Google launches new platform to help prevent Supply Chain attacks
SolarWinds and Codecov security incidents raise concerns about Supply Chain attacks. To ensure the integrity of software packages and prevent unauthorized modification, Google has come up with a solution called SLSA.
SLSA helps keep the entire software development and deployment process secure. As a result, it helps to reduce threats arising from unauthorized activities such as tampering with source code, tampering with software building platforms, etc.
In essence, SLSA is inspired by Google's internal process called Binary Authorization for Borg. This process includes a suite of tools to test and verify the origin of code and implement code identification to ensure that the software has been properly evaluated and authorized before deployment.
SLSA will be implemented to varying degrees. At higher levels, SLSA requires stronger security controls for the software building platform. Therefore, hackers will have a lot of difficulty in breaking in.
To implement SLSA, Google wishes to receive the cooperation of all agencies and businesses in the software industry. Google is also willing to share technical documents and standards necessary for partners to apply SLSA to their systems.
Google acknowledges that it is difficult to achieve the highest SLSA standards with most projects. However, adopting lower levels of SLSA would also increase security and pave the way for improved security of the open source ecosystem.
You should read it
- Hundreds of networks were accessed illegally when Codecov was attacked on a large scale
- It is not Intel, Samsung or Apple, Google, the little-known Dutch company that is the sole monopoly of the most important role in the global technology supply chain.
- Korea's supply chain faces unprecedented chaos due to the Covid-19 pandemic
- Exploring the Benefits of Using Supply Chain Analytics Software in Your Business
- New trend of global technology supply chain: 'Not Made in China'
- Google pledges $800 million to coronavirus relief, mostly in free ads
- Detects new Xcode malware targeting iOS developers
- Nikkei: Apple considers delaying the release of the iPhone 12 due to the corona virus effect
- How is the corona virus pandemic affecting the smartphone industry?
- Which country is STIHL chain saw? Is that good?
- 4 things to note before choosing to buy a PSU power supply for a PC
- How to Break a Chain