【24h】

Detecting Suspicious Package Updates

机译:检测可疑软件包更新

获取原文
获取原文并翻译 | 示例

摘要

With an increased level of automation provided by package managers, which sometimes allow updates to be installed automatically, malicious package updates are becoming a real threat in software ecosystems. To address this issue, we propose an approach based on anomaly detection, to identify suspicious updates based on security-relevant features that attackers could use in an attack. We evaluate our approach in the context of Node.jspm ecosystem, to show its feasibility in terms of reduced review effort and the correct identification of a confirmed malicious update attack. Although we do not expect it to be a complete solution in isolation, we believe it is an important security building block for software ecosystems.
机译:随着软件包管理器提供的自动化程度的提高,有时允许自动安装更新,恶意软件包更新正成为软件生态系统中的真正威胁。为了解决此问题,我们提出了一种基于异常检测的方法,以基于攻击者可以在攻击中使用的与安全相关的功能来识别可疑更新。我们在Node.js / npm生态系统的背景下评估我们的方法,以减少审查工作并正确识别已确认的恶意更新攻击来显示其可行性。尽管我们不希望它孤立地成为完整的解决方案,但我们认为它是软件生态系统的重要安全构建块。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号