On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from XZ

Research output: Working paper and reportsPreprint

Abstract

An emerging supply-chain attack due to a backdoor in XZ Utils has been identified. The backdoor allows an attacker to run commands remotely on vulnerable servers utilizing SSH without prior authentication. We have started to collect available information with regards to this attack to discuss current mitigation strategies for such kinds of supply-chain attacks. This paper introduces the critical attack path of the XZ backdoor and provides an overview about potential mitigation techniques related to relevant stages of the attack path.
Original languageEnglish
Place of Publicationhttps://arxiv.org
PublisherarXiv
Number of pages8
DOIs
Publication statusPublished - 13 Apr 2024

Publication series

NameCoRR - Computing Research Repository

Fields of science

  • 102 Computer Sciences
  • 102016 IT security
  • 505015 Legal informatics

JKU Focus areas

  • Digital Transformation
  • Sustainable Development: Responsible Technologies and Management

Cite this