NDSS 2025 – Attributing Open-Source Contributions Is Critical But Difficult
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,抓住主要观点。 文章是关于GitHub和开源安全的,特别是作者身份验证的问题。他们提到开源项目对软件供应链的重要性,以及验证提交者身份的挑战。攻击者可以利用GitHub的配置来伪装可信贡献者。 研究方法包括大规模测量和分析,发现大部分项目容易被滥用。他们还提到签名提交的使用率很低,说明这个措施没有被广泛采用。此外,现有的安全建议缺乏对GitHub处理电子邮件问题的认识。 总结的时候要简洁明了,涵盖关键点:攻击手段、研究结果、签名使用情况和安全建议不足。确保在100字以内表达清楚。 </think> 该研究分析了GitHub上的开源贡献归属问题及其对软件供应链安全的影响。通过大规模测量发现,85.9%的项目易受滥用攻击,57.3万邮箱地址可被恶意利用。尽管95.4%的用户未签名提交,但仅2%的用户和0.2%的项目所有提交均签名。现有安全建议缺乏对GitHub邮箱处理问题的认识。 2026-1-23 16:0:0 Author: securityboulevard.com(查看原文) 阅读量:1 收藏

Session 9D: Github + OSN Security

Authors, Creators & Presenters: Jan-Ulrich Holtgrave (CISPA Helmholtz Center for Information Security), Kay Friedrich (CISPA Helmholtz Center for Information Security), Fabian Fischer (CISPA Helmholtz Center for Information Security), Nicolas Huaman (Leibniz University Hannover), Niklas Busch (CISPA Helmholtz Center for Information Security), Jan H. Klemmer (CISPA Helmholtz Center for Information Security), Marcel Fourné (Paderborn University), Oliver Wiese (CISPA Helmholtz Center for Information Security), Dominik Wermke (North Carolina State University), Sascha Fahl (CISPA Helmholtz Center for Information Security)
PAPER
Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain Security
Critical open-source projects form the basis of many large software systems. They provide trusted and extensible implementations of important functionality for cryptography, compatibility, and security. Verifying commit authorship authenticity in open-source projects is essential and challenging. Git users can freely configure author details such as names and email addresses. Platforms like GitHub use such information to generate profile links to user accounts. We demonstrate three attack scenarios malicious actors can use to manipulate projects and profiles on GitHub to appear trustworthy. We designed a mixed-research study to assess the effect on critical open-source software projects and evaluated countermeasures. First, we conducted a large-scale measurement among 50,328 critical open-source projects on GitHub and demonstrated that contribution workflows can be abused in 85.9% of the projects. We identified 573,043 email addresses that a malicious actor can claim to hijack historic contributions and improve the trustworthiness of their accounts. When looking at commit signing as a countermeasure, we found that the majority of users (95.4%) never signed a commit, and for the majority of projects (72.1%), no commit was ever signed. In contrast, only 2.0% of the users signed all their commits, and for 0.2% of the projects all commits were signed. Commit signing is not associated with projects’ programming languages, topics, or other security measures. Second, we analyzed online security advice to explore the awareness of contributor spoofing and identify recommended countermeasures. Most documents exhibit awareness of the simple spoofing technique via Git commits but no awareness of problems with GitHub’s handling of email addresses.
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/YWXJ0gh70p4?si=Dpp0OHi3xyAZyFk2


文章来源: https://securityboulevard.com/2026/01/ndss-2025-attributing-open-source-contributions-is-critical-but-difficult/
如有侵权请联系:admin#unsafe.sh