What is Software Supply Chain Security?

09/08/2022
by   Marcela S. Melara, et al.
0

The software supply chain involves a multitude of tools and processes that enable software developers to write, build, and ship applications. Recently, security compromises of tools or processes has led to a surge in proposals to address these issues. However, these proposals commonly overemphasize specific solutions or conflate goals, resulting in unexpected consequences, or unclear positioning and usage. In this paper, we make the case that developing practical solutions is not possible until the community has a holistic view of the security problem; this view must include both the technical and procedural aspects. To this end, we examine three use cases to identify common security goals, and present a goal-oriented taxonomy of existing solutions demonstrating a holistic overview of software supply chain security.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/11/2023

Journey to the Center of Software Supply Chain Attacks

This work discusses open-source software supply chain attacks and propos...
research
04/26/2023

On the Way to SBOMs: Investigating Design Issues and Solutions in Practice

Software Bill of Materials (SBOM), offers improved transparency and supp...
research
07/21/2019

IoT Supply Chain Security: Overview, Challenges, and the Road Ahead

Supply chain is emerging as the next frontier of threats in the rapidly ...
research
07/31/2023

S3C2 Summit 2023-02: Industry Secure Supply Chain Summit

Recent years have shown increased cyber attacks targeting less secure el...
research
06/17/2021

Enabling Security-Oriented Orchestration of Microservices

As cloud providers push multi-tenancy to new levels to meet growing scal...
research
08/30/2023

Quantitative Toolchain Assurance

The software bill of materials (SBOM) concept aims to include more infor...
research
10/19/2021

Holistic Hardware Security Assessment Framework: A Microarchitectural Perspective

Our goal is to enable holistic hardware security evaluation from the mic...

Please sign up or login with your details

Forgot password? Click here to reset