Software Supply Chain Risk: Characterization, Measurement & Attenuation
With the accelerating adoption of open source software, and an ever-growing body of case studies of security vulnerabilities being introduced by said open source software (Log4J arbitrary code execution, OpenSSH backdoor by way of XZ-utils, and the Polyfill CDN take over), the need for supply chain...
Uloženo v:
| Vydáno v: | IEEE/ACM International Conference on Automated Software Engineering : [proceedings] s. 2506 - 2509 |
|---|---|
| Hlavní autor: | |
| Médium: | Konferenční příspěvek |
| Jazyk: | angličtina |
| Vydáno: |
ACM
27.10.2024
|
| Témata: | |
| ISSN: | 2643-1572 |
| On-line přístup: | Získat plný text |
| Tagy: |
Přidat tag
Žádné tagy, Buďte první, kdo vytvoří štítek k tomuto záznamu!
|
| Abstract | With the accelerating adoption of open source software, and an ever-growing body of case studies of security vulnerabilities being introduced by said open source software (Log4J arbitrary code execution, OpenSSH backdoor by way of XZ-utils, and the Polyfill CDN take over), the need for supply chain observability has become increasingly urgent. This need has been acknowledged by both industry and government, with calls to enforce the adoption of Software Bills of Materials (SBOMs).Current software security metrology efforts focus on individual packages within an ecosystem, with very little work exploring how security risk propagates through dependency networks. This research proposal sets out a number of research objectives and proposed approaches that when combined look to develop metrics that better align with the needs of software engineering practitioners, and further the understanding of the role of dependency networks in the propagation of risk within open source software. |
|---|---|
| AbstractList | With the accelerating adoption of open source software, and an ever-growing body of case studies of security vulnerabilities being introduced by said open source software (Log4J arbitrary code execution, OpenSSH backdoor by way of XZ-utils, and the Polyfill CDN take over), the need for supply chain observability has become increasingly urgent. This need has been acknowledged by both industry and government, with calls to enforce the adoption of Software Bills of Materials (SBOMs).Current software security metrology efforts focus on individual packages within an ecosystem, with very little work exploring how security risk propagates through dependency networks. This research proposal sets out a number of research objectives and proposed approaches that when combined look to develop metrics that better align with the needs of software engineering practitioners, and further the understanding of the role of dependency networks in the propagation of risk within open source software. |
| Author | Butler, Alexis |
| Author_xml | – sequence: 1 givenname: Alexis surname: Butler fullname: Butler, Alexis email: alexis.butler.2023@live.rhul.ac.uk organization: Royal Holloway University of London,London,United Kingdom |
| BookMark | eNotjktLw0AURkdRsNas3bjIypWp8364K0GrUBGsrsud9AYH2yRMJpT6642P1Tnwwcc5JydN2yAhl4zOGJPqVmjHNKezkUpTe0QyZ5yVlBrGpTXHZMK1FAVThp-RrO-Dp6MqzZiekMWqrdMeIuaroeu2h7z8gNDkr6H_vPvxCFXCGL4ghba5yZ8R-iHiDpuUX-fzlLAZfqcLclrDtsfsn1Py_nD_Vj4Wy5fFUzlfFjC2pIK5WjkvtLVjoDK6ct4qDiCktxsuDXhnKg0OURocUYm64h6k5xvvgToxJVd_vwER110MO4iHNaNGSyul-AZx_U6E |
| CODEN | IEEPAD |
| ContentType | Conference Proceeding |
| DBID | 6IE 6IL CBEJK RIE RIL |
| DOI | 10.1145/3691620.3695608 |
| DatabaseName | IEEE Electronic Library (IEL) Conference Proceedings IEEE Xplore POP ALL IEEE Xplore All Conference Proceedings IEEE/IET Electronic Library IEEE Proceedings Order Plans (POP All) 1998-Present |
| DatabaseTitleList | |
| Database_xml | – sequence: 1 dbid: RIE name: IEEE/IET Electronic Library url: https://ieeexplore.ieee.org/ sourceTypes: Publisher |
| DeliveryMethod | fulltext_linktorsrc |
| Discipline | Computer Science |
| EISBN | 9798400712487 |
| EISSN | 2643-1572 |
| EndPage | 2509 |
| ExternalDocumentID | 10764844 |
| Genre | orig-research |
| GroupedDBID | 6IE 6IF 6IH 6IK 6IL 6IM 6IN 6J9 AAJGR AAWTH ABLEC ACREN ADYOE ADZIZ AFYQB ALMA_UNASSIGNED_HOLDINGS AMTXH BEFXN BFFAM BGNUA BKEBE BPEOZ CBEJK CHZPO IEGSK IPLJI M43 OCL RIE RIL |
| ID | FETCH-LOGICAL-a248t-19f59b3688840576c9b852aa34b8d247ab97c6a9ee47ea9ec3fc2ba4b2dbba093 |
| IEDL.DBID | RIE |
| ISICitedReferencesCount | 0 |
| ISICitedReferencesURI | http://www.webofscience.com/api/gateway?GWVersion=2&SrcApp=Summon&SrcAuth=ProQuest&DestLinkType=CitingArticles&DestApp=WOS_CPL&KeyUT=001353105400263&url=https%3A%2F%2Fcvtisr.summon.serialssolutions.com%2F%23%21%2Fsearch%3Fho%3Df%26include.ft.matches%3Dt%26l%3Dnull%26q%3D |
| IngestDate | Wed Jan 15 06:20:43 EST 2025 |
| IsPeerReviewed | false |
| IsScholarly | true |
| Language | English |
| LinkModel | DirectLink |
| MergedId | FETCHMERGED-LOGICAL-a248t-19f59b3688840576c9b852aa34b8d247ab97c6a9ee47ea9ec3fc2ba4b2dbba093 |
| PageCount | 4 |
| ParticipantIDs | ieee_primary_10764844 |
| PublicationCentury | 2000 |
| PublicationDate | 2024-Oct.-27 |
| PublicationDateYYYYMMDD | 2024-10-27 |
| PublicationDate_xml | – month: 10 year: 2024 text: 2024-Oct.-27 day: 27 |
| PublicationDecade | 2020 |
| PublicationTitle | IEEE/ACM International Conference on Automated Software Engineering : [proceedings] |
| PublicationTitleAbbrev | ASE |
| PublicationYear | 2024 |
| Publisher | ACM |
| Publisher_xml | – name: ACM |
| SSID | ssib057256116 ssj0051577 |
| Score | 2.2722008 |
| Snippet | With the accelerating adoption of open source software, and an ever-growing body of case studies of security vulnerabilities being introduced by said open... |
| SourceID | ieee |
| SourceType | Publisher |
| StartPage | 2506 |
| SubjectTerms | Attenuation measurement Industries Metrology Observability Open source software Proposals Security Software engineering Software measurement Supply chains |
| Title | Software Supply Chain Risk: Characterization, Measurement & Attenuation |
| URI | https://ieeexplore.ieee.org/document/10764844 |
| WOSCitedRecordID | wos001353105400263&url=https%3A%2F%2Fcvtisr.summon.serialssolutions.com%2F%23%21%2Fsearch%3Fho%3Df%26include.ft.matches%3Dt%26l%3Dnull%26q%3D |
| hasFullText | 1 |
| inHoldings | 1 |
| isFullTextHit | |
| isPrint | |
| link | http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwlV27TsMwFLVoxcDEq4i3PCAmAolz_WJDFYWFquIhdauuHUdUSC1qUxB_j-2kVAwMTLEyWU587zlOzjmEnNk0Zyg9LTEp2gSUKBONChJrhS4gLYN_SwybkP2-Gg71oBGrRy2Mcy7-fOYuwzB-yy-mdhGOyvwOlwIUQIu0pBS1WGv58nDpm3cWsE5dhn2flrLx8smAX-XCAyHmOaoIjED9ClOJvaS3-c9ZbJHOSpVHBz_9ZpusuckO2VzGMtBml-6SuydfWj9x5miM7Pyi3VdP_-njeP52HcaNQXOtv7ygD6tTQnpObyoPomv77w556d0-d--TJi8hQQaqSjJdcm1y4UltgGHCaqM4Q8zBqIKBRKOlFaidA-n8xealZQbBsMIYTHW-R9qT6cTtE6o551gKy4vU8zdwShaIGaYWlENP2w5IJyzM6L22xBgt1-Twj_tHZIN5NBCKPpPHpF3NFu6ErNuPajyfncYH-Q3JQZ4b |
| linkProvider | IEEE |
| linkToHtml | http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwlV3NS8MwHA06BT3Nj4nf5iCerLZpPr3JcE7cxtAJu41f0hSH0MnWKf73Jm3n8ODBU0NPIWnyfi_pew-hcxPGBISjJToEE1DJ00CBpIExXCU0TL1_SxE2IXo9ORyqfiVWL7Qw1tri5zN75ZvFXX4yMXN_VOZWuOBUUrqK1hilJCzlWovPhwkH35GvdsqN2CG1EJWbT0TZdcxdKUQcS-WeE8hfcSoFmrTq_-zHFmosdXm4_4M422jFZjuovghmwNU63UX3z25z_YSpxUVo5xduvsI4w0_j2duNb1cWzaUC8xJ3l-eE-ALf5q6MLg3AG-ildTdotoMqMSEAQmUeRCplSsfc0VpfiHGjtGQEIKZaJoQK0EoYDspaKqx7mDg1RAPVJNEaQhXvoVo2yew-wooxBik3LAkdg6NWigQggtBQacERtwPU8AMzei9NMUaLMTn84_0Z2mgPup1R56H3eIQ2iasNPAQQcYxq-XRuT9C6-cjHs-lpManfMwuhYg |
| openUrl | ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rft.genre=proceeding&rft.title=IEEE%2FACM+International+Conference+on+Automated+Software+Engineering+%3A+%5Bproceedings%5D&rft.atitle=Software+Supply+Chain+Risk%3A+Characterization%2C+Measurement+%26+Attenuation&rft.au=Butler%2C+Alexis&rft.date=2024-10-27&rft.pub=ACM&rft.eissn=2643-1572&rft.spage=2506&rft.epage=2509&rft_id=info:doi/10.1145%2F3691620.3695608&rft.externalDocID=10764844 |