Journey to the Center of Software Supply Chain Attacks

04/11/2023
by   Piergiorgio Ladisa, et al.
0

This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool "Risk Explorer for Software Supply Chains" to explore such information and we discuss its industrial use-cases.

READ FULL TEXT

page 1

page 2

page 4

page 6

page 8

page 9

page 10

page 13

research
04/08/2022

Taxonomy of Attacks on Open-Source Software Supply Chains

The widespread dependency on open-source software makes it a fruitful ta...
research
05/23/2023

Software supply chain: review of attacks, risk assessment strategies and security controls

The software product is a source of cyber-attacks that target organizati...
research
06/28/2022

Building a Secure Software Supply Chain with GNU Guix

The software supply chain is becoming a widespread analogy to designate ...
research
08/06/2022

Preventing or Mitigating Adversarial Supply Chain Attacks; a legal analysis

The world is currently strongly connected through both the internet at l...
research
09/08/2022

What is Software Supply Chain Security?

The software supply chain involves a multitude of tools and processes th...
research
08/03/2022

Contrasting global approaches for identifying and managing cybersecurity risks in supply chains

Supply chains are increasingly targeted by threat actors. Using a recent...
research
09/28/2018

A Systems Approach to Achieving the Benefits of Artificial Intelligence in UK Defence

The ability to exploit the opportunities offered by AI within UK Defence...

Please sign up or login with your details

Forgot password? Click here to reset