中文

背刺者之刃集:开源软件供应链攻击综述

密码学与安全 2020-05-20 v1 软件工程

摘要

软件供应链攻击的特征是将恶意代码注入软件包中,以进一步破坏链条下游的依赖系统。近年来出现了若干起利用软件开发过程中开源使用日益增长的供应链攻击,这种增长由依赖管理器促成,后者在软件生命周期中自动解析、下载并安装数百个开源包。本文提出一个包含 174 个恶意软件包的数据集,这些包被用于针对开源软件供应链的真实世界攻击,并通过流行的包仓库 npm、PyPI 和 RubyGems 分发。这些包的时间跨度为 2015 年 11 月至 2019 年 11 月,经人工收集与分析。本文还提出两棵通用攻击树,以结构化方式概述向下游用户的依赖树中注入恶意代码、以及在不同时间和不同条件下执行此类代码的技术。本工作旨在促进开源社区与研究界未来预防性与检测性保障措施的发展。

关键词

引用

@article{arxiv.2005.09535,
  title  = {Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks},
  author = {Marc Ohm and Henrik Plate and Arnold Sykosch and Michael Meier},
  journal= {arXiv preprint arXiv:2005.09535},
  year   = {2020}
}

备注

This is a pre-print version of the paper that appears in the proceedings of The 17th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA)