5 papers
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
Tom Sorger, Eric Cornelissen, Aman Sharma +3
Software Bills of Materials (SBOMs) are increasingly mandated by regulators, yet existing sharing mechanisms impose a binary choice between full disclosure and full opacity. This e…
Granite: Granular Runtime Enforcement for GitHub Actions Permissions
Mojtaba Moazen, Amir. M Ahmadian, Musard Balliu
Modern software projects use automated CI/CD pipelines to streamline their development, build, and deployment processes. GitHub Actions is a popular CI/CD platform that enables pro…
NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js
Eric Cornelissen, Musard Balliu
The software supply chain is an increasingly common attack vector for malicious actors. The Node.js ecosystem has been subject to a wide array of attacks, likely due to its size an…
Securing P4 Programs by Information Flow Control
Anoud Alshnakat, Amir M. Ahmadian, Musard Balliu +2
Software-Defined Networking (SDN) has transformed network architectures by decoupling the control and data-planes, enabling fine-grained control over packet processing and forwardi…
Sharing without Showing: Secure Cloud Analytics with Trusted Execution Environments
Marcus Birgersson, Cyrille Artho, Musard Balliu
Many applications benefit from computations over the data of multiple users while preserving confidentiality. We present a solution where multiple mutually distrusting users' data…