By listing the components included in an application, Software Bills of Materials (SBOMs) are intended to support the timely identification of vulnerable components and ensure the security of the software supply chain. However, we question the underlying assumption that there is agreement on the components to be listed in an SBOM and that current technology is sufficient to secure the software supply chain. First, we propose a ground-up analysis of Component Inclusion Mechanisms (CIM) in the software's development lifecycle. Then we systematically analyze the four popular SBOM generation tools, cdxgen, syft, trivy, ORT, and the Microsoft sbom-tool, to understand how they define and identify relevant components. Finally, we assess these using a ground truth across the programming languages Python, Java, Go, PHP, Rust, and C. While today's tools are a step toward identifying components, our results show that no tool covers all identified CIMs and that common gaps exist across tools. We demonstrate that, under the current vague definitions and tooling, SBOMs exhibit ambiguity and blind spots in component inclusion. Thus, a security-grade SBOM is not achievable with the evaluated tools, necessitating further progress to ensure software supply chain security. We need to go back to the drawing board to clarify which components should be included in an SBOM and revise SBOM generators accordingly. Without a shared understanding of what a component is, any effort to secure software supply chains with SBOMs will fail.


翻译:通过列出应用程序中包含的组件,软件物料清单(SBOM)旨在支持及时识别易受攻击的组件,并确保软件供应链的安全性。然而,我们质疑其潜在假设——即对于SBOM中应列出的组件存在共识,且当前技术足以保障软件供应链安全。首先,我们对软件开发生命周期中的组件纳入机制(CIM)进行了基础性分析。随后,我们系统性地评估了四种主流SBOM生成工具——cdxgen、syft、trivy、ORT以及微软的sbom-tool,以理解它们如何定义和识别相关组件。最后,我们基于涵盖Python、Java、Go、PHP、Rust和C编程语言的真实基准数据集对这些工具进行了评估。尽管当前工具在组件识别方面迈出了一步,但我们的结果表明,没有任何工具能覆盖所有已识别的组件纳入机制,且不同工具间存在共同的遗漏。我们证明,在现有模糊定义和工具条件下,SBOM在组件纳入方面存在歧义和盲点。因此,使用这些评估工具无法实现安全级别的SBOM,这需要进一步推进以确保软件供应链安全。我们必须回归设计初衷,明确SBOM应包含哪些组件,并相应修订SBOM生成器。若对何为组件缺乏共同理解,任何利用SBOM保障软件供应链安全的努力都将失败。

0
下载
关闭预览

相关内容

软件定义战争:跨越两大软件领域的鸿沟
专知会员服务
13+阅读 · 6月30日
《用于建模系统攻击路径的强化学习环境》
专知会员服务
23+阅读 · 3月5日
中文版 | 软件定义部队的摩擦、迷雾与失效困境
专知会员服务
18+阅读 · 2025年7月22日
《软件保障路线图》12页slides,美国国防工业协会
专知会员服务
32+阅读 · 2023年8月11日
探索(Exploration)还是利用(Exploitation)?强化学习如何tradeoff?
深度强化学习实验室
13+阅读 · 2020年8月23日
初学者系列:推荐系统Wide & Deep Learning详解
深度学习的目标检测技术演进:R-CNN、Fast R-CNN、Faster R-CNN
数据挖掘入门与实战
13+阅读 · 2018年4月6日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
8+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Arxiv
0+阅读 · 6月9日
VIP会员
最新内容
《反无人机交战场景下的战斗归零研究》
专知会员服务
2+阅读 · 今天2:34
博士论文 | 用代码结构感知方法推进代码大模型
《决策模型比较研究》
专知会员服务
11+阅读 · 7月25日
《美军水下战与海床战概述及本地实施》
专知会员服务
6+阅读 · 7月25日
面向未来冲突推进陆军情报体制改革
专知会员服务
5+阅读 · 7月25日
相关基金
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
8+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员