谷歌浏览器插件
订阅小程序
在清言上使用

SoK: Practical Detection of Software Supply Chain Attacks

18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023(2023)

引用 0|浏览1
暂无评分
摘要
Detecting malicious packages used in software supply chain attacks has become increasingly important in recent years. Researchers are constantly developing and evaluating different tools and approaches. However, a comparison of all scientific publications on this topic does not yet exist. This paper examines existing publications and points out their characteristics, advantages and limitations. We identified and analyzed 20 publications that deal with malicious package detection. For those, we summarize the key points of each approach, present the experiments performed, discuss the features and limitations of each, and finally compare them to each other. We show that some tools and approaches are outdated, not fully evaluated, or not feasible for production use. Promising approaches for automatic detection of attacks in the software supply chain are outlined as well.
更多
查看译文
关键词
Systematization of Knowledge,Application Security,Malware,Software Supply Chain
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要