Skip to main content

Showing 1–2 of 2 results for author: Dunlap, T

Searching in archive cs. Search in all archives.
.
  1. arXiv:2311.01532  [pdf, other

    cs.CR

    VFCFinder: Seamlessly Pairing Security Advisories and Patches

    Authors: Trevor Dunlap, Elizabeth Lin, William Enck, Bradley Reaves

    Abstract: Security advisories are the primary channel of communication for discovered vulnerabilities in open-source software, but they often lack crucial information. Specifically, 63% of vulnerability database reports are missing their patch links, also referred to as vulnerability fixing commits (VFCs). This paper introduces VFCFinder, a tool that generates the top-five ranked set of VFCs for a given sec… ▽ More

    Submitted 2 November, 2023; originally announced November 2023.

  2. arXiv:2307.16557  [pdf, other

    cs.CR

    S3C2 Summit 2023-02: Industry Secure Supply Chain Summit

    Authors: Trevor Dunlap, Yasemin Acar, Michel Cucker, William Enck, Alexandros Kapravelos, Christian Kastner, Laurie Williams

    Abstract: Recent years have shown increased cyber attacks targeting less secure elements in the software supply chain and causing fatal damage to businesses and organizations. Past well-known examples of software supply chain attacks are the SolarWinds or log4j incidents that have affected thousands of customers and businesses. The US government and industry are equally interested in enhancing software supp… ▽ More

    Submitted 31 July, 2023; originally announced July 2023.

    Comments: arXiv admin note: text overlap with arXiv:2307.15642