arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

分布式开源漏洞生态系统

The Distributed Open-Source Vulnerability Ecosystem

Peter Mandl, Paul Mandl

arXiv 2607.14900首次发表:更新:

AI 中文总结

研究软件供应链安全中漏洞识别问题,提出将漏洞管理视为信息交换与转换分布式过程的概念框架,追踪漏洞信息流程,分析扫描器结果不一致原因,探讨对相关方面的影响。

AI 中文摘要

识别已知软件漏洞是软件供应链安全管理的核心任务。尽管公开的漏洞信息基于共享标准,但不同的漏洞扫描器对相同软件清单的报告结果往往不同。这些差异并非仅源于个别数据源或扫描器实现,而是在开源漏洞生态系统的多个阶段出现。本文提出一个概念框架,将漏洞管理描述为信息交换和转换的分布式过程。它追踪漏洞信息从创建、标准化到丰富再到上下文相关解释的过程。分析确定了异构信息源、不同的身份和版本模型、时间变化以及上下文相关评估是扫描器结果不一致的主要原因。然后讨论了对解释分析结果、设计可重复评估方法以及在实践中处理动态漏洞知识的影响。

英文摘要

Identifying known software vulnerabilities is a central task in software supply chain security management. Although publicly available vulnerability information is based on shared standards, different vulnerability scanners often report divergent results for identical software inventories. These differences do not arise solely from individual data sources or scanner implementations. They can emerge at several stages of the open-source vulnerability ecosystem. This paper presents a conceptual framework that describes vulnerability management as a distributed process of information exchange and transformation. It traces vulnerability information from its creation and standardization through enrichment to context-dependent interpretation. The analysis identifies heterogeneous information sources, divergent identity and version models, temporal change, and context-dependent assessment as major causes of inconsistent scanner findings. It then discusses the implications for interpreting analysis results, designing reproducible evaluation methods, and handling dynamic vulnerability knowledge in practice.

Comments15 pages, 4 figures, 2 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑