Google launches new platform to help prevent Supply Chain attacks
Supply Chain attack is a very dangerous type of attack and often has serious consequences.
SolarWinds and Codecov security incidents raise concerns about Supply Chain attacks. To ensure the integrity of software packages and prevent unauthorized modification, Google has come up with a solution called SLSA.
SLSA helps keep the entire software development and deployment process secure. As a result, it helps to reduce threats arising from unauthorized activities such as tampering with source code, tampering with software building platforms, etc.
In essence, SLSA is inspired by Google's internal process called Binary Authorization for Borg. This process includes a suite of tools to test and verify the origin of code and implement code identification to ensure that the software has been properly evaluated and authorized before deployment.
SLSA will be implemented to varying degrees. At higher levels, SLSA requires stronger security controls for the software building platform. Therefore, hackers will have a lot of difficulty in breaking in.
To implement SLSA, Google wishes to receive the cooperation of all agencies and businesses in the software industry. Google is also willing to share technical documents and standards necessary for partners to apply SLSA to their systems.
Google acknowledges that it is difficult to achieve the highest SLSA standards with most projects. However, adopting lower levels of SLSA would also increase security and pave the way for improved security of the open source ecosystem.
Discover more
Share by
David PacYou should read it
- Korea's supply chain faces unprecedented chaos due to the Covid-19 pandemic
- Exploring the Benefits of Using Supply Chain Analytics Software in Your Business
- New trend of global technology supply chain: 'Not Made in China'
- Google pledges $800 million to coronavirus relief, mostly in free ads
- Detects new Xcode malware targeting iOS developers
- The Quiet Details That Make a Sports Betting Platform Feel Reliable
- Instructions on creating toy set images with ChatGPT AI
- How are AI agents changing the journalism industry?
- NVIDIA Jetson chipset contains a series of security holes that allow data theft, DDoS attacks
- How to factory reset iPhone without password
- Steps to Scan documents directly using iPhone or iPad