Risk Explorer for Software Supply Chains - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2022

Risk Explorer for Software Supply Chains

Résumé

Supply chain attacks on open-source projects aim at injecting and spreading malicious code such that it is executed by direct and indirect downstream users. Recent work systematized the knowledge about such attacks and proposed a taxonomy in the form of an attack tree. We propose a visualization tool called Risk Explorer for Software Supply Chains, which allows inspecting the taxonomy of attack vectors, their descriptions, references to real-world incidents and other literature, as well as information about associated safeguards. Being open-source itself, the community can easily reference new attacks, accommodate for entirely new attack vectors or reflect the development of new safeguards.
Fichier principal
Vignette du fichier
3560835.3564546.pdf (995.96 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03921373 , version 1 (03-01-2023)

Licence

Paternité

Identifiants

Citer

Piergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier Barais, Serena Elisa Ponta. Risk Explorer for Software Supply Chains. CCS 2022 - ACM SIGSAC Conference on Computer and Communications Security, Nov 2022, Los Angeles, United States. pp.35-36, ⟨10.1145/3560835.3564546⟩. ⟨hal-03921373⟩
62 Consultations
96 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More