Software Supply Chain Security in Cloud-Native Systems: A Zero Trust Framework for Securing APIs, Containers, Dependencies, and CI/CD Pipelines
DOI:
https://doi.org/10.21590/Keywords:
Software Supply Chain Security, Zero Trust, Cloud-Native Security, API Security, Container Security, CI/CD Security, Dependency Security, Software Provenance, DevSecOps, Software Bill of Materials.Abstract
Software supply chain attacks have become a serious security concern in cloud-native environments, where applications depend on interconnected APIs, container images, open-source libraries, build systems, registries, and automated CI/CD pipelines. A weakness in any of these components can provide attackers with a path to alter source code, introduce malicious dependencies, steal credentials, compromise build processes, or deploy unauthorized software into production. Traditional perimeter-based security models are poorly suited to these distributed and highly automated environments because they often depend on implicit trust between internal systems and development stages. This article proposes a Zero Trust software supply chain security framework that applies continuous verification, least-privilege access, strong identity controls, software provenance, artifact integrity validation, and policy-based enforcement across the cloud-native software lifecycle. The framework addresses four major security domains: APIs, containers and cloud-native workloads, third-party dependencies, and CI/CD pipelines. It also incorporates software bills of materials, cryptographic signing, workload identity, secure build practices, runtime monitoring, and automated trust evaluation. A threat-control mapping and risk assessment model are used to examine how the proposed controls can reduce exposure to dependency poisoning, repository compromise, artifact tampering, credential theft, container attacks, and unauthorized deployment. The study provides a structured approach for integrating previously fragmented security controls into a unified supply chain security model and establishes a basis for future empirical evaluation in cloud-native production environments.
References
[1] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero
trust architecture (NIST Special Publication 800-207). National
Institute of Standards and Technology. https://doi.org/10.6028/
NIST.SP.800-207.
[2] Chandramouli, R., & Butcher, Z. (2023). A zero trust architecture
model for access control in cloud-native applications in multilocation
environments (NIST Special Publication 800-207A).
National Institute of Standards and Technology. https://doi.
org/10.6028/NIST.SP.800-207A.
[3] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., &
Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive
survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/
ACCESS.2022.3174679.
[4] Chandramouli, R., & Butcher, Z. (2020). Building secure
microservices-based applications using service-mesh architecture
(NIST Special Publication 800-204A). National Institute of
Standards and Technology.
[5] Potla, R. (2023). Designing a BTP-centric integration mesh for
shop-floor IoT, MES and ERP in discrete manufacturing. Journal
of Artificial Intelligence, Machine Learning and Data Science,
1(2), 1-8.
[6] Chandramouli, R., Butcher, Z., & Chetal, A. (2021). Attribute-based
access control for microservices-based applications using a service
mesh (NIST Special Publication 800-204B). National Institute
of Standards and Technology. https://doi.org/10.6028/NIST.
SP.800-204B.
[7] Chandramouli, R., Kautz, F., & Torres-Arias, S. (2024). Strategies
for the integration of software supply chain security in DevSecOps
CI/CD pipelines (NIST Special Publication 800-204D). National
Institute of Standards and Technology.
[8] Souppaya, M., Scarfone, K., & Dodson, D. (2022). Secure software
development framework (SSDF) version 1.1: Recommendations
for mitigating the risk of software vulnerabilities (NIST Special
Publication 800-218). National Institute of Standards and
Technology. https://doi.org/10.6028/NIST.SP.800-218.
[9] Ladisa, P., Plate, H., Martinez, M., & Barais, O. (2023). SoK:
Taxonomy of attacks on open-source software supply chains. In
2023 IEEE Symposium on Security and Privacy (SP) (pp. 1509–1526).
IEEE. https://doi.org/10.1109/SP46215.2023.10179304.
[10] Okafor, C., Schorlemmer, T. R., Torres-Arias, S., & Davis, J. C.
(2022). SoK: Analysis of software supply chain security by
establishing secure design properties. In Proceedings of the
2022 Workshop on Software Supply Chain Offensive Research
and Ecosystem Defenses (pp. 15–24). Association for Computing
Machinery. https://doi.org/10.1145/3560835.3564556.
[11] Torres-Arias, S., Afzali, H., Kuppusamy, T. K., Curtmola, R., &
Cappos, J. (2019). in-toto: Providing farm-to-table guarantees
for bits and bytes. In 28th USENIX Security Symposium (USENIX
Security 19) (pp. 1393–1410). USENIX Association.
[12] Ohm, M., Plate, H., Sykosch, A., & Meier, M. (2020). Backstabber’s
knife collection: A review of open source software supply chain
attacks. In Detection of Intrusions and Malware, and Vulnerability
Assessment (pp. 23–43). Springer. https://doi.org/10.1007/978-
3-030-52683-2_2.
[13] Duan, R., Alrawi, O., Kasturi, R. P., Elder, R., Saltaformaggio, B.,
& Lee, W. (2021). Towards measuring supply chain attacks on
package managers for interpreted languages. In Proceedings
of the Network and Distributed System Security Symposium
(NDSS 2021). Internet Society. https://doi.org/10.14722/
ndss.2021.23055.
[14] Vu, D. L., Pashchenko, I., Massacci, F., Plate, H., & Sabetta, A.
(2020). Towards using source code repositories to identify
software supply chain attacks. In Proceedings of the 2020 ACM
SIGSAC Conference on Computer and Communications Security
(pp. 2093–2095). Association for Computing Machinery. https://
doi.org/10.1145/3372297.3420015.
[15] Cappos, J., Samuel, J., Baker, S. M., & Hartman, J. H. (2008). A
look in the mirror: Attacks on package managers. In Proceedings
of the 15th ACM Conference on Computer and Communications
Security (pp. 565–574). Association for Computing Machinery.
https://doi.org/10.1145/1455770.1455841.
[16] Potla, R. B. (2024). Optimizing extended warehouse management
for make-to-order plants: Slotting, wave picking, and yard
orchestration at scale. Journal of Computer Science and
Technology Studies, 6(3), 181-192.
[17] Samuel, J., Mathewson, N., Cappos, J., & Dingledine, R. (2010).
Survivable key compromise in software update systems.
In Proceedings of the 17th ACM Conference on Computer and
Communications Security (pp. 61–72). Association for Computing
Machinery. https://doi.org/10.1145/1866307.1866315.
[18] Kuppusamy, T. K., Torres-Arias, S., Diaz, V., & Cappos, J. (2016).
Diplomat: Using delegations to protect community repositories.
In 13th USENIX Symposium on Networked Systems Design and
Implementation (NSDI 16) (pp. 567–581). USENIX Association.
[19] Kuppusamy, T. K., Diaz, V., & Cappos, J. (2017). Mercury:
Bandwidth-effective prevention of rollback attacks against
community repositories. In 2017 USENIX Annual Technical
Conference (USENIX ATC 17) (pp. 673–688). USENIX Association.
[20] Kunaparaju, C. (2024). Detecting and Preventing State-
Sponsored Cyber Attacks Using Deep Learning and Behavioral
Analytics. Journal of Electrical Systems, 20, 5471-5486.
[21] Zimmermann, M., Staicu, C. A., Tenny, C., & Pradel, M. (2019).
Small world with high risks: A study of security threats in the
npm ecosystem. In 28th USENIX Security Symposium (USENIX
Security 19) (pp. 995–1010). USENIX Association.
[22] Kula, R. G., German, D. M., Ouni, A., Ishio, T., & Inoue, K. (2018).
Do developers update their library dependencies? An empirical
study on the impact of security advisories on library migration.
Empirical Software Engineering, 23(1), 384–417. https://doi.
org/10.1007/s10664-017-9521-5.
[23] Decan, A., Mens, T., & Constantinou, E. (2018). On the
impact of security vulnerabilities in the npm package
dependency network. In Proceedings of the 15th International
Conference on Mining Software Repositories (pp. 181–
191). Association for Computing Machinery. https://doi.
org/10.1145/3196398.3196401.
[24] Pashchenko, I., Plate, H., Ponta, S. E., Sabetta, A., & Massacci, F.(2018). Vulnerable open source dependencies: Counting those
that matter. In Proceedings of the 12th ACM/IEEE International
Symposium on Empirical Software Engineering and Measurement
(Article 42, pp. 1–10). Association for Computing Machinery.
https://doi.org/10.1145/3239235.3268920.
[25] Lamb, C., & Zacchiroli, S. (2022). Reproducible builds: Increasing
the integrity of software supply chains. IEEE Software, 39(2),
62–70. https://doi.org/10.1109/MS.2021.3073045.
[26] Fourné, M., Wermke, D., Enck, W., Fahl, S., & Acar, Y. (2023). It’s
like flossing your teeth: On the importance and challenges of
reproducible builds for software supply chain security. In 2023
IEEE Symposium on Security and Privacy (SP) (pp. 1527–1544). IEEE.
https://doi.org/10.1109/SP46215.2023.10179320.
[27] Xia, B., Bi, T., Xing, Z., Lu, Q., & Zhu, L. (2023). An empirical
study on software bill of materials: Where we stand and the
road ahead. In 2023 IEEE/ACM 45th International Conference on
Software Engineering (ICSE) (pp. 2630–2642). IEEE. https://doi.
org/10.1109/ICSE48619.2023.00219.
[28] Jadala, S. K. (2024). Zero Trust Architecture and Identity Threat
Detection for Securing Cloud, IoT, and Hybrid Enterprise
Systems. International Journal of Humanities and Information
Technology, 6(04), 141-185.
[29] Zahan, N., Lin, E., Tamanna, M., Enck, W., & Williams, L. (2023).
Software bills of materials are required. Are we there yet?
IEEE Security & Privacy, 21(2), 82–88. https://doi.org/10.1109/
MSEC.2023.3237100.
[30] Stalnaker, T., Wintersgill, N., Chaparro, O., Di Penta, M.,
German, D. M., & Poshyvanyk, D. (2024). BOMs away! Inside
the minds of stakeholders: A comprehensive study of bills of
materials for software systems. In Proceedings of the IEEE/ACM
46th International Conference on Software Engineering (pp.
517–529). Association for Computing Machinery. https://doi.
org/10.1145/3597503.3623347.
[31] Potla, R. B. (2024). A SOX/ITAR-aligned global ERP template for
multi-plant manufacturers: Governance patterns and controls.
J Artif Intell Mach Learn & Data Sci, 2(2), 3222-3232.
[32] O’Donoghue, E., Boles, B., Izurieta, C., & Reinhold, A. M. (2024).
Impacts of software bill of materials (SBOM) generation on
vulnerability detection. In Proceedings of the 2024 Workshop on
Software Supply Chain Offensive Research and Ecosystem Defenses
(pp. 67–76). Association for Computing Machinery. https://doi.
org/10.1145/3689944.3696164.
[33] Sultan, S., Ahmad, I., & Dimitriou, T. (2019). Container security:
Issues, challenges, and the road ahead. IEEE Access, 7, 52976–
52996. https://doi.org/10.1109/ACCESS.2019.2911732.
[34] Rahman, A., Shamim, M. S. I., Bose, D. B., & Pandita, R. (2023).
Security misconfigurations in open source Kubernetes
manifests: An empirical study. ACM Transactions on Software
Engineering and Methodology, 32(4), Article 99, 1–36. https://
doi.org/10.1145/3579639.
[35] Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2022).
Challenges and solutions when adopting DevSecOps: A
systematic review. Information and Software Technology, 141,


