An Industry Interview Study of Software Signing for Supply Chain Security
Fuente:
arXiv
Salvato in:
| Autori principali: | Kalu, Kelechi G., Singla, Tanya, Okafor, Chinenye, Torres-Arias, Santiago, Davis, James C. |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
A Longitudinal Study of Usability in Identity-Based Software Signing
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
Why Software Signing (Still) Matters: Trust Boundaries in the Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
A Guide to Stakeholder Analysis for Cybersecurity Researchers
di: Davis, James C, et al.
Pubblicazione: (2025)
di: Davis, James C, et al.
Pubblicazione: (2025)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
Evaluating Software Supply Chain Security in Research Software
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
Software Supply Chain Security of Web3
di: Monperrus, Martin
Pubblicazione: (2025)
di: Monperrus, Martin
Pubblicazione: (2025)
Securing the Software Package Supply Chain for Critical Systems
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security
di: Maxam III, William P., et al.
Pubblicazione: (2024)
di: Maxam III, William P., et al.
Pubblicazione: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
Dirty-Waters: Detecting Software Supply Chain Smells
di: Liu, Raphina, et al.
Pubblicazione: (2024)
di: Liu, Raphina, et al.
Pubblicazione: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
di: Ruan, Bonan, et al.
Pubblicazione: (2025)
di: Ruan, Bonan, et al.
Pubblicazione: (2025)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
di: Reyes, Frank, et al.
Pubblicazione: (2024)
di: Reyes, Frank, et al.
Pubblicazione: (2024)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
di: Tran, Nguyen Khoi, et al.
Pubblicazione: (2023)
di: Tran, Nguyen Khoi, et al.
Pubblicazione: (2023)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
di: Bufalino, Jacopo, et al.
Pubblicazione: (2025)
di: Bufalino, Jacopo, et al.
Pubblicazione: (2025)
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
di: Cesarano, Carmine, et al.
Pubblicazione: (2025)
di: Cesarano, Carmine, et al.
Pubblicazione: (2025)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
Towards a Benchmark for Dependency Decision-Making
di: Singla, Tanmay, et al.
Pubblicazione: (2026)
di: Singla, Tanmay, et al.
Pubblicazione: (2026)
OmniBOR: A System for Automatic, Verifiable Artifact Resolution across Software Supply Chains
di: Seshadri, Bharathi, et al.
Pubblicazione: (2024)
di: Seshadri, Bharathi, et al.
Pubblicazione: (2024)
QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
di: Zhang, Ying, et al.
Pubblicazione: (2023)
di: Zhang, Ying, et al.
Pubblicazione: (2023)
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
di: Baird, Laura, et al.
Pubblicazione: (2026)
di: Baird, Laura, et al.
Pubblicazione: (2026)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
An Introduction to Adaptive Software Security
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
Understanding the Supply Chain and Risks of Large Language Model Applications
di: Ma, Yujie, et al.
Pubblicazione: (2025)
di: Ma, Yujie, et al.
Pubblicazione: (2025)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
di: Cusick, James J.
Pubblicazione: (2025)
di: Cusick, James J.
Pubblicazione: (2025)
Exploiting LLM Agent Supply Chains via Payload-less Skills
di: Liu, Xinyu, et al.
Pubblicazione: (2026)
di: Liu, Xinyu, et al.
Pubblicazione: (2026)
Software Security in Software-Defined Networking: A Systematic Literature Review
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns
di: Klemmer, Jan H., et al.
Pubblicazione: (2024)
di: Klemmer, Jan H., et al.
Pubblicazione: (2024)
Large Language Model Supply Chain: Open Problems From the Security Perspective
di: Hu, Qiang, et al.
Pubblicazione: (2024)
di: Hu, Qiang, et al.
Pubblicazione: (2024)
A Security Risk Assessment Method for Distributed Ledger Technology (DLT) based Applications: Three Industry Case Studies
di: Baninemeh, Elena, et al.
Pubblicazione: (2024)
di: Baninemeh, Elena, et al.
Pubblicazione: (2024)
Documenti analoghi
-
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
di: Okafor, Chinenye, et al.
Pubblicazione: (2024) -
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
di: Okafor, Chinenye, et al.
Pubblicazione: (2024) -
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025) -
A Longitudinal Study of Usability in Identity-Based Software Signing
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026) -
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)