ºÚÁÏÍø

Events

Public defence in the field of Computer Science, MSc Jacopo Bufalino

On the security of the Software Supply chain for the Cloud

Public defence from the Aalto University School of Science, Department of Computer Science.
Illustration featuring a cloud and padlock at the center, surrounded by abstract technology icons and circular data patterns
Copyright: Elisabetta Russo

In this event, we are committed ºÚÁÏÍø University’s principles for a safer space.

Principles for a safe space

Title of the thesis: On the security of the Software Supply chain for the Cloud

Thesis defender: Jacopo Bufalino 
Opponent: Assistant Professor Santiago Torres-Arias, Purdue University, United States
Custos: Professor Tuomas Aura, Aalto University School of Science

Most digital services run in the cloud and are assembled from interconnected components, including application code, open-source dependencies, third-party services, tools, and reusable configurations. Together, these components form a software supply chain whose weaknesses can compromise the security of cloud applications. This thesis investigates a recurring problem in this supply chain: security tools and configurations often fail to reflect how applications actually behave at runtime.

The thesis examines this problem in two areas. First, modern applications comprise interconnected services whose network boundaries are largely defined through configuration. Second, vulnerability scanners are used to determine whether software components contain known vulnerabilities. The thesis shows that both can provide incomplete or misleading assessments. A configuration that appears secure may still permit unintended communication at runtime, creating hidden paths through an application, while vulnerability scanners can produce inconsistent results that obscure genuine vulnerabilities. In both cases, an attacker may exploit one compromised component and move deeper into the system.

The research demonstrates that the configured behaviour of a cloud system can differ substantially from its observed runtime behaviour. Existing approaches typically analyse configuration before deployment or network traffic after deployment, but neither provides a complete view of the system on its own. To address this gap, the thesis develops methods and open-source tools that reconstruct the actual network connectivity of cloud applications, identify previously undocumented misconfigurations, and automatically generate policies that restrict unintended communication while preserving legitimate functionality.

The thesis therefore shows that security configurations and tools cannot be treated as authoritative representations of cloud-system security. Instead, their results must be continuously validated against observed system behaviour. The developed tools support DevOps engineers, security teams, and software maintainers in discovering hidden communication paths, reducing unnecessary network access, and improving the reliability of vulnerability assessments. More broadly, the findings provide concrete recommendations for improving security tooling, standards, and industry practices for cloud-native software supply chain.

Keywords: software supply chain, cloud-native security, kubernetes, SBOM, network misconfigurations

Thesis available for public display 7 days prior to the defence at . 

Contact Information: 
 

Doctoral theses of the School of Science

A large white 'A!' sculpture on the rooftop of the Undergraduate centre. A large tree and other buildings in the background.

Doctoral theses of the School of Science are available in the open access repository maintained by Aalto, Aaltodoc.

Zoom Quick Guide
  • Updated:
  • Published:
Share
URL copied!