Loading…
October 8, 2026 | Prague, Czechia
View More Details & Registration  |  Note: The schedule is subject to change.
You must be registered for Linux Security Summit Europe 2026 to participate in the sessions. Please visit the event registration page to purchase a ticket. 
Thursday, October 8
 

08:00 CEST

Registration & Badge Pick-up
Thursday October 8, 2026 08:00 - 17:40 CEST

Thursday October 8, 2026 08:00 - 17:40 CEST
Congress Hall Foyer 0A (Floor 0)

09:00 CEST

Welcome & Opening Remarks - Elena Reshetova, Intel
Thursday October 8, 2026 09:00 - 09:05 CEST

Speakers
avatar for Elena Reshetova

Elena Reshetova

Security Architect, Intel

Thursday October 8, 2026 09:00 - 09:05 CEST
Chamber Hall (Floor 3)

09:05 CEST

Security Implications of Kernel Electric Fence - Ernesto Martínez García, Graz University of Technology
Thursday October 8, 2026 09:05 - 09:50 CEST
With the continued rise of kernel heap vulnerabilities, the Linux kernel community has done substantial effort in hardening the slab allocator through defense-in-depth mechanisms. Modern hardened kernels now rely on a combination of allocator-level protections, including type and size segregation, randomization, memory tagging, and others. These mechanisms significantly raise the bar for...
See More →
Speakers
avatar for Ernesto Martínez García

Ernesto Martínez García

PhD Student, Graz University of Technology
Ernesto is a PhD student at the Graz University of Technology.
He's part of the Secure Systems group at the Institute of Information Security (ISEC), formerly IAIK.
Currently focuses on finding side-channel attacks on various Linux kernel mechanisms, such as KFENCE and KSM.
Pl... Read More →
Thursday October 8, 2026 09:05 - 09:50 CEST
Chamber Hall (Floor 3)

09:55 CEST

Update on Landlock: Scoping, Thread Synchronization, Networking and More - Mickaël Salaün, Cloudflare & Günther Noack, Google Switzerland
Thursday October 8, 2026 09:55 - 10:40 CEST
Landlock gained a few interesting features to restrict more operations. We'll explain unix socket restrictions, signal scoping, thread synchronization support, and UDP control. We'll also walk through some lesser known Linux features that make such restrictions sometimes challenging to properly handle. Finally, we'll talk about ongoing developments and the roadmap.
Speakers
avatar for Mickaël Salaün

Mickaël Salaün

Systems Engineer, Cloudflare
Mickaël Salaün is a kernel developer and open source enthusiast. He is mainly interested in Linux-based operating systems, especially from a security point of view. He has built security sandboxes before hacking into the kernel on a new LSM called Landlock, of which he is now the... Read More →
avatar for Günther Noack

Günther Noack

Staff Software Engineer, Google Switzerland
Günther Noack is a software engineer at Google, where he works on security things. He has contributed to Landlock in the kernel since 2022 and maintains the Landlock Go library. In his free time, he enjoys running and swimming.
Thursday October 8, 2026 09:55 - 10:40 CEST
Chamber Hall (Floor 3)

10:40 CEST

Morning Break
Thursday October 8, 2026 10:40 - 11:00 CEST

Thursday October 8, 2026 10:40 - 11:00 CEST
Chamber Hall (Floor 3)

11:00 CEST

Extending TPM Trust From the Kernel To Userspace - James Bottomley, Microsoft
Thursday October 8, 2026 11:00 - 11:45 CEST
The kernel uses a novel null seed scheme to protect the security of TPM communications against interposers as well as detect TPM reset attacks. Since the kernel can't verify the null seed on its own, the name of the derived key is projected up to userspace to be verified there. However, this verification can be done once on boot and lasts until the next reboot meaning any userspace...
See More →
Speakers
avatar for James Bottomley

James Bottomley

Partner Architect, Microsoft
James Bottomley is a Partner Architect at Microsoft working on Linux.
He is also Linux Kernel maintainer of the SCSI subsystem. He started
at AT&T Bell labs to work on Lock Manager technology for
clustering. In 2000 he helped found SteelEye Technology to bring HA to
Linux, be... Read More →
Thursday October 8, 2026 11:00 - 11:45 CEST
Chamber Hall (Floor 3)

11:50 CEST

Libturnstile: Unprivileged Interactive Sandboxing From Seccomp-unotify To Landlock Supervise - Tingmao Wang, Microsoft
Thursday October 8, 2026 11:50 - 12:35 CEST
Existing unprivileged sandboxing solutions often rely on fixed rulesets without the ability to discover and dynamically approve additional accesses. Today, there is no kernel API that supports this and is designed specifically for use by sandboxing tools or other integrated use cases like package managers or code editors. Over the past year, I have pursued a solution to this from two angles: a...
See More →
Speakers
avatar for Tingmao Wang

Tingmao Wang

Software Engineer, Microsoft
I'm a software engineer with a keen interest in security and the Linux kernel. At Microsoft, I work on Confidential Computing topics and Azure Container Instances. Outside of work, I have contributed to Landlock and 9pfs, and I'm continuing to progress the Landlock supervise project... Read More →
Thursday October 8, 2026 11:50 - 12:35 CEST
Chamber Hall (Floor 3)

12:35 CEST

Lunch Break
Thursday October 8, 2026 12:35 - 13:35 CEST

Thursday October 8, 2026 12:35 - 13:35 CEST
Chamber Hall (Floor 3)

13:35 CEST

Analyzing & Comparing MAC Policy - John Johansen & Georgia Garcia, Canonical
Thursday October 8, 2026 13:35 - 14:20 CEST
Different LSMs have different approaches to how they implement MAC policy. This session aims to present an analysis and comparison of Apparmor and SELinux approaches by transforming their policy into a common regular language. Using finite state analysis and transitive closure to find commonalities and differences between the different types of policy. We will discuss the approach used for the...
See More →
Speakers
avatar for John Johansen

John Johansen

Security Engineer, Canonical
John Johansen began working with open source software in the late 80s and began playing with Linux in 93. He completed a masters in mathematics at the University of Waterloo and the began working for Immunix doing compiler hardening, and then AppArmor. After Immunix was acquired by... Read More →
avatar for Georgia Garcia

Georgia Garcia

Software Engineer, Canonical
Georgia Garcia is a software engineer at Canonical and co-maintainer of the AppArmor project, specializing in Linux operating system security across both kernel space and userspace.
Thursday October 8, 2026 13:35 - 14:20 CEST
Chamber Hall (Floor 3)

14:25 CEST

Who Watches the Watcher? Hardening eBPF in Production Security Deployments - Hanshal Mehta, Independent
Thursday October 8, 2026 14:25 - 14:55 CEST
eBPF has become the backbone of modern Linux security tooling. Cilium, Tetragon, Falco, etc they all depend on eBPF's ability to hook kernel execution paths and enforce policy without a kernel patch or reboot. But there's a question the community has been slow to ask: who secures eBPF itself? Working on bpfman, an eBPF program manager, exposed me to the trust assumptions baked into how programs...
See More →
Speakers
avatar for Hanshal Mehta

Hanshal Mehta

Open Source Developer, Self
Open-source developer contributing to projects across the cloud-native and security space including OpenTelemetry, bpfman, Glasskube, Cyclops, and BuildSafe. Currently at SecurableAI working on open-source security tooling. Deep interest in performance engineering, cloudsecurity... Read More →
Thursday October 8, 2026 14:25 - 14:55 CEST
Chamber Hall (Floor 3)

15:00 CEST

Making AppArmor Confinement Actually Reach Production: An End-to-end Lifecycle for 1,700 Profiles - Maxime Bélair, Canonical
Thursday October 8, 2026 15:00 - 15:45 CEST
Upstream AppArmor ships around 120 confining profiles, mostly for system and network services, so most applications run unconfined. apparmor.d, the main effort at comprehensive confinement, ships around 1,700 profiles but barely reaches production. No distribution enables it, for good reasons: enforcing them all is heavy on CPU and memory; many profiles are unused or too strict for interactive...
See More →
Speakers
avatar for Maxime Bélair

Maxime Bélair

PhD, Canonical
Maxime is a security engineer at Canonical. He currently works on the development of AppArmor
Thursday October 8, 2026 15:00 - 15:45 CEST
Chamber Hall (Floor 3)

15:45 CEST

Afternoon Break
Thursday October 8, 2026 15:45 - 16:05 CEST

Thursday October 8, 2026 15:45 - 16:05 CEST
Chamber Hall (Floor 3)

16:05 CEST

Vock: Mapping Kernel Attack Surface With Zero-Configuration Coverage - Yunseong Kim, Ericsson Software Technology
Thursday October 8, 2026 16:05 - 16:50 CEST
There is no practical tool that maps userspace programs to the kernel code they exercise. strace shows syscall names but not kernel internals. KCOV requires kernel recompilation. perf is general-purpose and not designed for per-program kernel coverage. vock fills this gap. It takes any userspace program and outputs the exact kernel functions and branches that program reaches. Two modes: (1)...
See More →
Speakers
avatar for Yunseong Kim

Yunseong Kim

vock: Mapping Kernel Attack Surface with Zero-Configuration Coverage, Ericsson Software Technology
Upstream security hardening: https://lore.kernel.org/lkml/?q=yunseong
Thursday October 8, 2026 16:05 - 16:50 CEST
Chamber Hall (Floor 3)

16:55 CEST

Detection Engineering with RSigma - Mostafa Moradian, Tiger Data
Thursday October 8, 2026 16:55 - 17:40 CEST
Sigma is the open, vendor-neutral standard for detection rules, yet most Sigma tooling only translates rules into another vendor's query language. RSigma is a toolkit that evaluates Sigma directly against logs in real time: a parser, a compiled matcher, a stateful correlation engine, and a streaming daemon in one small static binary.This is a working session on detection engineering for Linux. We...
See More →
Speakers
avatar for Mostafa Moradian

Mostafa Moradian

Head of Security, Tiger Data
Mostafa Moradian is the Head of Security at TigerData, where he leads people and initiatives that strengthen the security posture across a global infrastructure. His work spans across large-scale security automation, open-source contributions and cross-functional engineering projects... Read More →
Thursday October 8, 2026 16:55 - 17:40 CEST
Chamber Hall (Floor 3)
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.