GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
Fuente:
arXiv
Saved in:
| Main Authors: | , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866916745021751296 |
|---|---|
| author | Cesarano, Carmine Monperrus, Martin Natella, Roberto |
| author_facet | Cesarano, Carmine Monperrus, Martin Natella, Roberto |
| contents | Modern software supply chain attacks consist of introducing new, malicious capabilities into trusted third-party software components, in order to propagate to a victim through a package dependency chain. These attacks are especially concerning for the Go language ecosystem, which is extensively used in critical cloud infrastructures. We present GoLeash, a novel system that applies the principle of least privilege at the package-level granularity, by enforcing distinct security policies for each package in the supply chain. This finer granularity enables GoLeash to detect malicious packages more precisely than traditional sandboxing that handles security policies at process- or container-level. Moreover, GoLeash remains effective under obfuscation, can overcome the limitations of static analysis, and incurs acceptable runtime overhead. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2505_11016 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement Cesarano, Carmine Monperrus, Martin Natella, Roberto Cryptography and Security Software Engineering Modern software supply chain attacks consist of introducing new, malicious capabilities into trusted third-party software components, in order to propagate to a victim through a package dependency chain. These attacks are especially concerning for the Go language ecosystem, which is extensively used in critical cloud infrastructures. We present GoLeash, a novel system that applies the principle of least privilege at the package-level granularity, by enforcing distinct security policies for each package in the supply chain. This finer granularity enables GoLeash to detect malicious packages more precisely than traditional sandboxing that handles security policies at process- or container-level. Moreover, GoLeash remains effective under obfuscation, can overcome the limitations of static analysis, and incurs acceptable runtime overhead. |
| title | GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2505.11016 |