GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Sicherheit
  • P323 - Sicherheit 2022 - Sicherheit, Schutz und Zuverlässigkeit
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • Sicherheit
  • P323 - Sicherheit 2022 - Sicherheit, Schutz und Zuverlässigkeit
  • Dokumentanzeige

Towards Detection of Malicious Software Packages Through Code Reuse by Malevolent Actors

Autor(en):
Ohm, Marc [DBLP] ;
Kempf, Lukas [DBLP] ;
Boes, Felix [DBLP] ;
Meier, Michael [DBLP]
Zusammenfassung
Trojanized software packages used in software supply chain attacks constitute an emerging threat. Unfortunately, there is still a lack of scalable approaches that allow automated and timely detection of malicious software packages and thus most detections are based on manual labor and expertise. However, it has been observed that most attack campaigns comprise multiple packages that share the same or similar malicious code. We leverage that fact to automatically reproduce manually identified clusters of known malicious packages that have been used in real world attacks, thus, reducing the need for expert knowledge and manual inspection. Our approach, AST Clustering using MCL to mimic Expertise (ACME), yields promising results with a F1 score of 0.99. Signatures are automatically generated based on characteristic code fragments from clusters and are subsequently used to scan the whole npm registry for unreported malicious packages. We are able to identify and report six malicious packages that have been removed from npm consequentially. Therefore, our approach can support the detection by reducing manual labor and hence may be employed by maintainers of package repositories to detect possible software supply chain attacks through trojanized software packages.
  • Vollständige Referenz
  • BibTeX
Ohm, M., Kempf, L., Boes, F. & Meier, M., (2022). Towards Detection of Malicious Software Packages Through Code Reuse by Malevolent Actors. In: Christian Wressnegger, D. R. (Hrsg.), GI SICHERHEIT 2022. Gesellschaft für Informatik, Bonn. (S. 35-47). DOI: 10.18420/sicherheit2022_02
@inproceedings{mci/Ohm2022,
author = {Ohm, Marc AND Kempf, Lukas AND Boes, Felix AND Meier, Michael},
title = {Towards Detection of Malicious Software Packages Through Code Reuse by Malevolent Actors},
booktitle = {GI SICHERHEIT 2022},
year = {2022},
editor = {Christian Wressnegger, Delphine Reinhardt} ,
pages = { 35-47 } ,
doi = { 10.18420/sicherheit2022_02 },
publisher = {Gesellschaft für Informatik, Bonn},
address = {}
}
DateienGroesseFormatAnzeige
B1-2.pdf287.5Kb PDF Öffnen

Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.18420/sicherheit2022_02

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

DOI: 10.18420/sicherheit2022_02
ISBN: 978-3-88579-717-3
ISSN: 1617-5468
Datum: 2022
Sprache: en (en)

Keywords

  • Software Supply Chain
  • Malware
  • Abstract Syntax Tree
  • Markov Cluster Algorithm
Sammlungen
  • P323 - Sicherheit 2022 - Sicherheit, Schutz und Zuverlässigkeit [22]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.