首页> 外文会议>International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment >Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks
【24h】

Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks

机译:Backstabber的刀具系列:开源软件供应链攻击的回顾

获取原文

摘要

A software supply chain attack is characterized by the injection of malicious code into a software package in order to compromise dependent systems further down the chain. Recent years saw a number of supply chain attacks that leverage the increasing use of open source during software development, which is facilitated by dependency managers that automatically resolve, download and install hundreds of open source packages throughout the software life cycle. Even though many approaches for detection and discovery of vulnerable packages exist, no prior work has focused on malicious packages. This paper presents a dataset as well as analysis of 174 malicious software packages that were used in real-world attacks on open source software supply chains and which were distributed via the popular package repositories npm, PyPI, and RubyGems. Those packages, dating from November 2015 to November 2019, were manually collected and analyzed. This work is meant to facilitate the future development of preventive and detective safeguards by open source and research communities.
机译:软件供应链攻击的特征是将恶意代码注入软件包中,以破坏链下游的相关系统。近年来,许多供应链攻击在软件开发过程中充分利用了开放源代码的使用,而依赖项管理器则可以在整个软件生命周期中自动解析,下载和安装数百个开放源代码包,从而促进了供应链攻击。即使存在许多检测和发现易受攻击的程序包的方法,但之前的工作都没有针对恶意程序包。本文介绍了一个数据集并分析了174种恶意软件软件包,这些软件包在现实世界中对开源软件供应链的攻击中使用,并通过流行的软件包存储库npm,PyPI和RubyGems进行分发。手动收集和分析了2015年11月至2019年11月的那些软件包。这项工作旨在促进开放源代码和研究社区未来的预防和侦探保障措施的发展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号