|
| |||||||||||
ChainSEC 2027 : ChainSEC 2027 : 1st Workshop on Software Supply Chain Security | |||||||||||
| Link: https://chain-sec.github.io/#home | |||||||||||
| |||||||||||
Call For Papers | |||||||||||
|
Topics of Interest
Non-exhaustive: Software provenance, SBOMs, and SLSA/in-toto-style attestation Software integrity, reproducible builds, and trusted-build infrastructure CI/CD pipeline security, containers, and deployment infrastructure Code signing, software identity, and secure update delivery Developer identity, authentication, and maintainer-account compromise Supply-chain attack vectors and exemplars (xz-utils-style backdoors, dependency confusion, typosquatting, account takeover); incident response and forensics Package registry and ecosystem infrastructure security; detection of malicious packages Supply-chain auditing, observability, runtime enforcement, and policy specification Third-party dependency management: vulnerability discovery, prioritization, and automated remediation Tools and techniques: software composition analysis, static analysis of dependencies and build artifacts, capability enforcement, debloating, automated program repair Datasets and benchmarking for supply-chain research (SBOM corpora, malware datasets, datasets for ML models) Hardware-assisted software supply chain integrity, attestation, and confidential computing for build pipelines Human, social, and economic factors: maintainer burnout, social engineering, open-source sustainability, trust, incentives, and empirical studies of best-practices adoption Regulatory frameworks (EU CRA, US federal software security policy), standards (NIST SSDF, CycloneDX, SPDX), and compliance Supply-chain security across application domains (healthcare, finance, automotive, critical infrastructure) Security of AI supply chains: provenance and integrity of models, training data, and model hubs; AI-generated and agent-authored code as an ingestion vector Submission Tracks All submissions use the IEEEtran 10pt conference format and are non-archival (no formal proceedings). - Talk proposals: up to 2 pages, extended abstracts for position, early-stage, vision, or lessons-learned contributions. - Poster proposals, 1 page, late-breaking results, PhD-in-progress, tool demos. Submit a 1-page extended abstract in IEEEtran format; accepted authors present a physical poster at the workshop. - Lightning-talk proposals, 1 page, provocative ideas for 5-minute presentations. Submissions are made through HotCRP. Each submission is reviewed by at least two PC members on fit, discussion potential, and clarity. Accepted contributions will be presented at the workshop; no formal proceedings are published, so authors retain full rights to submit elaborated versions to other venues. |
|