This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool "Risk Explorer for Software Supply Chains" to explore such information and we discuss its industrial use-cases.
翻译:本文讨论开源软件供应链攻击,并提出描述攻击者实施攻击方式的通用分类法。随后,我们提供一系列防护措施以缓解此类攻击。我们展示了工具“软件供应链风险探索器”用于探索相关信息,并讨论其工业应用场景。