3 papers
cs.CR2025
Finding Software Supply Chain Attack Paths with Logical Attack Graphs
Luıs Soeiro, Thomas Robert, Stefano Zacchiroli
Cyberattacks are becoming increasingly frequent and sophisticated, often exploiting the software supply chain (SSC) as an attack vector. Attack graphs provide a detailed representa…
cs.SE2025
Wild SBOMs: a Large-scale Dataset of Software Bills of Materials from Public Code
Luıs Soeiro, Thomas Robert, Stefano Zacchiroli
Developers gain productivity by reusing readily available Free and Open Source Software (FOSS) components. Such practices also bring some difficulties, such as managing licensing,…
cs.CR2023
Assessing the Threat Level of Software Supply Chains with the Log Model
Luıs Soeiro, Thomas Robert, Stefano Zacchiroli
The use of free and open source software (FOSS) components in all software systems is estimated to be above 90%. With such high usage and because of the heterogeneity of FOSS tools…