This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool "Risk Explorer for Software Supply Chains" to explore such information and we discuss its industrial use-cases.
@article{arxiv.2304.05200,
title = {Journey to the Center of Software Supply Chain Attacks},
author = {Piergiorgio Ladisa and Serena Elisa Ponta and Antonino Sabetta and Matias Martinez and Olivier Barais},
journal= {arXiv preprint arXiv:2304.05200},
year = {2023}
}
Comments
arXiv admin note: substantial text overlap with arXiv:2204.04008