SynthChain: A Synthetic Benchmark and Forensic Analysis of Advanced and Stealthy Software Supply Chain Attacks
Zhuoran Tan, Wenbo Guo, Taylor Brierley, Jiewen Luo, Jeremy Singer, and Christos Anagnostopoulos

TL;DR
SynthChain provides a comprehensive dataset and analysis framework for understanding and detecting stealthy, runtime-only software supply chain attacks across multiple platforms and scenarios, highlighting the limitations of single-source detection.
Contribution
We introduce SynthChain, a realistic, multi-source dataset and testbed for analyzing advanced supply chain attacks, including ground truth and coverage metrics, to improve detection strategies.
Findings
Single-source detection coverage is limited (~39%)
Two-source fusion significantly improves coverage (~64%)
Multi-source data enables more effective forensic analysis
Abstract
Advanced software supply chain (SSC) attacks are increasingly runtime-only and leave fragmented evidence across hosts, services, and build/dependency layers, so any single telemetry stream is inherently insufficient to reconstruct full compromise chains under realistic access and budget limits. We present SynthChain, a near-production testbed and a multi-source runtime dataset with chain-level ground truth, derived from real-world malicious packages and exploit campaigns. SynthChain covers seven representative supply-chain exploit scenarios across PyPI, npm, and a native C/C++ supply-chain case, spanning Windows and Linux, and involving four hosts and one containerized environment. Scenarios span realistic time windows from minutes to hours and are annotated with 14 MITRE ATT&CK tactics and 161 techniques (29-104 techniques per scenario). Beyond releasing the data, we quantify…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDigital and Cyber Forensics · Advanced Malware Detection Techniques · Security and Verification in Computing
