An Software Supply Chain (SSC) attack combines an upstream attack, where malicious codes are injected into a software artefact via a compromised life cycle activity, and a downstream attack on the consumers who use the compromised artefact. Organisations need thorough and trustworthy visibility over the entire SSC of their software inventory to detect risks early and rapidly identify compromised assets in the event of an SSC attack. One way to achieve such visibility is through SSC metadata, machine-readable and authenticated documents describing an artefact's lifecycle, such as how it was constructed and the utilised ``ingredients''. Adopting SSC metadata requires organisations to procure or develop a Software Supply Chain Metadata Management system (SCM2), a suite of software tools for performing life cycle activities of SSC metadata documents such as creation, signing, distribution, and consumption. Selecting or developing an SCM2 is challenging due to the lack of a comprehensive domain model and architectural blueprint to aid practitioners in navigating the vast design space of SSC metadata terminologies, frameworks, and solutions. This paper addresses the above-mentioned challenge with a Systematisation of Knowledge about SSC metadata and SCM2, presented as a Reference Architecture (RA). The RA comprises a domain model and an architectural blueprint for SCM2 systems, constructed from the concepts and building blocks scattered across existing SSC security frameworks and standards. Our evaluation shows that the RA framework is effective for analysing existing SCM2 solutions and guiding the engineering of new SCM2.
翻译:软件供应链攻击结合了上游攻击(即通过受损的生命周期活动将恶意代码注入软件制品)与针对使用该受损制品的消费者的下游攻击。组织需对其软件库存的整个软件供应链具备全面且可信的可见性,以尽早发现风险,并在遭遇软件供应链攻击时快速识别受损资产。实现此类可见性的一种途径是借助软件供应链元数据——即描述制品生命周期的机器可读且经认证的文档,例如其构建方式及所使用的"原材料"。采用软件供应链元数据要求组织采购或开发一套软件供应链元数据管理系统(SCM2),这是一系列用于执行软件供应链元数据文档生命周期活动(如创建、签名、分发和使用)的软件工具。由于缺乏全面的领域模型和架构蓝图来指导从业者在软件供应链元数据术语、框架和解决方案的广阔设计空间中导航,选择或开发SCM2颇具挑战性。本文通过系统化梳理关于软件供应链元数据及SCM2的知识,提出一个参考架构(RA)以应对上述挑战。该参考架构包含SCM2系统的领域模型和架构蓝图,其构建依据来自现有软件供应链安全框架与标准中分散的概念及构建模块。评估表明,该参考架构框架能有效分析现有SCM2解决方案,并指导新型SCM2的工程化开发。