发表机构
CrySyS Lab Budapest Univ. of Technology and Economics(布达佩斯技术与经济大学 CrySyS 实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出研究议程,通过知识系统化识别依赖建模与漏洞传播的不足,主张统一测量跨生态系统依赖结构,并应对AI辅助开发带来的新依赖模式挑战。
AI 中文摘要
软件供应链安全已变得日益关键,这源于对第三方依赖的广泛依赖以及现代软件生态系统不断增长的攻击面。然而,现有的定量、基于测量的分析和漏洞管理方法在很大程度上仍然分散且特定于生态系统,限制了它们跨环境提供可比风险评估的能力。本文提出了一项结构化研究计划,首先通过知识系统化(SoK)来综合当前研究现状并识别关键差距,突出依赖建模和漏洞传播分析中的局限性,特别是在传递依赖及其实际可利用性的处理方面。基于这些见解,我们主张采用统一的测量视角,以一致地表示和分析跨生态系统的依赖结构。我们进一步识别了由AI辅助软件开发带来的新兴挑战,其中编码大语言模型(LLM)可能促成传统软件成分分析(SCA)工具无法捕获的新依赖模式。这些转变促使我们重新思考依赖建模,以考虑不断演进的软件生成实践及其对软件安全性的长期结构性影响。
英文摘要
Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosystem-specific, limiting their ability to provide comparable risk assessments across environments. This paper presents a structured research plan, starting with a Systematization of Knowledge (SoK) to synthesize the current state of research and identify key gaps, highlighting the limitations in dependency modeling and vulnerability propagation analysis, particularly in the treatment of transitive dependencies and their real-world exploitability. Based on these insights, we argue for a unified measurement perspective capable of consistently representing and analyzing the cross-ecosystem dependency structure. We further identify emerging challenges introduced by AI-assisted software development, where coding LLMs are likely to contribute to new dependency patterns that are not captured by traditional Software Composition Analysis (SCA) tools. These shifts motivate a rethink of dependency modeling to account for evolving software-generation practices and their long-term structural impact on software security.
CommentsAccepted at IEEE ICSME 2026 , 6 pages , 3 figures