• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. SoK: Practical Detection of Software Supply Chain Attacks
 
  • Details
  • Full
Options
2023
Conference Paper
Title

SoK: Practical Detection of Software Supply Chain Attacks

Abstract
Detecting malicious packages used in software supply chain attacks has become increasingly important in recent years. Researchers are constantly developing and evaluating different tools and approaches. However, a comparison of all scientific publications on this topic does not yet exist. This paper examines existing publications and points out their characteristics, advantages and limitations. We identified and analyzed 20 publications that deal with malicious package detection. For those, we summarize the key points of each approach, present the experiments performed, discuss the features and limitations of each, and finally compare them to each other. We show that some tools and approaches are outdated, not fully evaluated, or not feasible for production use. Promising approaches for automatic detection of attacks in the software supply chain are outlined as well.
Author(s)
Ohm, Marc
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Stuke, Charlene
Universität Bonn
Mainwork
ARES 2023, the 18th International Conference on Availability, Reliability and Security. Proceedings  
Conference
International Conference on Availability, Reliability and Security 2023  
DOI
10.1145/3600160.3600162
Language
English
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
Keyword(s)
  • Application Security

  • Malware

  • Software Supply Chain

  • Systematization of Knowledge

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024