Exploring Risk: Understanding Software Supply Chain Attacks
Blog post from Endor Labs
Open-source software supply chain attacks, which involve injecting malicious code into open-source projects, have become increasingly common, with attackers employing techniques like typosquatting and dependency confusion. To address this, a comprehensive taxonomy was developed in 2021 by Piergiorgio Ladisa and his colleagues, offering a technology-agnostic overview of attack vectors. This taxonomy, structured as an attack tree with over 100 nodes, aims to systematically classify these attacks and enhance understanding of the threat landscape. The taxonomy is accompanied by the Risk Explorer tool, which provides an interactive visualization of attack vectors to facilitate education, threat modeling, and risk assessment. This tool is open-sourced and hosted by SAP, with contributions from Endor Labs, and is continuously updated to remain relevant amidst evolving threats. The taxonomy and Risk Explorer have been presented at various conferences and are intended to be part of broader industry efforts to secure software supply chains.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.