Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | Hamer, Sivana, Bowen, Jacob, Haque, Md Nazmul, Hines, Robert, Madden, Chris, Williams, Laurie |
|---|---|
| Format: | Preprint |
| Publié: |
2025
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
Documents similaires
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
par: Hamer, Sivana, et autres
Publié: (2025)
par: Hamer, Sivana, et autres
Publié: (2025)
Beyond Single Reports: Evaluating Automated ATT&CK Technique Extraction in Multi-Report Campaign Settings
par: Haque, Md Nazmul, et autres
Publié: (2026)
par: Haque, Md Nazmul, et autres
Publié: (2026)
Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers
par: Hamer, Sivana, et autres
Publié: (2024)
par: Hamer, Sivana, et autres
Publié: (2024)
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
par: Przymus, Piotr, et autres
Publié: (2025)
par: Przymus, Piotr, et autres
Publié: (2025)
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
par: Tamanna, Mahzabin, et autres
Publié: (2024)
par: Tamanna, Mahzabin, et autres
Publié: (2024)
Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem
par: Hamer, Sivana, et autres
Publié: (2024)
par: Hamer, Sivana, et autres
Publié: (2024)
S3C2 Summit 2025-07: Government Secure Supply Chain Summit
par: Hamer, Sivana, et autres
Publié: (2026)
par: Hamer, Sivana, et autres
Publié: (2026)
Understanding Crash Dynamics and Severity of EV Paratransit: Evidence From Easy Bike Accidents in Bangladesh
par: Haque, Nazmul
Publié: (2026)
par: Haque, Nazmul
Publié: (2026)
Yield reduction and arsenic accumulation in potatoes (Solanum tuberosum L.) in an arsenic contaminated soil
par: Nazmul Haque
Publié: (2015)
par: Nazmul Haque
Publié: (2015)
How Quantization Impacts Privacy Risk on LLMs for Code?
par: Haque, Md Nazmul, et autres
Publié: (2025)
par: Haque, Md Nazmul, et autres
Publié: (2025)
Real-Time Solar Field Dataset from Dhaka, Bangladesh (January–June)
par: Howlader, Md. Nazmul
Publié: (2026)
par: Howlader, Md. Nazmul
Publié: (2026)
DEEGITS: Deep Learning based Framework for Measuring Heterogenous Traffic State in Challenging Traffic Scenarios
par: Islam, Muttahirul, et autres
Publié: (2024)
par: Islam, Muttahirul, et autres
Publié: (2024)
Registration of ‘XZ 14069’ zoysiagrass
par: Susana R. Milla‐Lewis, et autres
Publié: (2025)
par: Susana R. Milla‐Lewis, et autres
Publié: (2025)
Secure or Suspect? Investigating Package Hallucinations of Shell Command in Original and Quantized LLMs
par: Haque, Md Nazmul, et autres
Publié: (2025)
par: Haque, Md Nazmul, et autres
Publié: (2025)
Trajectory-based real-time pedestrian crash prediction at intersections: A novel non-linear link function for block maxima led Bayesian GEV framework addressing heterogeneous traffic condition
par: Anowar, Parvez, et autres
Publié: (2025)
par: Anowar, Parvez, et autres
Publié: (2025)
Modeling Chaotic Pedestrian Behavior Using Chaos Indicators and Supervised Learning
par: Shahrier, Md. Muhtashim, et autres
Publié: (2025)
par: Shahrier, Md. Muhtashim, et autres
Publié: (2025)
How Do Semantically Equivalent Code Transformations Impact Membership Inference on LLMs for Code?
par: Yang, Hua, et autres
Publié: (2025)
par: Yang, Hua, et autres
Publié: (2025)
Influence of palm oil factory wastes as coarse aggregate species for green lightweight concrete
par: Md. Nazmul Huda
Publié: (2016)
par: Md. Nazmul Huda
Publié: (2016)
CNN-Based Framework for Pedestrian Age and Gender Classification Using Far-View Surveillance in Mixed-Traffic Intersections
par: Arif, Shisir Shahriar, et autres
Publié: (2025)
par: Arif, Shisir Shahriar, et autres
Publié: (2025)
Establishing a Baseline of Software Supply Chain Security Task Adoption by Software Organizations
par: Williams, Laurie, et autres
Publié: (2025)
par: Williams, Laurie, et autres
Publié: (2025)
Unraveling Log4Shell: Analyzing the Impact and Response to the Log4j Vulnerabil
par: Doll, John, et autres
Publié: (2025)
par: Doll, John, et autres
Publié: (2025)
ARCHITECTURAL DOCUMENTATION OF ADINA MURA MOSQUE: ONE OF THE EARLIEST EXAMPLE OF MEDIEVAL ISLAMIC ARCHITECTURE IN CUMILLA, BANGLADESH
par: Mahinul Haque, et autres
Publié: (2021)
par: Mahinul Haque, et autres
Publié: (2021)
How does the Performance of the Data-driven Traffic Flow Forecasting Models deteriorate with Increasing Forecasting Horizon? An Extensive Approach Considering Statistical, Machine Learning and Deep Learning Models
par: Sherfenaz, Amanta, et autres
Publié: (2025)
par: Sherfenaz, Amanta, et autres
Publié: (2025)
Initial results of our spectro-photometric monitoring of XZ Tau
par: Ghosh, Arpan, et autres
Publié: (2024)
par: Ghosh, Arpan, et autres
Publié: (2024)
Bayesian Inference for Left-Truncated Log-Logistic Distributions for Time-to-event Data Analysis
par: Mostafa, Fahad, et autres
Publié: (2025)
par: Mostafa, Fahad, et autres
Publié: (2025)
Seismic assessment on different irregular structure considering incident angles and soil structure interactions
par: Rahman, Mohammad Sabbir, et autres
Publié: (2025)
par: Rahman, Mohammad Sabbir, et autres
Publié: (2025)
Log-Augmented Generation: Scaling Test-Time Reasoning with Reusable Computation
par: Chen, Peter Baile, et autres
Publié: (2025)
par: Chen, Peter Baile, et autres
Publié: (2025)
The Future of China‐Gulf Solar and Wind Supply Chains
par: Li‐Chen Sim, et autres
Publié: (2024)
par: Li‐Chen Sim, et autres
Publié: (2024)
Java Classes with "-Er" and "-Utils" Suffixes Have Higher Complexity
par: Sukhova, Anna, et autres
Publié: (2024)
par: Sukhova, Anna, et autres
Publié: (2024)
LogDx-CI: Benchmarking Log Reduction Tools for LLM Root-Cause Diagnosis
par: Qin, Bowen
Publié: (2026)
par: Qin, Bowen
Publié: (2026)
Security Vulnerabilities in Software Supply Chain for Autonomous Vehicles
par: Haque, Md Wasiul, et autres
Publié: (2025)
par: Haque, Md Wasiul, et autres
Publié: (2025)
Abstract mindset favors well-being and reduces risk behaviors for adolescents in relative scarcity
par: Amparo Caballero
Publié: (2024)
par: Amparo Caballero
Publié: (2024)
An IoT Based Water-Logging Detection System: A Case Study of Dhaka
par: Islam, Md Manirul, et autres
Publié: (2024)
par: Islam, Md Manirul, et autres
Publié: (2024)
Proactive Software Supply Chain Risk Management Framework (P-SSCRM)
par: Williams, Laurie, et autres
Publié: (2024)
par: Williams, Laurie, et autres
Publié: (2024)
On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from XZ
par: Lins, Mario, et autres
Publié: (2024)
par: Lins, Mario, et autres
Publié: (2024)
Enhanced Efficacy of Synbiotics Compared to Antibiotics in Promoting Growth, Intestinal Health, and Immune Response in Stinging Catfish
par: Md Nazmul Islam Nayan, et autres
Publié: (2026)
par: Md Nazmul Islam Nayan, et autres
Publié: (2026)
How Do Developers Use Migration Guides? A Case Study of Log4j
par: Monno, Takahiro, et autres
Publié: (2026)
par: Monno, Takahiro, et autres
Publié: (2026)
Do Developers Depend on Deprecated Library Versions? A Mining Study of Log4j
par: Yoshioka, Haruhiko, et autres
Publié: (2025)
par: Yoshioka, Haruhiko, et autres
Publié: (2025)
Advanced Vulnerability Scanning for Open Source Software: Detection and Mitigation of Log4j Vulnerabilities
par: Wen, Victor, et autres
Publié: (2026)
par: Wen, Victor, et autres
Publié: (2026)
CIgrate: Automating CI Service Migration with Large Language Models
par: Hossain, Md Nazmul, et autres
Publié: (2025)
par: Hossain, Md Nazmul, et autres
Publié: (2025)
Documents similaires
-
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
par: Hamer, Sivana, et autres
Publié: (2025) -
Beyond Single Reports: Evaluating Automated ATT&CK Technique Extraction in Multi-Report Campaign Settings
par: Haque, Md Nazmul, et autres
Publié: (2026) -
Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers
par: Hamer, Sivana, et autres
Publié: (2024) -
Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack
par: Przymus, Piotr, et autres
Publié: (2025) -
Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security
par: Tamanna, Mahzabin, et autres
Publié: (2024)