1+ % Essential references for InstallTrust paper
2+
3+ @techreport {fireeye2020sunburst ,
4+ author = { {FireEye}} ,
5+ title = { Highly Evasive Attacker Leverages {SolarWinds} Supply Chain to Compromise Multiple Global Victims With {SUNBURST} Backdoor} ,
6+ institution = { FireEye} ,
7+ year = { 2020} ,
8+ type = { Technical Report}
9+ }
10+
11+ @online {xz2024backdoor ,
12+ author = { Goodin, Dan} ,
13+ title = { {XZ} Utils Backdoor: Everything You Need to Know} ,
14+ url = { https://arstechnica.com/security/2024/03/backdoor-found-in-widely-used-linux-utility-breaks-encrypted-ssh-connections/} ,
15+ urldate = { 2024-03-29} ,
16+ year = { 2024} ,
17+ month = mar
18+ }
19+
20+ @misc {crowdstrike2024outage ,
21+ author = { {CrowdStrike}} ,
22+ title = { {CrowdStrike} Update Causes Global {IT} Outage} ,
23+ year = { 2024} ,
24+ month = jul,
25+ howpublished = { Incident Report}
26+ }
27+
28+ @online {codecov2021incident ,
29+ author = { {Codecov}} ,
30+ title = { {Codecov} Security Incident} ,
31+ url = { https://about.codecov.io/security-update/} ,
32+ year = { 2021} ,
33+ month = apr,
34+ urldate = { 2024-01-15}
35+ }
36+
37+ @misc {kaseya2021ransomware ,
38+ author = { {Kaseya}} ,
39+ title = { {Kaseya} {VSA} Ransomware Attack} ,
40+ year = { 2021} ,
41+ month = jul,
42+ howpublished = { Security Advisory}
43+ }
44+
45+ @article {kuppusamy2016tuf ,
46+ author = { Kuppusamy, Trishank Karthik and Torres-Arias, Santiago and Diaz, Vladimir and Cappos, Justin} ,
47+ title = { The Update Framework: A Framework for Securing Software Update Systems} ,
48+ journal = { ACM Transactions on Privacy and Security} ,
49+ volume = { 19} ,
50+ number = { 3} ,
51+ pages = { 1--31} ,
52+ year = { 2016}
53+ }
54+
55+ @techreport {google2021slsa ,
56+ author = { {Google Open Source Security Team}} ,
57+ title = { Supply-chain Levels for Software Artifacts} ,
58+ institution = { Google} ,
59+ year = { 2021} ,
60+ type = { Technical Report} ,
61+ url = { https://slsa.dev/}
62+ }
63+
64+ @techreport {nist2024ssdf ,
65+ author = { {NIST}} ,
66+ title = { Secure Software Development Framework ({SSDF})} ,
67+ institution = { National Institute of Standards and Technology} ,
68+ year = { 2024} ,
69+ number = { 800-218} ,
70+ type = { Special Publication}
71+ }
72+
73+ @online {google2025android ,
74+ author = { {Google Android Security Team}} ,
75+ title = { Elevating {Android} security to keep it open and safe} ,
76+ url = { https://android-developers.googleblog.com/2025/08/elevating-android-security.html} ,
77+ year = { 2025} ,
78+ month = aug,
79+ urldate = { 2025-08-26}
80+ }
81+
82+ @online {apple2023security ,
83+ author = { {Apple Inc.}} ,
84+ title = { {Apple} Platform Security} ,
85+ url = { https://support.apple.com/guide/security/} ,
86+ year = { 2023} ,
87+ urldate = { 2023-12-01}
88+ }
89+
90+ @online {microsoft2024windows ,
91+ author = { {Microsoft Security Response Center}} ,
92+ title = { {Windows} Security Baselines} ,
93+ url = { https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-security-baselines} ,
94+ year = { 2024} ,
95+ month = jan,
96+ urldate = { 2024-01-15}
97+ }
98+
99+ @online {chen2023android ,
100+ author = { Chen, David K. and {Android Security Team}} ,
101+ title = { {Android} Security: 2023 Year in Review} ,
102+ url = { https://security.googleblog.com/2023/12/android-security-2023-year-in-review.html} ,
103+ year = { 2023} ,
104+ month = dec,
105+ urldate = { 2024-01-15}
106+ }
107+
108+ @online {liu2024ios ,
109+ author = { Liu, James and {Apple Security Team}} ,
110+ title = { {iOS} Security Guide 2024} ,
111+ url = { https://developer.apple.com/documentation/security} ,
112+ year = { 2024} ,
113+ urldate = { 2024-01-15}
114+ }
115+
116+ @techreport {anderson2024linux ,
117+ author = { Anderson, James P. and Wright, Chris} ,
118+ title = { {Linux} Security Modules: General Security Hooks for {Linux}} ,
119+ institution = { Linux Foundation} ,
120+ year = { 2024} ,
121+ type = { Technical Report}
122+ }
123+
124+ @inproceedings {ladisa2023taxonomy ,
125+ author = { Ladisa, Piergiorgio and Plate, Henrik and Martinez, Matias and Barais, Olivier} ,
126+ title = { {SoK}: Taxonomy of Attacks on Open-Source Software Supply Chains} ,
127+ booktitle = { 2023 {IEEE} Symposium on Security and Privacy ({SP})} ,
128+ pages = { 1509--1526} ,
129+ year = { 2023} ,
130+ publisher = { IEEE}
131+ }
132+
133+ @inproceedings {zimmermann2019npm ,
134+ author = { Zimmermann, Markus and Staicu, Cristian-Alexandru and Tenny, Cam and Pradel, Michael} ,
135+ title = { Small World with High Risks: A Study of Security Threats in the npm Ecosystem} ,
136+ booktitle = { 28th {USENIX} Security Symposium ({USENIX} Security 19)} ,
137+ pages = { 995--1010} ,
138+ year = { 2019} ,
139+ publisher = { USENIX Association}
140+ }
141+
142+ @techreport {pypi2023malware ,
143+ author = { {Python Software Foundation}} ,
144+ title = { {PyPI} Malware Statistics Report} ,
145+ institution = { Python Software Foundation} ,
146+ year = { 2023} ,
147+ month = dec,
148+ type = { Security Report}
149+ }
150+
151+ @online {npm2022colors ,
152+ author = { {npm, Inc.}} ,
153+ title = { Colors and Faker npm Packages Sabotaged} ,
154+ url = { https://blog.npmjs.org/post/672905398677561344/colors-and-faker-sabotaged} ,
155+ year = { 2022} ,
156+ month = jan,
157+ urldate = { 2022-01-15}
158+ }
159+
160+ @techreport {dependency2024confusion ,
161+ author = { {OWASP}} ,
162+ title = { Evolution of Dependency Confusion Attacks} ,
163+ institution = { Open Web Application Security Project} ,
164+ year = { 2024} ,
165+ month = mar,
166+ type = { Security Research Report}
167+ }
168+
169+ @inproceedings {torres2019intoto ,
170+ author = { Torres-Arias, Santiago and Ammula, Hrishikesh and Curtmola, Reza and Cappos, Justin} ,
171+ title = { in-toto: Providing farm-to-table guarantees for bits and bytes} ,
172+ booktitle = { 28th {USENIX} Security Symposium ({USENIX} Security 19)} ,
173+ pages = { 1393--1410} ,
174+ year = { 2019} ,
175+ publisher = { USENIX Association}
176+ }
177+
178+ @misc {cisa2024sbom ,
179+ author = { {CISA}} ,
180+ title = { Software Bill of Materials ({SBOM}) Requirements} ,
181+ year = { 2024} ,
182+ howpublished = { Federal Requirements} ,
183+ url = { https://www.cisa.gov/sbom}
184+ }
185+
186+ @misc {solarwinds2024sec ,
187+ author = { {U.S. Securities and Exchange Commission}} ,
188+ title = { {SEC} Charges {SolarWinds} and {CISO} with Fraud} ,
189+ year = { 2024} ,
190+ month = oct,
191+ howpublished = { Press Release} ,
192+ url = { https://www.sec.gov/news/press-release/2024-158}
193+ }
194+
195+ @techreport {forrester2024appsec ,
196+ author = { {Forrester Research}} ,
197+ title = { The State Of Application Security, 2024} ,
198+ institution = { Forrester Research} ,
199+ year = { 2024} ,
200+ type = { Industry Report}
201+ }
202+
203+ @techreport {gartner2024supply ,
204+ author = { {Gartner}} ,
205+ title = { Supply Chain Security: Market Guide} ,
206+ institution = { Gartner} ,
207+ year = { 2024} ,
208+ type = { Research Report}
209+ }
210+
211+ @misc {eu2024dma ,
212+ author = { {European Commission}} ,
213+ title = { Digital Markets Act} ,
214+ year = { 2024} ,
215+ howpublished = { {EU} Regulation 2022/1925} ,
216+ url = { https://eur-lex.europa.eu/eli/reg/2022/1925/oj}
217+ }
218+
219+ @misc {epic2021ruling ,
220+ author = { {U.S. District Court}} ,
221+ title = { Epic Games v. Apple Initial Ruling} ,
222+ year = { 2021} ,
223+ howpublished = { Case No. 4:20-cv-05640} ,
224+ note = { Northern District of California}
225+ }
226+
227+ @techreport {vu2024supplychain ,
228+ author = { Vu, Duc Ly and Newman, Zane} ,
229+ title = { Supply Chain Vulnerabilities in Modern Software} ,
230+ institution = { Security Research Institute} ,
231+ year = { 2024} ,
232+ type = { Research Report}
233+ }
234+
235+ @article {zahan2024packages ,
236+ author = { Zahan, Nasir and Zimmermann, Thomas and Godefroid, Patrice and Maddila, Chandra} ,
237+ title = { Weak Links in the npm Supply Chain} ,
238+ journal = { ACM Computing Surveys} ,
239+ year = { 2024}
240+ }
241+
242+ @techreport {google2024android ,
243+ author = { {Google Android Team}} ,
244+ title = { {Android} Security Enhancements 2024} ,
245+ institution = { Google} ,
246+ year = { 2024} ,
247+ type = { Technical Report}
248+ }
249+
250+ @online {kubernetes2024security ,
251+ author = { {Kubernetes Security Team}} ,
252+ title = { {Kubernetes} Supply Chain Security Guide} ,
253+ url = { https://kubernetes.io/docs/concepts/security/supply-chain-security/} ,
254+ year = { 2024} ,
255+ urldate = { 2024-01-15}
256+ }
257+
258+ @online {docker2024supply ,
259+ author = { {Docker Inc.}} ,
260+ title = { {Docker} Supply Chain Security Best Practices} ,
261+ url = { https://docs.docker.com/build/security/} ,
262+ year = { 2024} ,
263+ urldate = { 2024-01-15}
264+ }
265+
266+ @techreport {kumar2024iot ,
267+ author = { Kumar, Raj and Singh, Priya} ,
268+ title = { {IoT} Device Security Assessment Framework} ,
269+ institution = { IoT Security Research Group} ,
270+ year = { 2024} ,
271+ type = { Research Report}
272+ }
273+
274+ @article {sadeghi2024embedded ,
275+ author = { Sadeghi, Ahmad-Reza and Liu, Wei} ,
276+ title = { Embedded Systems Security in 2024} ,
277+ journal = { IEEE Security \& Privacy} ,
278+ year = { 2024} ,
279+ volume = { 22} ,
280+ number = { 1} ,
281+ pages = { 12--20}
282+ }
283+
284+ @online {rustup2024security ,
285+ author = { {Rust Foundation}} ,
286+ title = { {Rustup} Security Model and Best Practices} ,
287+ url = { https://forge.rust-lang.org/infra/channel-layout.html#security} ,
288+ year = { 2024} ,
289+ urldate = { 2024-01-15}
290+ }
291+
292+ @online {golang2024modules ,
293+ author = { {Go Team}} ,
294+ title = { {Go} Module Security Framework} ,
295+ url = { https://go.dev/doc/modules/security} ,
296+ year = { 2024} ,
297+ urldate = { 2024-01-15}
298+ }
299+
300+ @techreport {uk2024cma ,
301+ author = { {Competition and Markets Authority}} ,
302+ title = { Mobile App Stores Market Investigation} ,
303+ institution = { UK Competition and Markets Authority} ,
304+ year = { 2024} ,
305+ type = { Regulatory Report}
306+ }
307+
308+ @misc {india2024antitrust ,
309+ author = { {Competition Commission of India}} ,
310+ title = { Antitrust Investigation into App Store Practices} ,
311+ year = { 2024} ,
312+ howpublished = { Regulatory Filing}
313+ }
314+
315+ @misc {epic2024appeal ,
316+ author = { {U.S. Court of Appeals}} ,
317+ title = { Epic Games v. Apple Appeal Decision} ,
318+ year = { 2024} ,
319+ howpublished = { Court Ruling} ,
320+ note = { Ninth Circuit}
321+ }
322+
323+ @misc {japan2024appstore ,
324+ author = { {Japan Fair Trade Commission}} ,
325+ title = { Digital Platform Regulation Guidelines} ,
326+ year = { 2024} ,
327+ howpublished = { Regulatory Guidance}
328+ }
329+
330+ @misc {korea2021appstore ,
331+ author = { {Korea Communications Commission}} ,
332+ title = { App Store Payment Choice Law} ,
333+ year = { 2021} ,
334+ howpublished = { Legislative Action}
335+ }
0 commit comments