8 citations · 19 across the 17 of their papers we have counts for
4 papers · 1 filter
Not In My Git Yard: Catching Backdoors at Commit and Release Time
Dimitri Kokkonis, Michaël Marcozzi, Stefano Zacchiroli
Code-level backdoors-stealthy code changes that grant hidden privileges via secret triggers-pose a persistent threat to opensource software. Known attempts to inject such backdoors…
Finding Software Supply Chain Attack Paths with Logical Attack Graphs
Luıs Soeiro, Thomas Robert, Stefano Zacchiroli
Cyberattacks are becoming increasingly frequent and sophisticated, often exploiting the software supply chain (SSC) as an attack vector. Attack graphs provide a detailed representa…
ROSA: Finding Backdoors with Fuzzing
Dimitri Kokkonis, Michaël Marcozzi, Emilien Decoux +1
A code-level backdoor is a hidden access, programmed and concealed within the code of a program. For instance, hard-coded credentials planted in the code of a file server applicati…
Assessing the Threat Level of Software Supply Chains with the Log Model
Luıs Soeiro, Thomas Robert, Stefano Zacchiroli
The use of free and open source software (FOSS) components in all software systems is estimated to be above 90%. With such high usage and because of the heterogeneity of FOSS tools…