Propagation Model for SSC attacks: Why SBOM (tools) don't tell the whole truth

📅 2026-09-04
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究针对SBOM工具在检测软件供应链攻击传播效果上的不足,提出一个四阶段传播模型,并通过实证评估展示了现有工具的局限性。
📝 Abstract
Ensuring security of software supply chains (SSC) is indispensable in today's world of modern software practices. SBOM (tools) have been introduced as relevant building blocks to ensure the transparency of SSCs. However they have serious limitations in practices as their vulnerability detection and interpretation capacity is not sufficient to explain exploitability effects that can propagte through the whole chain. To address this gap, we propose a propagation-centred approach to SSC security and introduce a four-stage propagation model. We empirically evaluate four open-source SBOM tools against each stage using three projects and Log4j vulnerability as our test case. Our results show that current SBOM tools systematically support only Stage 1 (Structural Exposure) and Stage 2 (Vulnerability Class Presence) while Stage 3 (Code Reachability) and Stage 4 (Taint Path Analysis) require capabilities absent from the SBOM ecosystem. We argue that putting propagation effects at the centre of SSC security research is essential to prevent cyber risk evolving into systemic risks. Our research findings contribute to a future research and design of modern SSC security tools.
Problem

Research questions and friction points this paper is trying to address.

software supply chain
SBOM
vulnerability propagation
exploitability effects
cyber risk
Innovation

Methods, ideas, or system contributions that make the work stand out.

Propagation Model
SBOM Tools
Software Supply Chain Security
Code Reachability
Taint Path Analysis
🔎 Similar Papers
No similar papers found.
L
Ljubica Grgic
University of Liechtenstein, Vaduz, Liechtenstein
L
Lazar Maksimovic
University of Liechtenstein, Vaduz, Liechtenstein
Pavel Laskov
Pavel Laskov
University of Liechtenstein
Computer SecurityAdversarial Machine Learning