A blockchain‐based and microservices‐architected software composition analysis system

Author:

Zhou Xin1ORCID,Xu Jinwei1,Li Xiaokang1,Cao Lingli1,Li Lingjie2,Wang Yanze1,Li Shanshan1,Liu Hui1

Affiliation:

1. State Key Laboratory for Novel Software Institute Nanjing University Nanjing China

2. Huawei Technologies Co., Ltd Nanjing China

Abstract

Abstract“Shift To Left” is the cornerstone of the successful implementation of DevSecOps. By testing projects for vulnerabilities in the early stages of development, teams can save overall costs before security issues reach the build phase. As one of the popular practices in “Shift To Left,” the Software Composition Analysis (SCA) system aims to leverage the Software Bill of Materials (SBOM) to enhance software supply chain security. However, the SBOM lacks mature generation and distribution mechanisms, requiring incentive measures to drive industry consensus. Additionally, the data and tools associated with the SBOM lack effective record‐keeping and monitoring, making it challenging to ensure data integrity and tool security. Traditional SCA systems treat SBOM as a regular data format for external service provision, yet fail to solve problems such as lack of shared platforms, inability to guarantee data integrity and tool security, as well as issues with poor interoperation compatibility. This paper introduces blockchain technology into the SCA system, utilizing smart contracts to provide core SBOM tool services and microservices to improve the operational efficiency of smart contract deployment and maintenance. The proposed SCA system effectively provides a shared platform for SBOM with reliable data integrity, guaranteed tool security, and good interoperability.

Publisher

Wiley

Reference31 articles.

1. MuiríEO.Framing software component transparency: establishing a common software bill of material (SBOM). NTIA Nov 12;2019.

2. HendrickS ZemlinJ.The state of software bill of materials (SBOM) and cybersecurity readiness.https://www.linuxfoundation.org/research/the-state-of-software-bill-of-materials-sbom-and-cybersecurity-readiness

3. CarterH.The 2023 state of the software supply chain report.https://www.sonatype.com/state-of-the-software-supply-chain/introduction

4. NTIA.The minimum elements for a software bill of materials (SBOM).https://www.ntia.doc.gov/files/ntia/publications/sbom_minimum_elements_report.pdf

5. XiaB BiT XingZ LuQ ZhuL.An empirical study on software bill of materials: where we stand and the road ahead. arXiv preprint arXiv:230105362;2023.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3