a senior network defense analyst in the CERT Division at Carnegie Mellon University's Software Engineering Institute, discusses zero trust adoption and its benefits, applications, and available resources.…
S
Software Engineering Institute (SEI) Podcast Series

1 Uncertainty Quantification in Machine Learning: Measuring Confidence in Predictions 31:40
31:40
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:40
In this SEI Podcast, Dr. Eric Heim, a senior machine learning research scientist at Carnegie Mellon University's Software Engineering Institute (SEI), discusses the quantification of uncertainty in machine-learning (ML) systems. ML systems can make wrong predictions and give inaccurate estimates for the uncertainty of their predictions. It can be difficult to predict when their predictions will be wrong. Heim also discusses new techniques to quantify uncertainty, identify causes of uncertainty, and efficiently update ML models to reduce uncertainty in their predictions. The work of Heim and colleagues at the SEI Emerging Technology Center closes the gap between the scientific and mathematical advances from the ML research community and the practitioners who use the systems in real-life contexts, such as software engineers, software developers, data scientists, and system developers.…
S
Software Engineering Institute (SEI) Podcast Series

1 11 Rules for Ensuring a Security Model with AADL and Bell–LaPadula
48:05
48:05
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי48:05
In this SEI Podcast, Aaron Greenhouse, a senior architecture researcher with Carnegie Mellon University’s Software Engineering Institute, talks with principal researcher Suzanne Miller about use of the Bell–LaPadula mathematical security model in concert with the Architecture Analysis and Design Language (AADL) to model and validate confidentiality. Greenhouse and Miller also discuss 11 analysis rules that must be enforced over an AADL instance to ensure the consistency of a security model. Mapping Bell–LaPadula to AADL allows the expression of key concepts within the AADL model so that they can be analyzed automatically.…
S
Software Engineering Institute (SEI) Podcast Series

1 Benefits and Challenges of Model-Based Systems Engineering 33:10
33:10
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי33:10
Nataliya (Natasha) Shevchenko and Mary Popeck, both senior researchers in the CERT Division at Carnegie Mellon University’s Software Engineering Institute, discuss the use of model-based systems engineering (MBSE), which, in contrast to document-centric engineering, puts models at the center of system design. MBSE is used to support the requirements, design, analysis, verification, and validation associated with the development of complex systems.…
S
Software Engineering Institute (SEI) Podcast Series

1 Can DevSecOps Make Developers Happier? 41:17
41:17
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי41:17
Author Daniel H. Pink recently examined the factors that lead to job satisfaction among knowledge workers and summarized them in three components: autonomy, skill mastery, and purpose. In this SEI Podcast, Hasan Yasar, technical director of Continuous Deployment of Capability at Carnegie Mellon University’s Software Engineering Institute, relates these components to DevSecOps and summarizes a recent survey affirming that DevSecOps practices do indeed make developers and other stakeholders in their organizations happier.…
S
Software Engineering Institute (SEI) Podcast Series

1 Is Your Organization Ready for AI? 30:20
30:20
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי30:20
In this SEI Podcast, digital transformation lead Dr. Rachel Dzombak and research scientist Carol Smith, both with the SEI’s Emerging Technology Center at Carnegie Mellon University, discuss how AI Engineering can support organizations to implement AI systems. The conversation covers the steps that organizations need to take (as well as the hard conversations that need to occur) before they are AI ready.…
S
Software Engineering Institute (SEI) Podcast Series

1 Managing Vulnerabilities in Machine Learning and Artificial Intelligence Systems 40:59
40:59
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי40:59
The robustness and security of artificial intelligence, and specifically machine learning (ML), is of vital importance. Yet, ML systems are vulnerable to adversarial attacks. These can range from an attacker attempting to make the ML system learn the wrong thing (data poisoning), do the wrong thing (evasion attacks), or reveal the wrong thing (model inversion). Although there are several efforts to provide detailed taxonomies of the kinds of attacks that can be launched against a machine learning system, none are organized around operational concerns. In this podcast, Jonathan Spring, Nathan VanHoudnos, and Allen Householder, all researchers at the Carnegie Mellon University Software Engineering Institute, discuss the management of vulnerabilities in ML systems as well as the Adversarial ML Threat Matrix, which aims to close this gap between academic taxonomies and operational concerns.…
S
Software Engineering Institute (SEI) Podcast Series

In this SEI Podcast, Rachel Dzombak and Jay Palat discuss growth in the field of artificial intelligence (AI) and how organizations can hire and train staff to take advantage of the opportunities afforded by AI and machine learning—and the critical need for an AI engineering discipline to grow the AI workforce.…
S
Software Engineering Institute (SEI) Podcast Series

1 An Infrastructure-Focused Framework for Adopting DevSecOps 43:35
43:35
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי43:35
DevSecOps practices, including continuous-integration/continuous-delivery (CI/CD) pipelines, enable organizations to respond to security and reliability events quickly and efficiently and to produce resilient and secure software on a predictable schedule and budget. Despite growing evidence and recognition of the efficacy and value of these practices, the initial implementation and ongoing improvement of the methodology can be challenging. In this podcast from the Carnegie Mellon University Software Engineering Institute, senior engineers Vanessa Jackson and Lyndsi Hughes discuss with principal researcher Suzanne Miller the DevSecOps adoption framework, which guides organizations in the planning and implementation of a roadmap to functional CI/CD pipeline capabilities.…
S
Software Engineering Institute (SEI) Podcast Series

Rust is growing in popularity. Its unique security model promises memory safety and concurrency safety, while providing the performance of C/C++. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), David Svoboda and Joe Sible, both engineers in the SEI’s CERT Division, talk with principal researcher Suzanne Miller about the Rust programming language and its security-related features. Svoboda and Sible discuss Rust’s compile-time safety guarantees, the kinds of vulnerabilities that Rust fixes and those that it does not, situations in which users would not want to use Rust, and where interested users can go to get more information about the Rust programming language.…
S
Software Engineering Institute (SEI) Podcast Series

1 Improving Interoperability in Coordinated Vulnerability Disclosure with Vultron 51:16
51:16
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי51:16
Coordinated vulnerability disclosure (CVD) begins when at least one individual becomes aware of a vulnerability, but it can’t proceed without the cooperation of many. Software supply chains, software libraries, and component vulnerabilities have evolved in complexity and have become as much a part of the CVD process as vulnerabilities in vendors’ proprietary code. Many CVD cases now require coordination across multiple vendors. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Allen Householder, a senior vulnerability and incident researcher in the SEI’s CERT Division, talks with principal researcher Suzanne Miller about Vultron , a protocol for multi-party coordinated vulnerability disclosure (MPCVD).…
S
Software Engineering Institute (SEI) Podcast Series

1 Asking the Right Questions to Coordinate Security in the Supply Chain 31:11
31:11
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:11
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Dr. Carol Woody, a principal researcher in the SEI's CERT Division, talks with Suzanne Miller about the SEI’s newly released Acquisition Security Framework, which helps programs coordinate the management of engineering and supply-chain risks across system components including hardware, network interfaces, software interfaces, and mission capabilities.…
S
Software Engineering Institute (SEI) Podcast Series

1 Securing Open Source Software in the DoD 35:33
35:33
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי35:33
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Scott Hissam, a researcher within the SEI’s Software Solutions Division who works on software assurance in Department of Defense (DoD) systems, talks with Linda Parker Gates, initiative lead for the SEI’s Software Acquisition Pathways, about the use of free and open-source software (FOSS) in the DoD, building on insights that surfaced in a recent workshop held for producers and consumers of FOSS for DoD systems.…
S
Software Engineering Institute (SEI) Podcast Series

1 A Model-Based Tool for Designing Safety-Critical Systems 48:43
48:43
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי48:43
In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Dr. Sam Procter and Lutz Wrage, researchers with the SEI, discuss the Guided Architecture Trade Space Explorer (GATSE), a new SEI-developed model-based tool to help with the design of safety-critical systems. The GATSE tool allows engineers to evaluate more design options in less time than they can now. This prototype language extension and software tool partially automates the process of model-based systems engineering so that systems engineers can rapidly explore combinations of different design options.…
S
Software Engineering Institute (SEI) Podcast Series

1 Managing Developer Velocity and System Security with DevSecOps 32:55
32:55
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי32:55
In aiming for correctness and security of product, as well as for development speed, software development teams often face tension in their objectives. During a recent customer engagement that involved the development of a continuous-integration (CI) pipeline, developers wanted to develop features and deploy to production, deferring non-critical bugs as technical debt, whereas cyber engineers wanted compliant software by having the pipeline fail on any security requirement that was not met. In this podcast from the Carnegie Mellon University Software Engineering Institute (SEI), Alejandro Gomez, a researcher in the SEI’s CERT Division who worked on the customer project, talked with principal researcher Suzanne Miller about how the team explored—and eventually resolved—the two competing forces of developer velocity and cybersecurity enforcement by implementing DevSecOps practices.…
S
Software Engineering Institute (SEI) Podcast Series

1 A Method for Assessing Cloud Adoption Risks 21:47
21:47
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי21:47
The shift to a cloud environment provides significant benefits. Cloud resources can be scaled quickly, updated frequently, and widely accessed without geographic limitations. Realizing these benefits, however, requires organizations to manage associated organizational and technical risks. In this podcast from the Carnegie Mellon University Software Engineering Institute, Chris Alberts, principal cybersecurity analyst in the SEI’s CERT Division, discusses with principal researcher Suzanne Miller a prototype set of cloud adoption risk factors and describes a method that managers can employ to assess their cloud initiatives against these risk factors.…
S
Software Engineering Institute (SEI) Podcast Series

1 Software Architecture Patterns for Deployability 29:09
29:09
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי29:09
Competitive pressures in many domains, as well as development paradigms such as Agile and DevSecOps , have led to the increasingly common practice of continuous delivery or continuous deployment where frequent updates to software systems are rapidly and reliably fielded. In today’s systems, releases can occur at any time—possibly hundreds of releases per day—and each can be instigated by a different team within an organization. Being able to release frequently means that bug fixes and security patches do not have to wait until the next scheduled release, but rather can be made and released as soon as a bug is discovered and fixed. It also means that new features can be put into production at any time and don’t have to wait to be bundled into a release. In this podcast, Rick Kazman, an SEI visiting scientist and coauthor of Software Architecture in Practice , talks with principal researcher Suzanne Miller about using patterns for software deployability. These patterns fall into two broad categories: complete replacement of services and canary testing.…
S
Software Engineering Institute (SEI) Podcast Series

1 ML-Driven Decision Making in Realistic Cyber Exercises 48:58
48:58
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי48:58
In this podcast from the Carnegie Mellon University Software Engineering Institute, Thomas Podnar and Dustin Updyke, both senior cybersecurity engineers with the SEI’s CERT Division, discuss their work to apply machine learning to increase the realism of non-player characters (NPCs) in cyber training exercises.…
S
Software Engineering Institute (SEI) Podcast Series

1 A Roadmap for Creating and Using Virtual Prototyping Software 56:30
56:30
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי56:30
In this podcast from the Carnegie Mellon University Software Engineering Institute, Douglass Post and Richard Kendall, authors of "Creating and Using Virtual Prototyping Software: Principles and Practices" discuss with principal researcher Suzanne Miller experiences and insights that they gleaned from applying virtual prototyping in CREATE (Computational Research and Engineering Acquisition Tools and Environments), a multiyear DoD program to develop and deploy software for systems like ships, air vehicles, ground vehicles, and radio-frequency antennas. CREATE enabled engineers and scientists to design these complex systems and to accurately predict their performance.…
S
Software Engineering Institute (SEI) Podcast Series

1 Software Architecture Patterns for Robustness 31:13
31:13
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי31:13
In this podcast from the Carnegie Mellon University Software Engineering Institute, visiting scientist Rick Kazman and principal researcher Suzanne Miller discuss software architecture patterns and the effect that certain architectural patterns have on quality attributes, such as availability and robustness. Kazman also provides examples of mechanisms—such as architectural tactics and patterns—and the effects they have on availability and robustness, especially in cloud-based systems.…
S
Software Engineering Institute (SEI) Podcast Series

1 A Platform-Independent Model for DevSecOps 23:41
23:41
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי23:41
DevSecOps encompasses all the best software engineering principles known today with an emphasis on faster delivery through increased collaboration of all stakeholders resulting in more secure, useable, and higher-quality software systems. In this podcast from the Carnegie Mellon University Software Engineering Institute, researchers Tim Chick and Joe Yankel present a DevSecOps Platform-Independent Model (PIM), which uses model based systems engineering (MBSE) to formalize the practices of DevSecOps pipelines and organize relevant guidance. This first-of-its-kind model gives software development enterprises the structure and articulation needed for creating, maintaining, securing, and improving DevSecOps pipelines.…
S
Software Engineering Institute (SEI) Podcast Series

1 Using the Quantum Approximate Optimization Algorithm (QAOA) to Solve Binary-Variable Optimization Problems 27:36
27:36
הפעל מאוחר יותר
הפעל מאוחר יותר
רשימות
לייק
אהבתי27:36
In this podcast from the Carnegie Mellon University Software Engineering Institute, Jason Larkin and Daniel Justice, researchers in the SEI’s AI Division, discuss a paper outlining their efforts to simulate the performance of Quantum Approximate Optimization Algorithm (QAOA) for the Max-Cut problem and compare it with some of the best classical alternatives, for exact, approximate, and heuristic solutions.…
S
Software Engineering Institute (SEI) Podcast Series

To ensure trust, artificial intelligence systems need to be built with fairness, accountability, and transparency at each step of the development cycle. In this podcast from the Carnegie Mellon University Software Engineering Institute, Carol Smith, a senior research scientist in human machine interaction, and Dustin Updyke, a senior cybersecurity engineering in the SEI’s CERT Division, discuss the construction of trustworthy AI systems and factors influencing human trust of AI systems.…
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.