On the Way to SBOMs: Investigating Design Issues and Solutions in Practice

04/26/2023
by   Tingting Bi, et al.
0

Software Bill of Materials (SBOM), offers improved transparency and supply chain security by providing a machine-readable inventory of software components used. With the rise in software supply chain attacks, the SBOM has attracted attention from both academia and industry. This paper presents a study on the practice of SBOM, based on the analysis of 4,786 GitHub discussions from 510 SBOM-related projects. Our study identifies key topics, challenges, and solutions associated with effective SBOM usage. We also highlight commonly used tools and frameworks for generating SBOMs, along with their respective strengths and limitations. Our research underscores the importance of SBOMs in software development and the need for their widespread adoption to enhance supply chain security. Additionally, the insights gained from our study can inform future research and development in this field.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/13/2023

An Empirical Study on Software Bill of Materials: Where We Stand and the Road Ahead

The rapid growth of software supply chain attacks has attracted consider...
research
03/20/2023

Challenges of Producing Software Bill Of Materials for Java

Software bills of materials (SBOM) promise to become the backbone of sof...
research
07/05/2023

Trust in Software Supply Chains: Blockchain-Enabled SBOM and the AIBOM Future

Software Bill of Materials (SBOM) serves as a critical pillar in ensurin...
research
09/08/2022

What is Software Supply Chain Security?

The software supply chain involves a multitude of tools and processes th...
research
10/11/2022

Software Supply Chain Attribute Integrity (SCAI)

The Software Supply Chain Attribute Integrity, or SCAI (pronounced "sky"...
research
09/21/2023

BOMs Away! Inside the Minds of Stakeholders: A Comprehensive Study of Bills of Materials for Software Systems

Software Bills of Materials (SBOMs) have emerged as tools to facilitate ...
research
07/28/2023

S3C2 Summit 2202-09: Industry Secure Suppy Chain Summit

Recent years have shown increased cyber attacks targeting less secure el...

Please sign up or login with your details

Forgot password? Click here to reset