2023 An Analysis of Social Engineering Techniques in Launching Software Supply Chain Attacks Grant uri icon

Abstract

  • An analysis of social engineering techniques in launching software supply chain attacks:
    Any software can introduce vulnerabilities into a supply chain. As a system gets more complex, it’s critical to have checks and best practices to guarantee artifact integrity. Executive Order 14028 establishes new requirements such as systematic reviews, process improvements, and security standards for software suppliers, developers, and customers who acquire software for the Federal Government to secure the federal government's software supply chain. Primarily the focus has been on the technical aspect of security, including introducing the Supply Chain Levels for Software Artifacts (SLSA) framework. We want to study the impact of social engineering in launching software supply chain attacks based on SLSA, and analyze attacks in different steps of continuous integration/continuous delivery, including source code, build time, dependencies, and software distribution. We develop criteria to investigate these attacks and identify common attacks, existing countermeasures, and the security gaps that should be addressed by research and industry communities.
  • An analysis of social engineering techniques in launching software supply chain attacks:
    Any software can introduce vulnerabilities into a supply chain. As a system gets more complex, it’s critical to have checks and best practices to guarantee artifact integrity. Executive Order 14028 establishes new requirements such as systematic reviews, process improvements, and security standards for software suppliers, developers, and customers who acquire software for the Federal Government to secure the federal government's software supply chain. Primarily the focus has been on the technical aspect of security, including introducing the Supply Chain Levels for Software Artifacts (SLSA) framework. We want to study the impact of social engineering in launching software supply chain attacks based on SLSA, and analyze attacks in different steps of continuous integration/continuous delivery, including source code, build time, dependencies, and software distribution. We develop criteria to investigate these attacks and identify common attacks, existing countermeasures, and the security gaps that should be addressed by research and industry communities.


Date/time Interval

  • 2023-08-01 - 2024-12-01

Date Filed

  • 2023-03-01

Total Award Amount

  • 57000