Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Exploring Risk: Understanding Software Supply Chain Attacks

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
1,175
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

Open-source software supply chain attacks, which involve injecting malicious code into open-source projects, have become increasingly common, with attackers employing techniques like typosquatting and dependency confusion. To address this, a comprehensive taxonomy was developed in 2021 by Piergiorgio Ladisa and his colleagues, offering a technology-agnostic overview of attack vectors. This taxonomy, structured as an attack tree with over 100 nodes, aims to systematically classify these attacks and enhance understanding of the threat landscape. The taxonomy is accompanied by the Risk Explorer tool, which provides an interactive visualization of attack vectors to facilitate education, threat modeling, and risk assessment. This tool is open-sourced and hosted by SAP, with contributions from Endor Labs, and is continuously updated to remain relevant amidst evolving threats. The taxonomy and Risk Explorer have been presented at various conferences and are intended to be part of broader industry efforts to secure software supply chains.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.