activity
20242026
collaborators

6 papers

cs.CR2026

S3C2 Summit 2025-07: Government Secure Supply Chain Summit

Sivana Hamer, Pat Morrison, William Enck +6

Software supply chains, while providing immense economic and software development value, are only as strong as their weakest link. Over the past several years, there has been an ex…

cs.SE2026

Beyond Single Reports: Evaluating Automated ATT&CK Technique Extraction in Multi-Report Campaign Settings

Md Nazmul Haque, Sivana Hamer, Brandon Wroblewski +2

Large-scale cyberattacks, referred to as campaigns, are documented across multiple CTI reports from diverse sources, with some providing a high-level overview of attack techniques…

cs.SE2025

Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping

Sivana Hamer, Jacob Bowen, Md Nazmul Haque +3

The MITRE Adversarial Tactics, Techniques and Common Knowledge (MITRE ATT&CK) Attack Technique to Proactive Software Supply Chain Risk Management Framework (P-SSCRM) Task mapping d…

cs.SE2025

Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ Utils

Sivana Hamer, Jacob Bowen, Md Nazmul Haque +3

Software supply chain frameworks, such as the US NIST Secure Software Development Framework (SSDF), detail what tasks software development organizations are recommended or mandated…

cs.CE2024

Analyzing Challenges in Deployment of the SLSA Framework for Software Supply Chain Security

Mahzabin Tamanna, Sivana Hamer, Mindy Tran +3

In 2023, Sonatype reported a 200\% increase in software supply chain attacks, including major build infrastructure attacks. To secure the software supply chain, practitioners can f…

cs.SE2024

Trusting code in the wild: Exploring contributor reputation measures to review dependencies in the Rust ecosystem

Sivana Hamer, Nasif Imtiaz, Mahzabin Tamanna +2

Developers rely on open-source packages and must review dependencies to safeguard against vulnerable or malicious upstream code. A careful review of all dependencies changes often…