无边缘,无判定:对78K个野生软件物料清单中声明的依赖图的大规模实证研究
No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild
浏览论文内容
中文总结 AI 辅助
该研究对78K个野生SBOM文件中的声明依赖图进行大规模特征描述,发现其分为三种情况。指出边的发出由生成器决定,规范级机制使用少。认为前两种情况推断不合理,提出改进方法并发布相关工具和数据集,提高了KEV召回率。
中文摘要 AI 辅助
软件物料清单(SBOM)不仅作为组件清单使用,还作为依赖图使用:漏洞分类、可达性过滤和影响分析都要遍历SBOM声明的边。我们对来自野生SBOM数据集的78612个真实世界SBOM文件(77092个可解析)中的声明依赖图进行了首次大规模特征描述。我们发现总体分为三种情况:52.9%的SBOM根本不声明边(未达到NTIA依赖关系的最小元素要求),8.8%声明了一个依赖块,但大部分组件孤立(退化情况;在至少有50个组件的此类SBOM中,孤儿份额中位数为93%,我们的11个由Syft生成的容器镜像SBOM属于此情况,孤儿比例为95%-98%),38.3%形成连接良好的图。边的发出由生成器决定,而非所描述的软件(不同工具的无边缘率为0%-100%),声明图不完整性的规范级机制(CycloneDX组合)仅被0.10%的总体使用。我们认为在前两种情况下,常见的消费者推断“无路径意味着不可达”是从不完整工件得出的不合理封闭世界结论;在生产漏洞优先级系统中,用由退化检测器保护的明确“未知”级别取代由此产生的否决权,可将KEV召回率从0.600提高到0.950(受控重新评分;在实时端到端运行中为0.957)且无警报泛滥。我们发布了流扫描器和完整的每个SBOM拓扑数据集。
英文摘要
Software Bills of Materials (SBOMs) are consumed not only as component inventories but as dependency graphs: vulnerability triage, reachability filtering, and impact analysis all traverse the edges an SBOM declares. We present the first large-scale characterization of the declared dependency graph across 78,612 real-world SBOM files from the Wild SBOMs dataset (77,092 parseable). We find that the population splits into three regimes: 52.9% of SBOMs declare no edges at all (failing the NTIA minimum-elements requirement of dependency relationships), 8.8% declare a dependency block yet leave the majority of components isolated (degenerate regime; among such SBOMs with at least 50 components the median orphan share is 93%, and our 11 Syft-generated container-image SBOMs fall in this regime at 91.4-98.0% orphans), and 38.3% form well-connected graphs. Edge emission is determined by the generator, not the described software (0%-100% no-edge rates across tools), and the specification-level mechanism for declaring graph incompleteness (CycloneDX compositions) is used by 0.10% of CycloneDX documents. We argue that in the first two regimes, the common consumer inference "no path implies unreachable" is an unsound closed-world conclusion drawn from a demonstrably incomplete artifact; in a production vulnerability-prioritization system, replacing the resulting veto with an explicit "unknown" level guarded by a degeneracy detector recovered KEV recall from 0.600 to 0.950 (controlled re-scoring; 0.957 in a live end-to-end run) without alert flooding. We release our streaming scanner and the full per-SBOM topology dataset.