软件供应链 SBOM 关键技术研究
作者:
中图分类号:

TP311

基金项目:

中国科学院战略性先导科技专项(XDA0320401); 2023年开源社区软件物料清单SBOM平台项目(E3GX310201); 国家自然科学基金(62202457)


Research on Key Technologies of SBOM in Software Supply Chain
Author:
  • 摘要
  • | |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • | |
  • 文章评论
    摘要:

    供应链级别的开源软件及组件复用是当前软件开发的主流模式. 该模式避免了重复开发, 降低了研发成本, 提高了开发效率, 但是也不可避免地存在组件的来源未知, 成分不清, 漏洞不明, 许可证违规等问题. 为解决上述问题, 研究人员提出了软件物料清单(software bill of material, SBOM). SBOM详细列出了构成软件的组件及组件之间的关系, 揭示了潜在的和已知的威胁, 使软件透明化. 自提出以来, 国内外研究人员针对SBOM的研究主要聚焦在SBOM的现状、应用和工具上, 缺少理论化、体系化的研究. 综述SBOM的背景、基本概念、生成技术、工具及性能分析、应用、挑战与趋势, 并提出融合细粒度安全漏洞感知, 许可证冲突检测的SBOM+, 以期从概念、技术、工具、应用和发展等方面为SBOM、软件开发、供应链安全等研究人员提供支撑.

    Abstract:

    The current mainstream mode of software development is the supply chain-level reuse of open-source software and components. It avoids repetitive development, reduces research and development costs, and enhances development efficiency. However, it inevitably brings about issues such as unknown component sources, unclear component compositions, unidentified component vulnerabilities, and license violations. To address these issues, researchers propose software bill of materials (SBOM). SBOM provides a detailed list of software components and their relationships, reveals potential and known threats, and makes software transparent. Since its proposal, research on SBOM by researchers both at home and abroad mainly focus on its current status, applications, and tools, lacking theoretical and systematic research. This study presents a comprehensive review of the background, basic concepts, generation techniques, tools and performance analysis, applications, challenges, and trends of SBOM. It also proposes the new concept of SBOM+, which integrates fine-grained security vulnerability perception and license conflict detection. The aim is to provide support for researchers engaged in SBOM, software development, and supply chain security from the perspectives of concepts, technologies, tools, applications, and development.

    参考文献
    相似文献
    引证文献
引用本文

孙泽雨,吴敬征,凌祥,魏怡琳,罗天悦,武延军.软件供应链 SBOM 关键技术研究.软件学报,,():1-39

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2024-04-30
  • 最后修改日期:2024-06-17
  • 在线发布日期: 2025-03-19
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号