SOFTWARE SUPPLY CHAIN SECURITY: A TAXONOMY OF ATTACKS AND A COMPARATIVE ANALYSIS OF PROVENANCE-BASED COUNTERMEASURES
Keywords:
software supply chain security, software bill of materials, build provenance, SLSA, in-toto, reproducible builds, dependency confusion, open-source security, continuous integration, trust boundary.Abstract
This article analyses the security of the software supply chain, which has become one of the fastest-growing attack surfaces in modern information systems. A five-stage reference model of the supply chain with explicit trust boundaries is proposed, and a taxonomy of attacks is derived from it in which every class is bound to a concrete injection point: source tampering, dependency abuse, build injection, artifact substitution and delivery tampering. The verification problem is stated formally as a predicate over signed build provenance, and the resulting conditions are then used as evaluation criteria. On this basis the principal countermeasures — the software bill of materials (SPDX and CycloneDX), signed build provenance (in-toto and the SLSA Build levels), artifact signing and reproducible builds — are compared with respect to the attack classes they actually mitigate rather than the guarantees they are commonly assumed to provide. The analysis is validated against the XZ Utils backdoor (CVE-2024-3094). It is shown that a bill of materials and a valid artifact signature would not have prevented that attack, whereas a hermetic build at SLSA Build Level 3 combined with reproducible builds breaks its central mechanism — the divergence between the released source archive and the publicly auditable repository. The residual gap between declared and auditable build inputs is formalised and proposed as a practical assurance metric. The compliance of the examined mechanisms with the legislation of the Republic of Uzbekistan and with international regulation is substantiated. The results indicate that supply chain assurance should be designed as a verification chain over the build process rather than as an inventory of components.
References
1. Ladisa P., Plate H., Martinez M., Barais O. SoK: Taxonomy of Attacks on Open-Source Software Supply Chains // 2023 IEEE Symposium on Security and Privacy (SP). – IEEE, 2023. – P. 1509–1526.
2. Ohm M., Plate H., Sykosch A., Meier M. Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks // Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA 2020). Lecture Notes in Computer Science, vol. 12223. – Cham: Springer, 2020. – P. 23–43.
3. Zahan N., Zimmermann T., Godefroid P., Murphy B., Maddila C., Williams L. What are Weak Links in the npm Supply Chain? // Proceedings of the 44th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP). – IEEE/ACM, 2022. – P. 331–340.
4. Torres-Arias S., Afzali H., Kuppusamy T.K., Curtmola R., Cappos J. in-toto: Providing farm-to-table guarantees for bits and bytes // Proceedings of the 28th USENIX Security Symposium. – USENIX Association, 2019. – P. 1393–1410.
5. Newman Z., Meyers J.S., Torres-Arias S. Sigstore: Software Signing for Everybody // Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS). – ACM, 2022. – P. 2353–2367.
6. Okafor C., Schorlemmer T.R., Torres-Arias S., Davis J.C. SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties // Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED). – ACM, 2022. – P. 15–24.
7. Enck W., Williams L. Top Five Challenges in Software Supply Chain Security: Observations from 30 Industry and Government Organizations // IEEE Security & Privacy. – 2022. – Vol. 20, No. 2. – P. 96–100.
8. Souppaya M., Scarfone K., Dodson D. Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities: NIST Special Publication 800-218. – Gaithersburg: National Institute of Standards and Technology, 2022. – 36 p.
9. Boyens J., Smith A., Bartol N., Winkler K., Holbrook A., Fallon M. Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations: NIST Special Publication 800-161 Revision 1. – Gaithersburg: National Institute of Standards and Technology, 2022. – 326 p.
10. Supply-chain Levels for Software Artifacts (SLSA), Specification version 1.0. – Open Source Security Foundation, 2023. – URL: https://slsa.dev/spec/v1.0/
11. ECMA-424: CycloneDX Bill of Materials Standard, 1st edition. – Geneva: Ecma International, 2024. – 38 p.
12. ISO/IEC 5962:2021. Information technology — SPDX Specification V2.2.1. – Geneva: ISO, 2021. – 192 p.
13. The Minimum Elements For a Software Bill of Materials (SBOM). – Washington: National Telecommunications and Information Administration, United States Department of Commerce, 2021. – 28 p.
14. Executive Order 14028 of May 12, 2021. Improving the Nation’s Cybersecurity // Federal Register. – 2021. – Vol. 86, No. 93. – P. 26633–26647.
15. Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act) // Official Journal of the European Union. – L, 2024/2847, 20.11.2024.
16. Threat Landscape for Supply Chain Attacks. – Athens: European Union Agency for Cybersecurity (ENISA), 2021. – 32 p.
17. Peisert S., Schneier B., Okhravi H., Massacci F., Benzel T., Landwehr C., Mannan M., Aspinall D., Schaumont P., Bishop M. Perspectives on the SolarWinds Incident // IEEE Security & Privacy. – 2021. – Vol. 19, No. 2. – P. 7–13.
18. CVE-2024-3094: Malicious code in the upstream xz/liblzma tarballs. – National Vulnerability Database, National Institute of Standards and Technology, 2024. – URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3094
19. Freund A. Backdoor in upstream xz/liblzma leading to ssh server compromise: oss-security mailing list announcement, 29 March 2024. – URL: https://www.openwall.com/lists/oss-security/2024/03/29/4
20. Open Source Malware Index, Q2 2025. – Fulton: Sonatype Inc., 2025. – 14 p.
21. Cappos J., Samuel J., Baker S., Hartman J.H. A Look in the Mirror: Attacks on Package Managers // Proceedings of the 15th ACM Conference on Computer and Communications Security (CCS). – ACM, 2008. – P. 565–574.
22. Lamb C., Zacchiroli S. Reproducible Builds: Increasing the Integrity of Software Supply Chains // IEEE Software. – 2022. – Vol. 39, No. 2. – P. 62–70.
23. On Cybersecurity: Law of the Republic of Uzbekistan of 15 April 2022, No. ZRU-764. – National Database of Legislation of the Republic of Uzbekistan, No. 03/22/764/0313, 16.04.2022. – URL: https://lex.uz/ru/acts/-5960604
24. On Informatization: Law of the Republic of Uzbekistan of 11 December 2003, No. 560-II (as amended). – URL: https://lex.uz/ru/docs/82956
25. On Personal Data: Law of the Republic of Uzbekistan of 2 July 2019, No. ZRU-547 (as amended). – URL: https://lex.uz/ru/docs/4396428
26. On the Strategy of Development of New Uzbekistan for 2022–2026: Decree of the President of the Republic of Uzbekistan of 28 January 2022, No. UP-60. – URL: https://lex.uz/ru/docs/5841077
Downloads
Published
Versions
- 2026-10-10 (2)
- 2026-10-10 (1)





