Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils
Sivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines, Chris Madden, Laurie Williams
摘要
Software supply chain frameworks, such as the US NIST Secure Software Development Framework (SSDF), detail what tasks software development organizations are recommended or mandated to adopt to reduce security risk. However, to further reduce the risk of similar attacks occurring, software organizations benefit from knowing what tasks mitigate attack techniques the attackers are currently using to address specific threats, prioritize tasks, and close mitigation gaps. The goal of this study is to aid software organizations in reducing the risk of software supply chain attacks by systematically synthesizing how framework tasks mitigate the attack techniques used in the SolarWinds, Log4j, and XZ Utils attacks. We qualitatively analyzed 106 Cyber Threat Intelligence (CTI) reports of the 3 attacks to gather the attack techniques. We then systematically constructed a mapping between attack techniques and the 73 tasks enumerated in 10 software supply chain frameworks. Afterward, we established and ranked priority tasks that mitigate attack techniques. The three mitigation tasks with the highest scores are role-based access control, system monitoring, and boundary protection. Additionally, three mitigation tasks were missing from all ten frameworks, including sustainable open-source software and environmental scanning tools. Thus, software products would still be vulnerable to software supply chain attacks even if organizations adopted all recommended tasks.
• Software and its engineering → Development frameworks and environments; Risk management; • Security and privacy → Software and application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola 等USENIX Security 2019 · 被引用 98 次
- BOMs Away! Inside the Minds of Stakeholders: A Comprehensive Study of Bills of Materials for Software SystemsTrevor Stalnaker, Nathan Wintersgill, Oscar Chaparro, Massimiliano Di Penta 等ICSE 2024 · 被引用 50 次
- Sigstore: Software Signing for EverybodyZachary Newman, John Speed Meyers, Santiago Torres-AriasCCS 2022 · 被引用 35 次
- How Ready is Your Ready? Assessing the Usability of Incident Response Playbook FrameworksRock Stevens, Daniel Votipka, Josiah Dykstra, Fernando Tomlinson 等CHI 2022 · 被引用 29 次
- Leveraging Large Language Models to Detect NPM Malicious PackagesNusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh 等ICSE 2025 · 被引用 8 次
相关 Paper
- : Mitigating Software Supply Chain Vulnerabilities via Zero-Trust DependenciesPaschal C. Amusuo, Kyle A. Robinson, Tanmay Singla, Huiyun Peng 等ICSE 2025 · 被引用 2 次
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl 等USENIX Security 2025
- Where is it? Tracing the Vulnerability-relevant Files from Vulnerability ReportsJiamou Sun, Jieshan Chen, Zhenchang Xing, Qinghua Lu 等ICSE 2024 · 被引用 8 次
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl 等ICSE 2025 · 被引用 1 次
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
