Journey to the Center of Software Supply Chain Attacks

Piergiorgio Ladisa, Serena Elisa Ponta, Antonino Sabetta, Matías Martínez, Olivier Barais · IEEE Security & Privacy · 2023

This article discusses open source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool Risk Explorer for Software Supply Chains to explore such information, and we discuss its industrial use-cases.

Read the paper · More papers on PaperTik