English

Journey to the Center of Software Supply Chain Attacks

Cryptography and Security 2023-04-12 v1 Software Engineering

Abstract

This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool "Risk Explorer for Software Supply Chains" to explore such information and we discuss its industrial use-cases.

Keywords

Cite

@article{arxiv.2304.05200,
  title  = {Journey to the Center of Software Supply Chain Attacks},
  author = {Piergiorgio Ladisa and Serena Elisa Ponta and Antonino Sabetta and Matias Martinez and Olivier Barais},
  journal= {arXiv preprint arXiv:2304.05200},
  year   = {2023}
}

Comments

arXiv admin note: substantial text overlap with arXiv:2204.04008