Fighting Supply Chain Attacks with Effect Systems
This program is tentative and subject to change.
Today, most software is developed by leveraging existing packages, allowing developers to accelerate development. The proliferation of package dependencies creates a target-rich environment for malicious actors to inject malware, steal sensitive information, or cause destruction. Such supply-chain attacks constantly threaten package ecosystems such as Cargo, NPM, and Maven.
In this paper, we explore how to fight against such attacks by leveraging effect systems. While effect systems predict the behavior of software components, there is a practical gap between a programming language with an effect system and a programming language ecosystem that can use such effects to thwart attacks. To close this gap, we introduce a notion of effect-safe package upgrade and develop an effect-aware package manager that enforces safety through effect lock files.
We extend the Flix programming language and its compiler toolchain with an effect-aware package manager. We introduce the notion of secure, trusted, and unsafe packages to control access to the Java Class Library and Java Virtual Machine. We evaluate the usefulness of the proposed effect-aware package manager with a case study of 51 supply-chain attacks from the ``Backstabbers Knife Collection'' corpus of malware. The study suggests that 48 of these attacks are likely preventable with our proposed effect-aware package manager.
This program is tentative and subject to change.
Wed 7 OctDisplayed time zone: Pacific Time (US & Canada) change
13:30 - 15:00 | Security and Information FlowOOPSLA at Junior Ballroom 1&2 Chair(s): Mae Milano Princeton University | ||
13:30 18mTalk | (Dis)Proving Spectre Security with Speculation-Passing Style OOPSLA Santiago Arranz Olmos Max Planck Institute for Security and Privacy, Gilles Barthe MPI-SP; IMDEA Software Institute, Lionel Blatter Max Planck Institute for Security and Privacy, Xingyu Xie MPI-SP, Zhiyuan Zhang MPI-SP | ||
13:48 18mTalk | Decompiling for Constant-Time Analysis OOPSLA Santiago Arranz Olmos Max Planck Institute for Security and Privacy, Gilles Barthe MPI-SP; IMDEA Software Institute, Lionel Blatter Max Planck Institute for Security and Privacy, Youcef Bouzid ENS Paris-Saclay, Sören van der Wall TU Braunschweig, Zhiyuan Zhang MPI-SP | ||
14:06 18mTalk | Sound Enforcement of Dynamic Release Information Flow Policy OOPSLA | ||
14:24 18mTalk | A Type System for Optimizing Dynamic IFC OOPSLA Daniel Galán Pascual ETH Zurich, François Hublet ETH Zurich, Srđan Krstić ETH Zürich, Roman Fischer ETH Zurich, Colin Pfingstl ETH Zurich, David Basin ETH Zurich | ||
14:42 18mTalk | Fighting Supply Chain Attacks with Effect Systems OOPSLA Magnus Madsen Aarhus University, Andreas Stenbæk Larsen Aarhus University, Jakob Schneider Villumsen Aarhus University, Aslan Askarov Aarhus University | ||