Quantitative Toolchain Assurance

08/30/2023
by   Dennis Volpano, et al.
0

The software bill of materials (SBOM) concept aims to include more information about a software build such as copyrights, dependencies and security references. But SBOM lacks visibility into the process for building a package. Efforts such as Supply-chain Levels for Software Artifacts (SLSA) try to remedy this by focusing on the quality of the build process. But they lack quantitative assessment of that quality. They are purely qualitative. A new form of assurance case and new technique for structuring it, called process reduction, are presented. An assurance case for a toolchain is quantitative and when structured as a process reduction can measure the strength of the toolchain via the strength of the reduction. An example is given for a simple toolchain.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/13/2023

An Empirical Study on Software Bill of Materials: Where We Stand and the Road Ahead

The rapid growth of software supply chain attacks has attracted consider...
research
07/31/2023

S3C2 Summit 2023-02: Industry Secure Supply Chain Summit

Recent years have shown increased cyber attacks targeting less secure el...
research
02/17/2023

A Review of Attacks Against Language-Based Package Managers

The liberalization of software licensing has led to unprecedented re-use...
research
10/11/2022

Software Supply Chain Attribute Integrity (SCAI)

The Software Supply Chain Attribute Integrity, or SCAI (pronounced "sky"...
research
09/08/2022

What is Software Supply Chain Security?

The software supply chain involves a multitude of tools and processes th...
research
07/05/2023

Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future

Software Bill of Materials (SBOM) serves as a critical pillar in ensurin...
research
06/07/2021

QFuzz: Quantitative Fuzzing for Side Channels

Side channels pose a significant threat to the confidentiality of softwa...

Please sign up or login with your details

Forgot password? Click here to reset