Supply Chain Security
In the computer science field, security has generally been piecemeal in nature, rather than a holistic operation that can guarantee the security of a project from end to end. Faculty and students at the Center for Cybersecurity have been actively engaged in changing this perspective by developing and implementing both software and hardware supply chain defenses. These strategies include identifying flaws in microchips, ensuring consistency and quality control in digitally-manufactured products, adding transparency and accountability to each step in the software supply chain, and utilizing financial incentives as a defensive strategy.
Relevant Faculty
Lab/Center Links
Sample Projects/Papers/Programs
- In-toto
- The Update Framework (TUF)
- Uptane
- The Archive Framework
- “Cyber Insurance Against Cyberattacks on Electric Vehicle Charging Stations”
- “Computational Sensor Fingerprints”
- “On omitting commits and committing omissions: Preventing git metadata tampering that (re) introduces software vulnerabilities”
- A Python toolbox for modeling and optimization of photo acquisition & distribution pipelines
Grants
- Reducing Container Kernel Attack Surface with TRACKS-NSF
- NSF SaTC: TTP: Medium: Securing Python’s Software Supply Chain
- NSF SaTC: TTP: Medium: Collaborative: Securing the Software Supply Chain
- 2022 NSF CAREER Award (to Brendan Dolan-Gavitt to support improved ways to assess vulnerability discovery tools)