{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2013:PHOE5O3YBVCVBSCP7Q7MB3CZVX","short_pith_number":"pith:PHOE5O3Y","canonical_record":{"source":{"id":"1310.3307","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2013-10-11T22:43:15Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"292a11b41b5e694b25ba88adbc1da92bb249afe054d83e677e705f5ac3e84950","abstract_canon_sha256":"a00e0d30ba84faed5adc81aba8b7ce4de9aeb8daa28652eb25aa21c3a1caab7d"},"schema_version":"1.0"},"canonical_sha256":"79dc4ebb780d4550c84ffc3ec0ec59adef20952cab9f3b6a9c6c9a7923d3941c","source":{"kind":"arxiv","id":"1310.3307","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1310.3307","created_at":"2026-05-18T03:10:36Z"},{"alias_kind":"arxiv_version","alias_value":"1310.3307v1","created_at":"2026-05-18T03:10:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1310.3307","created_at":"2026-05-18T03:10:36Z"},{"alias_kind":"pith_short_12","alias_value":"PHOE5O3YBVCV","created_at":"2026-05-18T12:27:54Z"},{"alias_kind":"pith_short_16","alias_value":"PHOE5O3YBVCVBSCP","created_at":"2026-05-18T12:27:54Z"},{"alias_kind":"pith_short_8","alias_value":"PHOE5O3Y","created_at":"2026-05-18T12:27:54Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2013:PHOE5O3YBVCVBSCP7Q7MB3CZVX","target":"record","payload":{"canonical_record":{"source":{"id":"1310.3307","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2013-10-11T22:43:15Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"292a11b41b5e694b25ba88adbc1da92bb249afe054d83e677e705f5ac3e84950","abstract_canon_sha256":"a00e0d30ba84faed5adc81aba8b7ce4de9aeb8daa28652eb25aa21c3a1caab7d"},"schema_version":"1.0"},"canonical_sha256":"79dc4ebb780d4550c84ffc3ec0ec59adef20952cab9f3b6a9c6c9a7923d3941c","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T03:10:36.163183Z","signature_b64":"FyKhXeNClZjCwwYzuF3X36LRRN9uqGOoBAkM6i06T1pvfeGXTBmnS6+M23Atjv81883by+4XoRlJaIK3w0RJAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"79dc4ebb780d4550c84ffc3ec0ec59adef20952cab9f3b6a9c6c9a7923d3941c","last_reissued_at":"2026-05-18T03:10:36.162567Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T03:10:36.162567Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1310.3307","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:10:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l6WP8J2gSPmJFBHintMuie8DjIBCp1ecYvfklup5rlZ30CNPiY5L/er2WVJRk9Q7mfTN3s7qowc2XW5bPPAXAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-21T21:58:56.111387Z"},"content_sha256":"dff9a99114c36f879f89b4ea955c7d8a6f51b6955453d24b144bc94962e71ea8","schema_version":"1.0","event_id":"sha256:dff9a99114c36f879f89b4ea955c7d8a6f51b6955453d24b144bc94962e71ea8"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2013:PHOE5O3YBVCVBSCP7Q7MB3CZVX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Measuring Software Diversity, with Applications to Security","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Jeremy Rossman, Julio Hernandez-Castro","submitted_at":"2013-10-11T22:43:15Z","abstract_excerpt":"In this work, we briefly introduce and discuss some of the diversity measures used in Ecology. After a succinct description and analysis of the most relevant ones, we single out the Shannon-Weiner index. We justify why it is the most informative and relevant one for measuring software diversity. Then, we show how it can be used for effectively assessing the diversity of various real software ecosystems. We discover in the process a frequently overlooked software monopoly, and its key security implications. We finally extract some conclusions from the results obtained, focusing mostly on their "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1310.3307","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:10:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kFWk0WKyBiFB+lsBT501dcKa9KDP72be9mDLYvloNpv7kJzvbwJHRWUiJuJTP723xVupQ6OTntdH6qUgA/mSAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-21T21:58:56.111737Z"},"content_sha256":"d5ea451700ddaf81de8ae8f5ca0cdefab5d9a96baea2ed01b70c1b263f9d8edf","schema_version":"1.0","event_id":"sha256:d5ea451700ddaf81de8ae8f5ca0cdefab5d9a96baea2ed01b70c1b263f9d8edf"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/PHOE5O3YBVCVBSCP7Q7MB3CZVX/bundle.json","state_url":"https://pith.science/pith/PHOE5O3YBVCVBSCP7Q7MB3CZVX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/PHOE5O3YBVCVBSCP7Q7MB3CZVX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-21T21:58:56Z","links":{"resolver":"https://pith.science/pith/PHOE5O3YBVCVBSCP7Q7MB3CZVX","bundle":"https://pith.science/pith/PHOE5O3YBVCVBSCP7Q7MB3CZVX/bundle.json","state":"https://pith.science/pith/PHOE5O3YBVCVBSCP7Q7MB3CZVX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/PHOE5O3YBVCVBSCP7Q7MB3CZVX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2013:PHOE5O3YBVCVBSCP7Q7MB3CZVX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a00e0d30ba84faed5adc81aba8b7ce4de9aeb8daa28652eb25aa21c3a1caab7d","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2013-10-11T22:43:15Z","title_canon_sha256":"292a11b41b5e694b25ba88adbc1da92bb249afe054d83e677e705f5ac3e84950"},"schema_version":"1.0","source":{"id":"1310.3307","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1310.3307","created_at":"2026-05-18T03:10:36Z"},{"alias_kind":"arxiv_version","alias_value":"1310.3307v1","created_at":"2026-05-18T03:10:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1310.3307","created_at":"2026-05-18T03:10:36Z"},{"alias_kind":"pith_short_12","alias_value":"PHOE5O3YBVCV","created_at":"2026-05-18T12:27:54Z"},{"alias_kind":"pith_short_16","alias_value":"PHOE5O3YBVCVBSCP","created_at":"2026-05-18T12:27:54Z"},{"alias_kind":"pith_short_8","alias_value":"PHOE5O3Y","created_at":"2026-05-18T12:27:54Z"}],"graph_snapshots":[{"event_id":"sha256:d5ea451700ddaf81de8ae8f5ca0cdefab5d9a96baea2ed01b70c1b263f9d8edf","target":"graph","created_at":"2026-05-18T03:10:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"In this work, we briefly introduce and discuss some of the diversity measures used in Ecology. After a succinct description and analysis of the most relevant ones, we single out the Shannon-Weiner index. We justify why it is the most informative and relevant one for measuring software diversity. Then, we show how it can be used for effectively assessing the diversity of various real software ecosystems. We discover in the process a frequently overlooked software monopoly, and its key security implications. We finally extract some conclusions from the results obtained, focusing mostly on their ","authors_text":"Jeremy Rossman, Julio Hernandez-Castro","cross_cats":["cs.SE"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2013-10-11T22:43:15Z","title":"Measuring Software Diversity, with Applications to Security"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1310.3307","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:dff9a99114c36f879f89b4ea955c7d8a6f51b6955453d24b144bc94962e71ea8","target":"record","created_at":"2026-05-18T03:10:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a00e0d30ba84faed5adc81aba8b7ce4de9aeb8daa28652eb25aa21c3a1caab7d","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2013-10-11T22:43:15Z","title_canon_sha256":"292a11b41b5e694b25ba88adbc1da92bb249afe054d83e677e705f5ac3e84950"},"schema_version":"1.0","source":{"id":"1310.3307","kind":"arxiv","version":1}},"canonical_sha256":"79dc4ebb780d4550c84ffc3ec0ec59adef20952cab9f3b6a9c6c9a7923d3941c","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"79dc4ebb780d4550c84ffc3ec0ec59adef20952cab9f3b6a9c6c9a7923d3941c","first_computed_at":"2026-05-18T03:10:36.162567Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T03:10:36.162567Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"FyKhXeNClZjCwwYzuF3X36LRRN9uqGOoBAkM6i06T1pvfeGXTBmnS6+M23Atjv81883by+4XoRlJaIK3w0RJAQ==","signature_status":"signed_v1","signed_at":"2026-05-18T03:10:36.163183Z","signed_message":"canonical_sha256_bytes"},"source_id":"1310.3307","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:dff9a99114c36f879f89b4ea955c7d8a6f51b6955453d24b144bc94962e71ea8","sha256:d5ea451700ddaf81de8ae8f5ca0cdefab5d9a96baea2ed01b70c1b263f9d8edf"],"state_sha256":"8887b2d319125988d3bb12178090f2987cee854bf4ea35f50c1dcfc61262a0b5"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2/mIcydZVgcaRR0dP0FgV5WZcbaEr7/3POUnpGxALE0Oba4qyhpiV3QS8WebDHmXnrCJzSzOMFQvM0bdtVoSBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-21T21:58:56.113649Z","bundle_sha256":"f69d088168fd30a9b92c7270e656b280be74e0895d6ddb7456913a12f50fae07"}}