: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
Paschal C. Amusuo, Kyle A. Robinson, Tanmay Singla, Huiyun Peng, Aravind Machiry, Santiago Torres-Arias, Laurent Simon, James C. Davis
摘要
Third-party libraries like Log4j accelerate software application development but introduce substantial risk. Vulnerabilities in these libraries have led to Software Supply Chain (SSC) attacks that compromised resources within the host system. These attacks benefit from current application permissions approaches: third-party libraries are implicitly trusted in the application runtime. An application runtime designed with ZeroTrust Architecture (ZTA) principles - secure access to resources, continuous monitoring, and least-privilege enforcement - could mitigate SSC attacks, as it would give zero implicit trust to these libraries. However, no individual security defense incorporates these principles at a low runtime cost. This paper proposes Zero-Trust Dependencies to mitigate SSC vulnerabilities: we apply the NIST ZTA to software applications. First, we assess the expected effectiveness and configuration cost of Zero-Trust Dependencies using a study of third-party software libraries and their vulnerabilities. Then, we present a system design, <tex xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink"></tex>, that enables the application of Zero-Trust Dependencies to software applications and a prototype, <tex xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink"></tex>, for Java applications. Finally, with evaluations on recreated vulnerabilities and realistic applications, we show that <tex xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink"></tex> can defend against prevalent vulnerability classes, introduces negligible cost, and is easy to configure and use.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- FLEXDROID: Enforcing In-App Privilege Separation in AndroidJaebaek Seo, Daehyeok Kim, Donghyun Cho, Insik Shin 等NDSS 2016 · 被引用 114 次
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola 等USENIX Security 2019 · 被引用 98 次
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn 等NDSS 2018 · 被引用 66 次
- PMFuzz: test case generation for persistent memory programsSihang Liu, Suyash Mahar, Baishakhi Ray, Samira Manabi KhanASPLOS 2021 · 被引用 36 次
相关 Paper
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines 等ICSE 2026 · 被引用 5 次
- Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its EcosystemAbdullah AlHamdan, Cristian-Alexandru StaicuNDSS 2025
- RTrace: Towards Better Visibility of Shared Library ExecutionHuaifeng Zhang, Ahmed Ali-EldinNDSS 2026
- Sleeping Giants - Activating Dormant Java Deserialization Gadget Chains through Stealthy Code ChangesBruno Kreyssig, Sabine Houy, Timothée Riom, Alexandre BartelCCS 2025
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai 等NDSS 2026 · 被引用 1 次
