Uppsats

Supply chain attacks in open source projects

Master-uppsats

Lunds universitet/Institutionen för elektro- och informationsteknik

Publicerad: 2022

Språk: Engelska

Nyckelord

klicka för att söka

Sammanfattning

The space of open source supply chain attacks is ever evolving and growing. There is extensive previous work identifying and collecting open source supply chain attacks, as well as identifying patterns in these attacks and proving that machine learning models may be able to detect these patterns. The aim of this thesis is to develop such a system and study its efficacy in detecting attacks. To achieve this, packages from the npm Registry, PyPi, and RubyGems originating from three previous data sets were combined into one data set and manually labeled. UniXcoder was used to generate embeddings of the source code, these were then fed to the Markov Clustering Algorithm to create clusters of attacks. Unknown files were compared against representative embeddings of these clusters to classify them as either malicious or benign. Two different methods for cluster generation and three different cluster optimization metrics were explored. The best performing approach achieved a F1 score of 0.85, outperforming a similar approach within the field. This approach seems to have no major differences in performance between obfuscated or un-obfuscated attacks. Neither did the programming language of attacks seem to impact performance significantly.

Information

Lärosäte / institution
Lunds universitet/Institutionen för elektro- och informationsteknik
Publiceringsdatum
2022
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.