Assessing Security Risks of Software Supply Chains Using Software Bill of Materials

被引:1
|
作者
O'Donoghue, Eric [1 ]
Reinhold, Ann Marie [1 ]
Izurieta, Clemente [1 ,2 ]
机构
[1] Montana State Univ, Gianforte Sch Comp, Bozeman, MT 59717 USA
[2] Idaho Natl Lab, Pacif Northwest Natl Lab, Bozeman, MT USA
关键词
Software Supply Chain Security; Software Bill of Materials; Mining Software Repositories; Third Party Code;
D O I
10.1109/SANER-C62648.2024.00023
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The software supply chain is composed of a growing number of components including binaries, libraries, tools, and microservices necessary to meet the requirements of modern software. Products assembled by software vendors are usually comprised of open-source and commercial components. Software supply chain attacks are one of the largest growing categories of cybersecurity threats and the large number of dependencies of a vendor's product makes it possible for a single vulnerability to propagate to many vendor products. Additionally, the software supply chain offers a large attack surface that allows vulnerabilities in upstream transitive dependencies to affect the core software. Software Bill Of Materials (SBOM) is an emerging technology that can be used in tandem with analysis tools to detect and mitigate security vulnerabilities in software supply chains. In this research, we use open-source tools Trivy and Grype to assess the security of 1,151 SBOMs mined from third-party software repositories of various domains and sizes. We explore the distribution of software vulnerabilities across SBOMs and look for the most vulnerable software components. We conclude that this research demonstrates the threat of security via software supply chain vulnerabilities as well as the viability of using SBOMs to help assess security in the software supply chain.
引用
收藏
页码:134 / 140
页数:7
相关论文
共 50 条
  • [1] Building resilient medical technology supply chains with a software bill of materials
    Seth Carmody
    Andrea Coravos
    Ginny Fahs
    Audra Hatch
    Janine Medina
    Beau Woods
    Joshua Corman
    npj Digital Medicine, 4
  • [2] Building resilient medical technology supply chains with a software bill of materials
    Carmody, Seth
    Coravos, Andrea
    Fahs, Ginny
    Hatch, Audra
    Medina, Janine
    Woods, Beau
    Corman, Joshua
    NPJ DIGITAL MEDICINE, 2021, 4 (01)
  • [3] Delta Security Certification for Software Supply Chains
    Milankovich, Akos
    Tuma, Katja
    IEEE SECURITY & PRIVACY, 2023, 21 (06) : 24 - 33
  • [4] Malware, weakware, and the security of software supply chains
    Axelrod, C.W. (waxelrod@delta-risk.net), 1600, U.S. Department of Defense (27):
  • [5] The Software Bill of Materials
    Riehle, Dirk
    COMPUTER, 2025, 58 (04) : 115 - 120
  • [6] Software Supply Chains
    Murphy, Gail C.
    2015 ACM/IEEE 18TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS (MODELS), 2015, : 2 - 2
  • [7] Software Supply Chains
    Defranco J.F.
    Kshetri N.
    Computer, 2022, 55 (10): : 16 - 17
  • [9] Catalog of metrics for assessing security risks of software throughout the software development life cycle
    Sultan, Khalid
    En-Nouaary, Abdeslam
    Hanaou-Lhadj, Abdelwahab
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND ASSURANCE, 2008, : 461 - 465
  • [10] Efforts to Improve and Utilize Security Transparency in Software Supply Chains
    Wada, Yasunori
    Arakawa, Reika
    NTT Technical Review, 2024, 22 (11): : 64 - 68