SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
Fuente:
arXiv
Salvato in:
| Autori principali: | Okafor, Chinenye, Schorlemmer, Taylor R., Torres-Arias, Santiago, Davis, James C. |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
An Industry Interview Study of Software Signing for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024)
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
di: Okafor, Chinenye, et al.
Pubblicazione: (2024)
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024)
SoK: The Design Paradigm of Safe and Secure Defaults
di: Ruohonen, Jukka
Pubblicazione: (2024)
di: Ruohonen, Jukka
Pubblicazione: (2024)
Evaluating Software Supply Chain Security in Research Software
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
di: Hegewald, Richard, et al.
Pubblicazione: (2025)
Software Supply Chain Security of Web3
di: Monperrus, Martin
Pubblicazione: (2025)
di: Monperrus, Martin
Pubblicazione: (2025)
SoK: A Defense-Oriented Evaluation of Software Supply Chain Security
di: Ishgair, Eman Abu, et al.
Pubblicazione: (2024)
di: Ishgair, Eman Abu, et al.
Pubblicazione: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
di: Schmid, Larissa, et al.
Pubblicazione: (2026)
Securing the Software Package Supply Chain for Critical Systems
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
di: Pohl, Timo, et al.
Pubblicazione: (2025)
di: Pohl, Timo, et al.
Pubblicazione: (2025)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
SoK: A Literature and Engineering Review of Regular Expression Denial of Service (ReDoS)
di: Bhuiyan, Masudul Hasan Masud, et al.
Pubblicazione: (2024)
di: Bhuiyan, Masudul Hasan Masud, et al.
Pubblicazione: (2024)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
di: O'Donoghue, Eric, et al.
Pubblicazione: (2025)
SoK: Enhancing Privacy-Preserving Software Development from a Developers' Perspective
di: Wijesundara, Tharaka, et al.
Pubblicazione: (2025)
di: Wijesundara, Tharaka, et al.
Pubblicazione: (2025)
SoK: Prudent Evaluation Practices for Fuzzing
di: Schloegel, Moritz, et al.
Pubblicazione: (2024)
di: Schloegel, Moritz, et al.
Pubblicazione: (2024)
SoK: Where to Fuzz? Assessing Target Selection Methods in Directed Fuzzing
di: Weissberg, Felix, et al.
Pubblicazione: (2025)
di: Weissberg, Felix, et al.
Pubblicazione: (2025)
SoK: Web3 RegTech for Cryptocurrency VASP AML/CFT Compliance
di: Mao, Qian'ang, et al.
Pubblicazione: (2025)
di: Mao, Qian'ang, et al.
Pubblicazione: (2025)
A Longitudinal Study of Usability in Identity-Based Software Signing
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
di: Bufalino, Jacopo, et al.
Pubblicazione: (2025)
di: Bufalino, Jacopo, et al.
Pubblicazione: (2025)
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
Dirty-Waters: Detecting Software Supply Chain Smells
di: Liu, Raphina, et al.
Pubblicazione: (2024)
di: Liu, Raphina, et al.
Pubblicazione: (2024)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
di: Zhang, Ying, et al.
Pubblicazione: (2023)
di: Zhang, Ying, et al.
Pubblicazione: (2023)
An Introduction to Adaptive Software Security
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
di: Nia, Mehran Alidoost
Pubblicazione: (2023)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
di: Przymus, Piotr, et al.
Pubblicazione: (2025)
Software Security Analysis in 2030 and Beyond: A Research Roadmap
di: Böhme, Marcel, et al.
Pubblicazione: (2024)
di: Böhme, Marcel, et al.
Pubblicazione: (2024)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
di: Ruan, Bonan, et al.
Pubblicazione: (2025)
di: Ruan, Bonan, et al.
Pubblicazione: (2025)
An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security
di: Maxam III, William P., et al.
Pubblicazione: (2024)
di: Maxam III, William P., et al.
Pubblicazione: (2024)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
di: Reyes, Frank, et al.
Pubblicazione: (2024)
di: Reyes, Frank, et al.
Pubblicazione: (2024)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
di: Tran, Nguyen Khoi, et al.
Pubblicazione: (2023)
di: Tran, Nguyen Khoi, et al.
Pubblicazione: (2023)
QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
di: Amusuo, Paschal C., et al.
Pubblicazione: (2023)
Software Security in Software-Defined Networking: A Systematic Literature Review
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
di: Diouf, Moustapha Awwalou, et al.
Pubblicazione: (2025)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
di: Cusick, James J.
Pubblicazione: (2025)
di: Cusick, James J.
Pubblicazione: (2025)
Securing Tomorrow's Smart Cities: Investigating Software Security in Internet of Vehicles and Deep Learning Technologies
di: Jain, Ridhi, et al.
Pubblicazione: (2024)
di: Jain, Ridhi, et al.
Pubblicazione: (2024)
Large Language Model Supply Chain: Open Problems From the Security Perspective
di: Hu, Qiang, et al.
Pubblicazione: (2024)
di: Hu, Qiang, et al.
Pubblicazione: (2024)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
di: Pecka, Nicholas, et al.
Pubblicazione: (2025)
di: Pecka, Nicholas, et al.
Pubblicazione: (2025)
SecDOAR: A Software Reference Architecture for Security Data Orchestration, Analysis and Reporting
di: Chauhan, Muhammad Aufeef, et al.
Pubblicazione: (2024)
di: Chauhan, Muhammad Aufeef, et al.
Pubblicazione: (2024)
Challenges in Developing Secure Software -- Results of an Interview Study in the German Software Industry
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
di: Mattukat, Alex R., et al.
Pubblicazione: (2025)
Documenti analoghi
-
An Industry Interview Study of Software Signing for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2024) -
DiVerify: Hardening Identity-Based Software Signing with Diverse-Context Scopes
di: Okafor, Chinenye, et al.
Pubblicazione: (2024) -
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026) -
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
di: Schorlemmer, Taylor R., et al.
Pubblicazione: (2024) -
SoK: The Design Paradigm of Safe and Secure Defaults
di: Ruohonen, Jukka
Pubblicazione: (2024)