The University of Southampton
University of Southampton Institutional Repository

Software supply chain: review of attacks, risk assessment strategies and security controls

Software supply chain: review of attacks, risk assessment strategies and security controls
Software supply chain: review of attacks, risk assessment strategies and security controls
The software product is a source of cyber-attacks that target organizations by using their software supply chain as a distribution vector. As the reliance of software projects on open-source or proprietary modules is increasing drastically, SSC is becoming more and more critical and, therefore, has attracted the interest of cyber attackers. While existing studies primarily focus on software supply chain attacks' prevention and detection methods, there is a need for a broad overview of attacks and comprehensive risk assessment for software supply chain security. This study conducts a systematic literature review to fill this gap. We analyze the most common software supply chain attacks by providing the latest trend of analyzed attacks, and we identify the security risks for open-source and third-party software supply chains. Furthermore, this study introduces unique security controls to mitigate analyzed cyber-attacks and risks by linking them with real-life security incidence and attacks.
Software Supply Chain, Security, Risk, Attack, Security Controls
arXiv
Gokkaya, Betul
7c7964ae-106f-4f4f-8ea4-01fb4c65caac
Aniello, Leonardo
9846e2e4-1303-4b8b-9092-5d8e9bb514c3
Halak, Basel
8221f839-0dfd-4f81-9865-37def5f79f33
Gokkaya, Betul
7c7964ae-106f-4f4f-8ea4-01fb4c65caac
Aniello, Leonardo
9846e2e4-1303-4b8b-9092-5d8e9bb514c3
Halak, Basel
8221f839-0dfd-4f81-9865-37def5f79f33

[Unknown type: UNSPECIFIED]

Record type: UNSPECIFIED

Abstract

The software product is a source of cyber-attacks that target organizations by using their software supply chain as a distribution vector. As the reliance of software projects on open-source or proprietary modules is increasing drastically, SSC is becoming more and more critical and, therefore, has attracted the interest of cyber attackers. While existing studies primarily focus on software supply chain attacks' prevention and detection methods, there is a need for a broad overview of attacks and comprehensive risk assessment for software supply chain security. This study conducts a systematic literature review to fill this gap. We analyze the most common software supply chain attacks by providing the latest trend of analyzed attacks, and we identify the security risks for open-source and third-party software supply chains. Furthermore, this study introduces unique security controls to mitigate analyzed cyber-attacks and risks by linking them with real-life security incidence and attacks.

Text
2305.14157v1 - Author's Original
Download (768kB)

More information

Published date: 23 May 2023
Keywords: Software Supply Chain, Security, Risk, Attack, Security Controls

Identifiers

Local EPrints ID: 503718
URI: http://eprints.soton.ac.uk/id/eprint/503718
PURE UUID: 305d0a1e-14af-4d2c-a353-5838e67e2ed0
ORCID for Betul Gokkaya: ORCID iD orcid.org/0009-0009-3632-9768
ORCID for Leonardo Aniello: ORCID iD orcid.org/0000-0003-2886-8445
ORCID for Basel Halak: ORCID iD orcid.org/0000-0003-3470-7226

Catalogue record

Date deposited: 11 Aug 2025 16:53
Last modified: 22 Aug 2025 02:28

Export record

Altmetrics

Contributors

Author: Betul Gokkaya ORCID iD
Author: Leonardo Aniello ORCID iD
Author: Basel Halak ORCID iD

Download statistics

Downloads from ePrints over the past year. Other digital versions may also be available to download e.g. from the publisher's website.

View more statistics

Atom RSS 1.0 RSS 2.0

Contact ePrints Soton: eprints@soton.ac.uk

ePrints Soton supports OAI 2.0 with a base URL of http://eprints.soton.ac.uk/cgi/oai2

This repository has been built using EPrints software, developed at the University of Southampton, but available to everyone to use.

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we will assume that you are happy to receive cookies on the University of Southampton website.

×