3 papers
cs.CR2026
VeriPort: Automated and Verified Patch Backporting at Scale
Jonah Ghebremichael, Wenxin Jiang, Mikola Lysenko +3
One of the key challenges for securing the software supply chain is addressing known vulnerabilities in third-party open-source dependencies. Security patches are frequently only a…
cs.CR2025
ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale
Wenxin Jiang, Berk Çakar, Mikola Lysenko +1
Package confusion attacks such as typosquatting threaten software supply chains. Attackers make packages with names that syntactically or semantically resemble legitimate ones, tri…
cs.CR2024
Leveraging Large Language Models to Detect npm Malicious Packages
Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko +2
Existing malicious code detection techniques demand the integration of multiple tools to detect different malware patterns, often suffering from high misclassification rates. There…