深入软件供应链攻击中心之旅
密码学与安全
2023-04-12 v1 软件工程
摘要
本工作讨论了开源软件供应链攻击,并提出了一种描述攻击者如何实施此类攻击的通用分类法。随后我们提供了一系列缓解此类攻击的防护措施。我们展示了我们的工具“软件供应链风险探索器(Risk Explorer for Software Supply Chains)”来探索此类信息,并讨论了其工业用例。
引用
@article{arxiv.2304.05200,
title = {Journey to the Center of Software Supply Chain Attacks},
author = {Piergiorgio Ladisa and Serena Elisa Ponta and Antonino Sabetta and Matias Martinez and Olivier Barais},
journal= {arXiv preprint arXiv:2304.05200},
year = {2023}
}
备注
arXiv admin note: substantial text overlap with arXiv:2204.04008