Back to results

Massachusetts Institute of Technology

Graph Metrics for Improving Cybersecurity on Software Dependency Networks

Abstract

dc:description.abstract

Modern software ecosystems are deeply interconnected, allowing a vulnerability in a single component to propagate and affect many others. In this thesis, we model software ecosystems as directed graphs, and apply various graph-theoretic metrics to quantify security risk. We compare two deep learning frameworks (PyTorch and TensorFlow) with two traditional software frameworks (npm and PyPI), identifying critical properties of their dependency structures, which motivates several recommendations for improving software supply chain security.

Degree

thesis:*
Name thesis:degree_name
Master
Department dc:contributor.department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Grantor dc:publisher
Massachusetts Institute of Technology
Year dc:date.issued
2025

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Yao, Darren Z.
Advisors dc:contributor.advisor
  • Pal, Ranjan
  • Siegel, Michael D.

Rights

dc:rights
Statement dc:rights
  • In Copyright - Educational Use Permitted
  • Copyright retained by author(s)

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/1721.1/162980
OAI identifier oai:identifier
oai:dspace.mit.edu:1721.1/162980

Chain of custody

source
Harvested from
MIT
Base URL
dspace.mit.edu/oai/request
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
related terms
citation

Yao, Darren Z.. Graph Metrics for Improving Cybersecurity on Software Dependency Networks. Massachusetts Institute of Technology, 2025. https://hdl.handle.net/1721.1/162980