skip to main content
US FlagAn official website of the United States government
dot gov icon
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
https lock icon
Secure .gov websites use HTTPS
A lock ( lock ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


Title: Thermal Covert Channels Leveraging Package-on-Package DRAM
Award ID(s):
1651945
PAR ID:
10132053
Author(s) / Creator(s):
; ; ; ;
Date Published:
Journal Name:
International Conference on Trust, Security and Privacy in Computing and Communications
Page Range / eLocation ID:
319 to 326
Format(s):
Medium: X
Sponsoring Org:
National Science Foundation
More Like this
  1. With an increased level of automation provided by package managers, which sometimes allow updates to be installed automatically, malicious package updates are becoming a real threat in software ecosystems. To address this issue, we propose an approach based on anomaly detection, to identify suspicious updates based on security-relevant features that attackers could use in an attack. We evaluate our approach in the context of Node.js/npm ecosystem, to show its feasibility in terms of reduced review effort and the correct identification of a confirmed malicious update attack. Although we do not expect it to be a complete solution in isolation, we believe it is an important security building block for software ecosystems. 
    more » « less