Events

EE September Seminar

Title: Beyond Compliance: Why Many SBOMs Fall Short (And How to Improve Yours)

Speaker: Logan Kostick, Johns Hopkins University

Date & Time: September 15th, 2026 at 1:00 PM

Location: Steinman Hall, ST619

RSVP Link: https://docs.google.com/forms/d/e/1FAIpQLSdWgIVQui4Wtj_fDakIiE68c9DOcaVurwRs1PRiFp-ugi5kYw/viewform?pli=1

Abstract: Regulators, focus groups, and others have increasingly pushed the generation and consumption of Software Bills of Materials (SBOMs) to improve the security of software and cyberphysical systems; however, the usability of these artifacts often falls short of their intended purpose. This research explores the tension between industry best practices, regulatory compliance, and practical effectiveness. Often revealing the inherent conflict between SBOM generation and consumption. We examine key usability failures: lack of clarity in SBOM definitions, the proper scoping of cyberphysical systems, intellectual property disclosure, and system vulnerability disclosure.

Bio: Logan is a Ph.D candidate at Johns Hopkins University, advised by Dr. Avi Rubin and Dr. Michael Rushanan. His research focuses on the software supply chain security and the applicability to cyberphysical systems . He has also worked as a research intern at Harbor Labs and Riverside Research. 

Flyer for September EE Seminar

Last Updated: 09/10/2026 15:08