Ένα policy-driven πλαίσιο προεγκαταστασιακής άμυνας για την ασφάλεια της Python software supply chain
A policy-driven pre-installation defense framework for Python package supply-chain security

View/ Open
Keywords
Software supply chain security ; PyPI ; Python packages ; Static analysis ; Machine learning ; Random forest ; Pre-install defense ; Fusion policy ; Dependency confusion ; TyposquattingAbstract
This thesis presents SupplyGuard, a policy-driven pre-installation defense framework for Python software supply-chain security. The addressed problem is the installation of malicious or suspicious Python packages from ecosystems such as PyPI, where a normal pip install command may introduce code containing obfuscation, suspicious network indicators, install-time logic, or other risk signals.
SupplyGuard is implemented as a PyPI-compatible gateway/proxy. Each package artifact is inspected before installation using a static-only process: package code is not executed, the package is not imported, and build-time or runtime hooks are not triggered. The analysis is organized around five engines: static rules, machine-learning risk scoring, gateway static scanning, provenance/typosquatting/dependency-confusion checks, and artifact integrity checks. Their outputs are combined by a fusion policy that produces the final installation action and an evidence/audit record.
In the frozen benchmark used in this thesis, consisting of 700 assumed-clean and 3,701 malicious-labeled artifacts, the full A–E fusion policy stopped 3,358 of 3,701 malicious-labeled artifacts before installation (90.73%). The clean false-403 rate was 114/700 (16.29%), while the permanent clean block rate was 1/700 (0.14%). Engine B, based on a Random Forest classifier, achieved 0.9466 accuracy, 0.9465 macro-F1 and 0.9838 ROC-AUC on the internal held-out test set. In a frozen shape-matched external evaluation, the same ML signal retained moderate discrimination with 0.8427 ROC-AUC, without supporting a full source-independent generalization claim.
The contribution of this thesis is an explainable pre-install risk-reduction framework rather than an absolute malware detector. SupplyGuard demonstrates that multiple imperfect risk signals, organized through policy-driven fusion, can reduce risk before Python packages are installed while preserving evidence, review and auditability.


