从组件快照到生命周期轨迹:基于智能体的软件成分分析
From Component Snapshots to Lifecycle Traces: Agent-Based Software Composition Analysis
- Huazhong University of Science and Technology(华中科技大学)
机构由 AI 辅助整理,请以论文原文为准。
中文总结 AI 辅助
针对软件成分分析仅提供阶段快照而无法追踪跨生命周期演变的问题,提出基于智能体的SCA-Agent方法,重建组件生命周期轨迹,在105个真实项目中达到96.69%的漏洞暴露评估F1分数,优于传统工具。
中文摘要 AI 辅助
软件供应链安全需要准确识别第三方组件,并理解它们从开发到执行的演变过程。现有的软件成分分析(SCA)方法检查清单文件、构建环境、发布制品、容器或运行时状态,但通常只生成软件成分的阶段特定视图。由于依赖关系在生命周期各阶段被解析、移除、重新打包和转换,单一快照无法同时捕获组件的来源和最终去向。结合多个阶段的快照仍无法解决其跨阶段关系。我们提出了SCA-Agent,一种基于智能体的生命周期感知SCA方法,可在代码、构建、发布、部署和运行时阶段重建有证据支持的组件生命周期轨迹。SCA-Agent自适应地探索项目特定的分析路径,收集阶段特定证据,并关联跨阶段观察结果,以恢复组件身份、版本、引入路径、传播关系和最终生命周期状态。我们在来自Java、JavaScript和Python生态系统的105个真实世界项目上评估了SCA-Agent。SCA-Agent在所有生命周期阶段和生态系统中实现了最高的组件检测F1分数。在漏洞暴露评估方面,其F1分数达到96.69%,超过最佳传统SCA工具18.76个百分点。这些结果表明,生命周期感知的SCA支持可追溯的组件来源和更准确的软件供应链风险评估。
英文摘要
Software supply-chain security requires accurate identification of third-party components and an understanding of how they evolve from development to execution. Existing software composition analysis (SCA) approaches examine manifests, build environments, release artifacts, containers, or runtime states, but typically produce only stage-specific views of software composition. As dependencies are resolved, removed, repackaged, and transformed across lifecycle stages, a single snapshot cannot capture both where a component originates and where it ultimately ends up. Combining snapshots from multiple stages still leaves their cross-stage relationships unresolved. We present SCA-Agent, an agent-based approach to lifecycle-aware SCA that reconstructs evidence-backed component lifecycle traces across Code, Build, Release, Deploy, and Runtime. SCA-Agent adaptively explores project-specific analysis paths, gathers stage-specific evidence, and correlates observations across stages to recover component identities, versions, introduction paths, propagation relationships, and final lifecycle states. We evaluate SCA-Agent on 105 real-world projects from the Java, JavaScript, and Python ecosystems. SCA-Agent achieves the highest component detection F1 across all lifecycle stages and ecosystems. For vulnerability exposure assessment, it reaches an F1 score of 96.69%, exceeding the best traditional SCA tool by 18.76 percentage points. These results show that lifecycle-aware SCA supports traceable component provenance and more accurate software supply-chain risk assessment.