BOMs Away! Inside the Minds of Stakeholders: A Comprehensive Study of Bills of Materials for Software Systems

09/21/2023
by   Trevor Stalnaker, et al.
0

Software Bills of Materials (SBOMs) have emerged as tools to facilitate the management of software dependencies, vulnerabilities, licenses, and the supply chain. While significant effort has been devoted to increasing SBOM awareness and developing SBOM formats and tools, recent studies have shown that SBOMs are still an early technology not yet adequately adopted in practice. Expanding on previous research, this paper reports a comprehensive study that investigates the current challenges stakeholders encounter when creating and using SBOMs. The study surveyed 138 practitioners belonging to five stakeholder groups (practitioners familiar with SBOMs, members of critical open source projects, AI/ML, cyber-physical systems, and legal practitioners) using differentiated questionnaires, and interviewed 8 survey respondents to gather further insights about their experience. We identified 12 major challenges facing the creation and use of SBOMs, including those related to the SBOM content, deficiencies in SBOM tools, SBOM maintenance and verification, and domain-specific challenges. We propose and discuss 4 actionable solutions to the identified challenges and present the major avenues for future research and development.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/19/2023

Software Architecture in Practice: Challenges and Opportunities

Software architecture has been an active research field for nearly four ...
research
03/20/2023

Challenges of Producing Software Bill Of Materials for Java

Software bills of materials (SBOM) promise to become the backbone of sof...
research
08/22/2023

On-Premise AIOps Infrastructure for a Software Editor SME: An Experience Report

Information Technology has become a critical component in various indust...
research
01/13/2023

An Empirical Study on Software Bill of Materials: Where We Stand and the Road Ahead

The rapid growth of software supply chain attacks has attracted consider...
research
04/26/2023

On the Way to SBOMs: Investigating Design Issues and Solutions in Practice

Software Bill of Materials (SBOM), offers improved transparency and supp...
research
04/13/2022

Lessons learned from replicating a study on information-retrieval based test case prioritization

Objective: In this study, we aim to replicate an artefact-based study on...
research
04/03/2023

Characterizing the Users, Challenges, and Visualization Needs of Knowledge Graphs in Practice

This study presents insights from interviews with nineteen Knowledge Gra...

Please sign up or login with your details

Forgot password? Click here to reset