{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:34:37Z","timestamp":1784997277567,"version":"3.55.0"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031141782","type":"print"},{"value":"9783031141799","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-14179-9_19","type":"book-chapter","created":{"date-parts":[[2022,9,4]],"date-time":"2022-09-04T23:02:47Z","timestamp":1662332567000},"page":"281-295","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Alice in\u00a0(Software Supply) Chains: Risk Identification and\u00a0Evaluation"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2609-6787","authenticated-orcid":false,"given":"Giacomo","family":"Benedetti","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7155-7429","authenticated-orcid":false,"given":"Luca","family":"Verderame","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2272-2376","authenticated-orcid":false,"given":"Alessio","family":"Merlo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,5]]},"reference":[{"key":"19_CR1","doi-asserted-by":"publisher","unstructured":"Alberts, C.J., Dorofee, A.J., Creel, R., Ellison, R.J., Woody, C.: A systemic approach for assessing software supply-chain risk. In: 2011 44th Hawaii International Conference on System Sciences, Kauai, HI, pp. 1\u20138, January 2011. https:\/\/doi.org\/10.1109\/HICSS.2011.36","DOI":"10.1109\/HICSS.2011.36"},{"key":"19_CR2","unstructured":"Argon: 2021 software supply chain security report (2021). https:\/\/info.aquasec.com\/argon-supply-chain-attacks-study"},{"key":"19_CR3","doi-asserted-by":"publisher","unstructured":"Armando, A., Costa, G., Merlo, A., Verderame, L.: Enabling BYOD through secure meta-market. In: Proceedings of the 2014 ACM Conference on Security and Privacy in Wireless & Mobile Networks, WiSec 2014, pp. 219\u2013230. Association for Computing Machinery, New York (2014). https:\/\/doi.org\/10.1145\/2627393.2627410","DOI":"10.1145\/2627393.2627410"},{"key":"19_CR4","unstructured":"Barab\u00e1si, A.L.: Network Science. Cambridge University Press (2016). http:\/\/networksciencebook.com\/"},{"key":"19_CR5","doi-asserted-by":"publisher","unstructured":"Caputo, D., Verderame, L., Ranieri, A., Merlo, A., Caviglione, L.: Fine-hearing google home: why silence will not protect your privacy. J. Wireless Mob. Netw. Ubiquit. Comput. Dependable Appl., 35\u201353 (2020). https:\/\/doi.org\/10.22667\/JOWUA.2020.03.31.035","DOI":"10.22667\/JOWUA.2020.03.31.035"},{"key":"19_CR6","unstructured":"Cormen, T.H., Leiserson, C.E., Rivest, R.L., Stein, C.: Introduction to Algorithms. MIT Press, Cambridge (2017)"},{"key":"19_CR7","unstructured":"Cumming, A.: Open Source Intelligence (OSINT): Issues for Congress (2007)"},{"key":"19_CR8","unstructured":"Darkport Technologies Limited: shhgit. https:\/\/github.com\/eth0izzle\/shhgit"},{"key":"19_CR9","unstructured":"Dowd, M., McDonald, J., Schuh, J.: The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Pearson Education (2006)"},{"key":"19_CR10","doi-asserted-by":"publisher","unstructured":"Ebert, C., Gallardo, G., Hernantes, J., Serrano, N.: DevOps. IEEE Softw. (3), 94\u2013100 (2016). https:\/\/doi.org\/10.1109\/MS.2016.68","DOI":"10.1109\/MS.2016.68"},{"key":"19_CR11","unstructured":"European Union Agency for Cybersecurity: ENISA Threat Landscape for Supply Chain Attacks. Publications Office, LU (2021). https:\/\/data.europa.eu\/doi\/10.2824\/168593"},{"key":"19_CR12","unstructured":"FIRST.ORG Inc.: CVSS. https:\/\/www.first.org\/cvss\/"},{"key":"19_CR13","unstructured":"Flynn, C.: PyPI Stats. https:\/\/pypistats.org\/packages\/__all__"},{"key":"19_CR14","doi-asserted-by":"publisher","unstructured":"Ghaffarian, S.M., Shahriari, H.R.: Software vulnerability analysis and discovery using machine-learning and data-mining techniques: a survey. ACM Comput. Surv. (4) (2017). https:\/\/doi.org\/10.1145\/3092566","DOI":"10.1145\/3092566"},{"key":"19_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1007\/978-3-642-40588-4_25","volume-title":"Security Engineering and Intelligence Informatics","author":"N Gobbo","year":"2013","unstructured":"Gobbo, N., Merlo, A., Migliardi, M.: A denial of service attack to GSM networks via attach procedure. In: Cuzzocrea, A., Kittl, C., Simos, D.E., Weippl, E., Xu, L. (eds.) CD-ARES 2013. LNCS, vol. 8128, pp. 361\u2013376. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40588-4_25"},{"key":"19_CR16","unstructured":"Graphviz Authors: Graphviz. https:\/\/graphviz.org\/"},{"key":"19_CR17","unstructured":"Hex-Rays: Ida Decompiler. https:\/\/hex-rays.com\/decompiler\/"},{"key":"19_CR18","unstructured":"Kaloroumakis, P.E., Smith, M.J.: Toward a knowledge graph of cybersecurity countermeasures (2021)"},{"key":"19_CR19","doi-asserted-by":"publisher","unstructured":"Liu, B., Shi, L., Cai, Z., Li, M.: Software vulnerability discovery techniques: a survey. In: 2012 Fourth International Conference on Multimedia Information Networking and Security, pp. 152\u2013156 (2012). https:\/\/doi.org\/10.1109\/MINES.2012.202","DOI":"10.1109\/MINES.2012.202"},{"key":"19_CR20","unstructured":"Jackson, M.: Codecov supply chain breach - explained step by step. https:\/\/blog.gitguardian.com\/codecov-supply-chain-breach\/"},{"key":"19_CR21","unstructured":"Maltego Technologies: Maltego. https:\/\/www.maltego.com\/"},{"key":"19_CR22","doi-asserted-by":"publisher","first-page":"251","DOI":"10.3233\/JHS-130476","volume":"3","author":"M Migliardi","year":"2013","unstructured":"Migliardi, M., Merlo, A.: Improving energy efficiency in distributed intrusion detection systems. J. High Speed Netw. 3, 251\u2013264 (2013). https:\/\/doi.org\/10.3233\/JHS-130476","journal-title":"J. High Speed Netw."},{"key":"19_CR23","unstructured":"National Security Agency: Ghidra. https:\/\/ghidra-sre.org\/"},{"key":"19_CR24","unstructured":"OWASP Foundation Inc.: OWASP dependency-check. https:\/\/owasp.org\/www-project-dependency-check\/"},{"key":"19_CR25","unstructured":"radareorg: Radare2. https:\/\/rada.re\/"},{"key":"19_CR26","unstructured":"ReproducibleBuilds: Reproduciblebuilds. https:\/\/reproducible-builds.org\/"},{"key":"19_CR27","unstructured":"Revenera: The 2022 state of the software supply chain report (2022). https:\/\/info.revenera.com\/SCA-RPT-OSS-License-Compliance-2022\/"},{"key":"19_CR28","doi-asserted-by":"publisher","unstructured":"Romdhana, A., Ceccato, M., Georgiu, G.C., Merlo, A., Tonella, P.: COSMO: code coverage made easier for android. In: 2021 14th IEEE Conference on Software Testing, Verification and Validation (ICST), pp. 417\u2013423 (2021). https:\/\/doi.org\/10.1109\/ICST49551.2021.00053","DOI":"10.1109\/ICST49551.2021.00053"},{"key":"19_CR29","unstructured":"ShiftLeftSecurity: SLScan. https:\/\/slscan.io\/"},{"key":"19_CR30","unstructured":"Shodan: Shodan. https:\/\/www.shodan.io\/"},{"key":"19_CR31","unstructured":"Snyk Limited: Snyk open source. https:\/\/snyk.io\/"},{"key":"19_CR32","unstructured":"The Linux Foundation: SLSA. https:\/\/slsa.dev\/"},{"key":"19_CR33","unstructured":"The MITRE Corporation: CVE. https:\/\/cve.mitre.org\/"},{"key":"19_CR34","unstructured":"The MITRE Corporation: CWE-20: improper input validation. https:\/\/cwe.mitre.org\/data\/definitions\/20.html"},{"key":"19_CR35","unstructured":"The MITRE Corporation: CWE-478: missing default case in switch statement. https:\/\/cwe.mitre.org\/data\/definitions\/478.html"},{"key":"19_CR36","unstructured":"The MITRE Corporation: CWE-798: use of hard-coded credentials. https:\/\/cwe.mitre.org\/data\/definitions\/798.html"},{"key":"19_CR37","unstructured":"The MITRE Corporation: CWE-89: improper neutralization of special elements used in an SQL command (\u2018SQL Injection\u2019). https:\/\/cwe.mitre.org\/data\/definitions\/89.html"},{"key":"19_CR38","unstructured":"The MITRE Corporation: CWE VIEW 699: software development. https:\/\/cwe.mitre.org\/data\/definitions\/699.html"},{"key":"19_CR39","unstructured":"The MITRE Corporation: MITRE ATT &CK. https:\/\/attack.mitre.org\/"},{"key":"19_CR40","unstructured":"The MITRE Corporation: MITRE Common Weakness Enumeration. https:\/\/cwe.mitre.org\/"},{"key":"19_CR41","doi-asserted-by":"publisher","unstructured":"Vu, D.L., Massacci, F., Pashchenko, I., Plate, H., Sabetta, A.: LastPyMile: identifying the discrepancy between sources and packages. In: Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Athens Greece, pp. 780\u2013792, August 2021. https:\/\/doi.org\/10.1145\/3468264.3468592","DOI":"10.1145\/3468264.3468592"},{"key":"19_CR42","doi-asserted-by":"publisher","unstructured":"Vu, D.L., Pashchenko, I., Massacci, F., Plate, H., Sabetta, A.: Typosquatting and combosquatting attacks on the python ecosystem. In: 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS PW), pp. 509\u2013514 (2020). https:\/\/doi.org\/10.1109\/EuroSPW51379.2020.00074","DOI":"10.1109\/EuroSPW51379.2020.00074"},{"key":"19_CR43","doi-asserted-by":"publisher","unstructured":"Yan, D., Niu, Y., Liu, K., Liu, Z., Liu, Z., Bissyand\u00e9, T.F.: Estimating the attack surface from residual vulnerabilities in open source software supply chain. In: 2021 IEEE 21st International Conference on Software Quality, Reliability and Security (QRS), pp. 493\u2013502 (2021). https:\/\/doi.org\/10.1109\/QRS54544.2021.00060","DOI":"10.1109\/QRS54544.2021.00060"},{"key":"19_CR44","doi-asserted-by":"publisher","unstructured":"Zampetti, F., Geremia, S., Bavota, G., Di Penta, M.: CI\/CD pipelines evolution and restructuring: a qualitative and quantitative study. In: 2021 IEEE International Conference on Software Maintenance and Evolution (ICSME), pp. 471\u2013482 (2021). https:\/\/doi.org\/10.1109\/ICSME52107.2021.00048","DOI":"10.1109\/ICSME52107.2021.00048"}],"container-title":["Communications in Computer and Information Science","Quality of Information and Communications Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-14179-9_19","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,4]],"date-time":"2022-09-04T23:19:13Z","timestamp":1662333553000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-14179-9_19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031141782","9783031141799"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-14179-9_19","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"5 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"QUATIC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on the Quality of Information and Communications Technology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Talavera de la Reina","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"quatic2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.quatic.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"54","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"33% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}