This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember your browser. We use this information to improve and customize your browsing experience, for analytics and metrics about our visitors both on this website and other media, and for marketing purposes. By using this website, you accept and agree to be bound by UVic’s Terms of Use for web and social media privacy.  If you do not agree to the above, you can configure your browser’s setting to “do not track.”

Skip to main content

Solomon Onyeke Ameh

  • BEng (Covenant University, 2022)

Notice of the Final Oral Examination for the Degree of Master of Applied Science

Topic

Software Supply-Chain Security Modeling and Analysis using the Production View

Department of Electrical and Computer Engineering

Date & location

  • Tuesday, September 29, 2026

  • 9:00 A.M.

  • Virtual Defence

Reviewers

Supervisory Committee

  • Dr. Issa Traore, Department of Electrical and Computer Engineering, Uvic (Co-Supervisor)

  • Dr. Mohammed Mamun, Department of Electrical and Computer Engineering, UVic (Co-Supervisor) 

External Examiner

  • Dr. Alex Thomo, Department of Computer Science, University of Victoria 

Chair of Oral Examination

  • Dr. Margaret-Anne Storey, Department of Computer Science, UVic

     

Abstract

Supply chain management (SCM) is a dynamic field with varying definitions, diverse terminology, and limited visibility across organizations, making it difficult to represent secure chains. This thesis proposes and defines a production view modeling framework in which the supply chain is represented as a sequence of individual production steps. The framework was designed to preserve more details than producer-level representations and to support structural analysis of where important production steps occur within the chain. Warfield’s partitioning methods are used to describe structural levels, dependence, influence, and independent regions of the supply chain, providing a basis for identifying production steps that may be critical from a security perspective. The framework was evaluated using large-scale software supply chains (SSCs) constructed from the npm, PyPI, and Maven ecosystems, containing 250,944 packages and 1,063,358 dependency relationships. The evaluation focused on previously legitimate packages that were later compromised in recent supply-chain campaigns, including incidents linked to Shai-Hulud and TeamPCP. We compared the production view representation with detectors that rely on package metadata and examined what happens when metadata associated with the assessed package becomes unreliable. When package metadata was complete and unchanged, the npm metadata detector achieved an area under the receiver operating characteristic (ROC-AUC) curve of 0.992 and an area under the precision–recall (PR-AUC) curve of 0.929. Under adversarial manipulation, however, performance decreased substantially to 0.435 ROC-AUC and 0.019 PR-AUC. In comparison, production view features derived from structural position, centrality, upstream and downstream reach, and relationships with compromised or vulnerable production steps remained comparatively stable, achieving a ROC-AUC of 0.736 and a PR-AUC of 0.142. We also used Warfield’s partitioning to evaluate a two-stage detector that propagates risk scores from upstream Warfield’s levels, improving the results to 0.804 ROC-AUC and 0.201 PR-AUC. This work bridges theoretical supply-chain concepts and practical supply-chain security by defining an interpretable framework and demonstrating its application to a large software supply-chain dataset.