SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
复制标题
SoK:通过建立安全设计属性来分析软件供应链安全
DOI:
10.1145/3560835.3564556
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Davis, James C.
中科院分区:
文献类型:
--
作者:
Okafor, Chinenye;Schorlemmer, Taylor R.;Torres-Arias, Santiago;Davis, James C.
This paper systematizes knowledge about secure software supply chain patterns. It identifies four stages of a software supply chain attack and proposes three security properties crucial for a secured supply chain: transparency, validity, and separation. The paper describes current security approaches and maps them to the proposed security properties, including research ideas and case studies of supply chains in practice. It discusses the strengths and weaknesses of current approaches relative to known attacks and details the various security frameworks put out to ensure the security of the software supply chain. Finally, the paper highlights potential gaps in actor and operation-centered supply chain security techniques.
登录
查看更多内容
DOI:
--
发表时间:
2022
期刊:
IEEE Symposium on Security and Privacy
影响因子:
--
作者:
Piergiorgio Ladisa;H. Plate;Matias Martinez;Olivier Barais
通讯作者:
Olivier Barais
DOI:
10.5555/3361338.3361435
发表时间:
2019
期刊:
Proc. of the 28th USENIX Security Symposium
影响因子:
--
作者:
Torres-Arias, Santiago;Afzali, Hammad;Kuppusamy, Trishank Karthik;Curtmola, Reza;Cappos, Justin
通讯作者:
Cappos, Justin
影响因子:
2.6
作者:
Jon M. Boyens;Celia Paulsen;Rama S Moorthy;Nadya Bartol
通讯作者:
Nadya Bartol
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
Jon M. Boyens;Angela Smith;Nadya Bartol;Kris Winkler;Alex Holbrook;Matthew Fallon
通讯作者:
Matthew Fallon
DOI:
10.1145/3510003.3510168
发表时间:
2022
期刊:
2022 IEEE/ACM 44th International Conference on Software Engineering (ICSE)
影响因子:
--
作者:
Elizabeth Wyss;Lorenzo De Carli;Drew Davidson
通讯作者:
Drew Davidson