Plotting OSS-Based Supply Chain Attack Strategies and the Defense Failure
摘要
The supply chain attack, which targets open-source software, is currently the most discussed cyberattack. This is due to the recent open-source XZ utils and PyPI projects based attacks where the attackers employed similar strategies. A backdoor was injected in the libraries developed by these projects for future exploitation when software users installed them on systems. These attacks were executed by the trusted developers of these projects and influenced by unknown promoters. Therefore, there is a need to scrutinize Open Source Software (OSS) Security to protect the legacy of Open Software development for the future. This paper provides an overview of these two attack strategies through their case studies, which aid in the creation of a generic attack framework for supply chain attacks on OSS. We present the existing detection methods for OSS security in this work and their lacunas taking into account at various stages of a supply chain attack. This makes it necessary to build platforms that allow the current OSS security detection modules to be utilized in sequence. Therefore, we introduce an OSS security Detection platform that does not completely address the limitations of the detection technique, but when combined, they can maximize the effectiveness of an OSS security quality check.