Commit Signatures for Centralized Version Control Systems

Commit Signatures for Centralized Version Control Systems
复制标题

集中版本控制系统的提交签名

DOI:
--
复制
发表时间:
2019
期刊:
IFIP International Information Security Conference
影响因子:
--
通讯作者:
Justin Cappos
Justin Cappos
中科院分区:
--
文献类型:
--
作者:
Sangat Vaidya;Santiago Torres;Reza Curtmola;Justin Cappos

文献摘要

被引文献

相似文献

版本控制系统(VCS-ES)在软件开发生命周期中扮演着重要的角色,但从历史上看,与其重要性相比,它们的安全性一直相对不发达。最近的历史表明,源代码存储库代表了吸引人的攻击目标。破坏存储库数据完整性的攻击可能会对数百万用户造成负面影响。一些VCS-E,如Git,使用提交签名作为一种机制,为开发人员提供对他们贡献给存储库的代码的加密保护。然而,包括著名的ApacheSubversion(SVN)在内的一整类其他VCS-E都缺乏这样的保护。
Version Control Systems (VCS-es) play a major role in the software development life cycle, yet historically their security has been relatively underdeveloped compared to their importance. Recent history has shown that source code repositories represent appealing attack targets. Attacks that violate the integrity of repository data can impact negatively millions of users. Some VCS-es, such as Git, employ commit signatures as a mechanism to provide developers with cryptographic protections for the code they contribute to a repository. However, an entire class of other VCS-es, including the well-known Apache Subversion (SVN), lacks such protections.