Software supply chain: review of attacks, risk assessment strategies and security controls

05/23/2023
by   Betul Gokkaya, et al.
0

The software product is a source of cyber-attacks that target organizations by using their software supply chain as a distribution vector. As the reliance of software projects on open-source or proprietary modules is increasing drastically, SSC is becoming more and more critical and, therefore, has attracted the interest of cyber attackers. While existing studies primarily focus on software supply chain attacks' prevention and detection methods, there is a need for a broad overview of attacks and comprehensive risk assessment for software supply chain security. This study conducts a systematic literature review to fill this gap. We analyze the most common software supply chain attacks by providing the latest trend of analyzed attacks, and we identify the security risks for open-source and third-party software supply chains. Furthermore, this study introduces unique security controls to mitigate analyzed cyber-attacks and risks by linking them with real-life security incidence and attacks.

READ FULL TEXT
research
04/11/2023

Journey to the Center of Software Supply Chain Attacks

This work discusses open-source software supply chain attacks and propos...
research
08/07/2022

Automatic Security Assessment of GitHub Actions Workflows

The demand for quick and reliable DevOps operations pushed distributors ...
research
12/08/2022

A systematic literature review on Ransomware attacks

In the area of information technology, cybersecurity is critical. Inform...
research
04/08/2022

Taxonomy of Attacks on Open-Source Software Supply Chains

The widespread dependency on open-source software makes it a fruitful ta...
research
07/28/2023

S3C2 Summit 2202-09: Industry Secure Suppy Chain Summit

Recent years have shown increased cyber attacks targeting less secure el...
research
10/27/2022

Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment

This paper provides the first large-scale data-driven analysis to evalua...
research
08/09/2023

An Empirical Study on Using Large Language Models to Analyze Software Supply Chain Security Failures

As we increasingly depend on software systems, the consequences of breac...

Please sign up or login with your details

Forgot password? Click here to reset