无万灵药:验证Python包构建
No Snake Oil: Verifying Python Package Builds
AI总结:
研究针对Python包供应链的验证问题,提出daleq4py工具,通过基于保留出处的数据记录规则的归一化函数内核建立Python轮子等效性,实验表明该工具大大扩展了可被接受为等效的重建集。
AI中文摘要:
Python已成为与人工智能交互的默认语言,包通过Python包索引(PyPI)等注册表分发,因此需要分析此类包的供应链。一种分析方法是重建包以识别注入恶意软件的受损构建。在强化环境中独立重建有额外优势,可生成和记录出处以提高包的可信度。研究发现macaron和oss-rebuild这两个自动化重建工具的字节对字节等效率通常较低,分析了原因。提出daleq4py工具,通过基于保留出处的数据记录规则的归一化函数内核来建立Python轮子的等效性。实验结果表明daleq4py大大扩展了可被接受为等效的重建集。
英文摘要:
Python has become the default language for interacting with AI, with packages being distributed through registries like the Python Package Index (PyPI). This creates a need to analyse supply chains comprising such packages. One such analysis is to rebuild packages in order to identify compromised builds injecting malware. Independent rebuilds in hardened environments have the added advantage that they can generate and record provenance in order to increase the trustworthiness of packages. Two tools that are designed to automate such rebuilds and run them at scale are macaron and oss-rebuild. We study 12,180 popular releases from PyPI and find that the byte-for-byte equivalence rate is generally low. We analyse the reasons why they produce different wheels, and find that equivalence between the original and rebuilt wheels can often still be established, preserving most of the guarantees users expect from rebuildable releases. We present and evaluate daleq4py, a tool to establish the equivalence of Python wheels through the kernel of a normalisation function that is based on provenance-preserving datalog rules. Experimental results show that daleq4py substantially expands the set of rebuilds that can be accepted as equivalent. Although only 15.4% of macaron rebuilds and 19.1% of oss-rebuild rebuilds are byte-for-byte identical to the published PyPI wheels, daleq4py establishes wheel equivalence for 60.2% and 78.9% of source-equivalent rebuilds, respectively.