Fighting Supply Chain Attacks with Effect Systems
Magnus Madsen, Andreas Stenbæk Larsen, Jakob Schneider Villumsen, Aslan Askarov
摘要
Today, most software is developed by building on packages, allowing developers to accelerate development. The proliferation of package dependencies creates a target-rich environment for malicious actors to hijack packages to inject malware, steal sensitive information, or cause destruction. Such supply chain attacks constantly threaten package ecosystems such as Cargo, npm, and Maven. In this paper, we explore how to fight against such attacks by leveraging effect systems. While effect systems predict the behavior of software components, there is a practical gap between a programming language with an effect system and a programming language ecosystem that can use such effects to thwart attacks. To close this gap, we introduce a notion of an effect-safe package upgrade and develop an effect-aware package manager that enforces safety through effect lock files. We extend the Flix programming language and its compiler toolchain with an effect-aware package manager. We evaluate the usefulness of the proposed effect-aware package manager with a case study of 51 supply chain attacks from the "Backstabbers Knife Collection" corpus of malware. The study suggests that 48 of these attacks are likely preventable with our proposed effect-aware package manager.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted LanguagesRuian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder 等NDSS 2021
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl 等ICSE 2025 · 被引用 1 次
- Beyond Typosquatting: An In-depth Look at Package ConfusionShradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson 等USENIX Security 2023
- Associated Effects: Flexible Abstractions for Effectful ProgrammingMatthew Lutze, Magnus MadsenPLDI 2024 · 被引用 9 次
- Maltracker: A Fine-Grained NPM Malware Tracker Copiloted by LLM-Enhanced DatasetZeliang Yu, Ming Wen, Xiaochen Guo, Hai JinISSTA 2024 · 被引用 16 次
