Skip to main content

Showing 1–2 of 2 results for author: Singla, T

Searching in archive cs. Search in all archives.
.
  1. arXiv:2310.14117  [pdf, other

    cs.CR cs.SE

    ZTD$_{JAVA}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies

    Authors: Paschal C. Amusuo, Kyle A. Robinson, Tanmay Singla, Huiyun Peng, Aravind Machiry, Santiago Torres-Arias, Laurent Simon, James C. Davis

    Abstract: Third-party software components like Log4J accelerate software application development but introduce substantial risk. These components have led to many software supply chain attacks. These attacks succeed because third-party software components are implicitly trusted in an application. Although several security defenses exist to reduce the risks from third-party software components, none of them… ▽ More

    Submitted 25 April, 2024; v1 submitted 21 October, 2023; originally announced October 2023.

    Comments: 15 pages, 5 figures, 5 tables

    ACM Class: K.6.5; D.4.6

  2. arXiv:2308.04898  [pdf, other

    cs.CR cs.LG cs.SE

    An Empirical Study on Using Large Language Models to Analyze Software Supply Chain Security Failures

    Authors: Tanmay Singla, Dharun Anandayuvaraj, Kelechi G. Kalu, Taylor R. Schorlemmer, James C. Davis

    Abstract: As we increasingly depend on software systems, the consequences of breaches in the software supply chain become more severe. High-profile cyber attacks like those on SolarWinds and ShadowHammer have resulted in significant financial and data losses, underlining the need for stronger cybersecurity. One way to prevent future breaches is by studying past failures. However, traditional methods of anal… ▽ More

    Submitted 9 August, 2023; originally announced August 2023.

    Comments: 22 pages, 9 figures