CCS2025

What Gets Measured Gets Managed: Mitigating Supply Chain Attacks with a Link Integrity Management System

Johnny So, Michael Ferdman, Nick Nikiforakis

Abstract

The web continues to grow, but dependency-monitoring tools and standards for resource integrity lag behind. Currently, there exists no robust method to verify the integrity of web resources, much less in a generalizable yet performant manner, and supply chains remain one of the most targeted parts of the attack surface of web applications.