On the Feasibility of Cross-Language Detection of Malicious Packages in npm and PyPI

Author:

Ladisa Piergiorgio1ORCID,Ponta Serena Elisa2ORCID,Ronzoni Nicola2ORCID,Martinez Matias3ORCID,Barais Olivier4ORCID

Affiliation:

1. SAP Security Research, Université de Rennes, INRIA, IRISA, France

2. SAP Security Research, France

3. Universitat Politècnica de Catalunya-BarcelonaTech, Spain

4. Université de Rennes, Inria, CNRS, IRISA, France

Funder

AssureMOSS

Sec4AI4Sec

Publisher

ACM

Reference37 articles.

1. [n. d.]. 1. An Introduction to Distutils. https://docs.python.org/3/distutils/introduction.html. [Accessed 02-Dec-2022]. [n. d.]. 1. An Introduction to Distutils. https://docs.python.org/3/distutils/introduction.html. [Accessed 02-Dec-2022].

2. [n. d.]. Backstabber’s Knife Collection. https://dasfreak.github.io/Backstabbers-Knife-Collection/. [Accessed 07-Sep-2022]. [n. d.]. Backstabber’s Knife Collection. https://dasfreak.github.io/Backstabbers-Knife-Collection/. [Accessed 07-Sep-2022].

3. [n. d.]. Gems with Extensions. https://guides.rubygems.org/gems-with-extensions. [Accessed 30-Jun-2023]. [n. d.]. Gems with Extensions. https://guides.rubygems.org/gems-with-extensions. [Accessed 30-Jun-2023].

4. [n. d.]. Octoverse 2022: The state of open source. https://octoverse.github.com/. [Accessed 22-Nov-2022]. [n. d.]. Octoverse 2022: The state of open source. https://octoverse.github.com/. [Accessed 22-Nov-2022].

5. [n. d.]. package.json - npm Docs. https://docs.npmjs.com/cli/v8/configuring-npm/package-json#scripts. [Accessed 02-Dec-2022]. [n. d.]. package.json - npm Docs. https://docs.npmjs.com/cli/v8/configuring-npm/package-json#scripts. [Accessed 02-Dec-2022].

Cited by 1 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Maltracker: A Fine-Grained NPM Malware Tracker Copiloted by LLM-Enhanced Dataset;Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis;2024-09-11

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3