SMT: SBOM and Merkle Tree Based Integrity Verification for Serverless Environments
Serverless computing environments are vulnerable to software supply chain attacks due to their heavy reliance on external libraries. However, existing integrity verification methods are centered on runtime execution logs, which limits their ability to directly detect tampering with function code and dependencies. In th...