arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.05380cs.CR

软件供应链攻击的传播模型:为何SBOM(工具)无法呈现全部真相

Propagation Model for SSC attacks: Why SBOM (tools) don't tell the whole truth

发表机构列支敦士登大学
查看机构详情
  • University of Liechtenstein(列支敦士登大学)

机构由 AI 辅助整理,请以论文原文为准。

Ljubica Grgic, Lazar Maksimovic, Pavel Laskov

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对SBOM工具无法完整呈现软件供应链攻击传播效应的问题,提出四阶段传播模型,实证发现现有SBOM工具仅支持前两个阶段,成果为SSC安全工具研发提供支撑。

中文摘要 AI 辅助

确保软件供应链(SSC)的安全性在当今现代软件实践中不可或缺。SBOM(软件物料清单)工具已被引入作为确保SSC透明度的相关基础组件,然而在实际应用中存在严重局限性:其漏洞检测与解释能力不足以说明可在整个供应链中传播的利用性影响。为解决这一缺口,本文提出一种以传播为核心的SSC安全方法,并引入四阶段传播模型。我们以三个项目和Log4j漏洞为测试用例,针对每个阶段对四种开源SBOM工具进行实证评估。结果显示,当前SBOM工具仅系统支持阶段1(结构暴露)和阶段2(漏洞类别存在),而阶段3(代码可达性)与阶段4(污点路径分析)所需的能力在SBOM生态系统中缺失。我们认为,将传播效应置于SSC安全研究的核心,对于防止网络风险演变为系统性风险至关重要,研究成果将为未来现代SSC安全工具的研究与设计提供支撑。

英文摘要

Ensuring security of software supply chains (SSC) is indispensable in today's world of modern software practices. SBOM (tools) have been introduced as relevant building blocks to ensure the transparency of SSCs. However they have serious limitations in practices as their vulnerability detection and interpretation capacity is not sufficient to explain exploitability effects that can propagte through the whole chain. To address this gap, we propose a propagation-centred approach to SSC security and introduce a four-stage propagation model. We empirically evaluate four open-source SBOM tools against each stage using three projects and Log4j vulnerability as our test case. Our results show that current SBOM tools systematically support only Stage 1 (Structural Exposure) and Stage 2 (Vulnerability Class Presence) while Stage 3 (Code Reachability) and Stage 4 (Taint Path Analysis) require capabilities absent from the SBOM ecosystem. We argue that putting propagation effects at the centre of SSC security research is essential to prevent cyber risk evolving into systemic risks. Our research findings contribute to a future research and design of modern SSC security tools.

补充信息

↑