3 citations · 3 across the 6 of their papers we have counts for
4 papers · 1 filter
Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation
Julien Malka, Aman Sharma, Martin Monperrus +2
Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regar…
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
Tom Sorger, Eric Cornelissen, Aman Sharma +3
Software Bills of Materials (SBOMs) are increasingly mandated by regulators, yet existing sharing mechanisms impose a binary choice between full disclosure and full opacity. This e…
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
Frank Reyes, Federico Bono, Aman Sharma +2
Java projects frequently rely on package managers such as Maven to manage complex webs of external dependencies. While these tools streamline development, they also introduce subtl…
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
Aman Sharma, Martin Wittlinger, Benoit Baudry +1
Software supply chain attacks have become a significant threat as software development increasingly relies on contributions from multiple, often unverified sources. The code from u…