GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cesarano, Carmine, Monperrus, Martin, Natella, Roberto
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916745021751296
author Cesarano, Carmine
Monperrus, Martin
Natella, Roberto
author_facet Cesarano, Carmine
Monperrus, Martin
Natella, Roberto
contents Modern software supply chain attacks consist of introducing new, malicious capabilities into trusted third-party software components, in order to propagate to a victim through a package dependency chain. These attacks are especially concerning for the Go language ecosystem, which is extensively used in critical cloud infrastructures. We present GoLeash, a novel system that applies the principle of least privilege at the package-level granularity, by enforcing distinct security policies for each package in the supply chain. This finer granularity enables GoLeash to detect malicious packages more precisely than traditional sandboxing that handles security policies at process- or container-level. Moreover, GoLeash remains effective under obfuscation, can overcome the limitations of static analysis, and incurs acceptable runtime overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2505_11016
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
Cesarano, Carmine
Monperrus, Martin
Natella, Roberto
Cryptography and Security
Software Engineering
Modern software supply chain attacks consist of introducing new, malicious capabilities into trusted third-party software components, in order to propagate to a victim through a package dependency chain. These attacks are especially concerning for the Go language ecosystem, which is extensively used in critical cloud infrastructures. We present GoLeash, a novel system that applies the principle of least privilege at the package-level granularity, by enforcing distinct security policies for each package in the supply chain. This finer granularity enables GoLeash to detect malicious packages more precisely than traditional sandboxing that handles security policies at process- or container-level. Moreover, GoLeash remains effective under obfuscation, can overcome the limitations of static analysis, and incurs acceptable runtime overhead.
title GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2505.11016