3 citations · 6 across the 15 of their papers we have counts for
15 papers
Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations
Abhishek Reddypalle, Dennis Roellke, Santiago Torres-Arias
Modern software supply chains have evolved into vast, heterogeneous networks where transparency - the granular understanding of all software components - is now a critical security…
A Longitudinal Study of Usability in Identity-Based Software Signing
Kelechi G. Kalu, Hieu Tran, Santiago Torres-Arias +2
Identity-based software signing tools aim to make software artifact provenance verifiable while reducing the operational burden of long-lived key management. However, there is limi…
Trustworthy and Confidential SBOM Exchange
Eman Abu Ishgair, Chinenye Okafor, Marcela S. Melara +1
Software Bills of Materials (SBOMs) have become a regulatory requirement for improving software supply chain security and trust by means of transparency regarding components that m…
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
Kelechi G. Kalu, Sofia Okorafor, Betül Durak +4
Many critical information technology and cyber-physical systems rely on a supply chain of open-source software projects. OSS project maintainers often integrate contributions from…
Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore
Kelechi G. Kalu, Sofia Okorafor, Tanmay Singla +3
Software signing is the most robust method for ensuring the integrity and authenticity of components in a software supply chain. Legacy key-managed signing tools (e.g., OpenPGP) bu…
A Study of Malware Prevention in Linux Distributions
Duc-Ly Vu, Trevor Dunlap, Karla Obermeier-Velazquez +4
Malicious attacks on open-source software packages are a growing concern. The discovery of the XZ Utils backdoor intensified these concerns because of the potential widespread impa…