REVIEW 5 cited by
On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from XZ
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
An emerging supply-chain attack due to a backdoor in XZ Utils has been identified. The backdoor allows an attacker to run commands remotely on vulnerable servers utilizing SSH without prior authentication. We have started to collect available information with regards to this attack to discuss current mitigation strategies for such kinds of supply-chain attacks. This paper introduces the critical attack path of the XZ backdoor and provides an overview about potential mitigation techniques related to relevant stages of the attack path.
Forward citations
Cited by 5 Pith papers
-
Threadbox: Sandboxing for Modular Security
Threadbox is a thread-granular, non-inheriting Linux sandbox with Pledge-like promises and function-level annotation, demonstrated on Flask, magic-wormhole, and a PDF reader.
-
Playing in the Sandbox: A Study on the Usability of Seccomp
Seven experienced developers produced different Seccomp sandboxes for the same program, struggled to map syscalls to code, and often built over-privileged or fragile policies.
-
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
The paper proposes ARMS, a reputation framework with seven security signals and metrics to help OSS maintainers assess contributor cybersecurity risk.
-
A Compact Broadband Purcell Filter for Superconducting Quantum Circuits in a 3D Flip-Chip Architecture
A four-pole 3D flip-chip Purcell filter gives a flat 1 GHz passband at 7.68 GHz with >45 dB stopband suppression and supports six strongly coupled multiplexed readout resonators.
-
Towards Socio-Technical Topology-Aware Adaptive Threat Detection in Software Supply Chains
Socio-technical monitoring of developer behavior and code changes could flag supply-chain attacks, as illustrated retrospectively on the XZ Utils backdoor.
Discussion (0). Continue with ORCID to comment.