Assessing Software Supply Chain Risk Using Public Data

被引:0
|
作者
Benthall, Sebastian [1 ]
机构
[1] Ion Channel, W Palm Beach, FL 33401 USA
关键词
Vulnerability discovery; security; supply chain risk; VULNERABILITY DISCOVERY MODELS; SYSTEMS;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The software supply chain is a source of cybersecurity risk for many commercial and government organizations. Public data may be used to inform automated tools for detecting software supply chain risk during continuous integration and deployment. We link data from the National Vulnerability Database (NVD) with open version control data for the open source project OpenSSL, a widely used secure networking library that made the news when a significant vulnerability, Heartbleed, was discovered in 2014. We apply the Alhazmi-Malaiya Logistic (AML) model for software vulnerability discovery to this case. This model predicts a sigmoid cumulative vulnerability discovery function over time. Some versions of OpenSSL do not conform to the predictions of the model because they contain a temporary plateau in the cumulative vulnerability discovery plot. This temporary plateau feature is an empirical signature of a security failure mode that may be useful in future studies of software supply chain risk.
引用
收藏
页数:5
相关论文
共 50 条
  • [1] Supply Chain Risk Management Using Software Tool
    Marija, Matotek
    Ivan, Barac
    Dusan, Regodic
    Gojko, Grubor
    [J]. ACTA POLYTECHNICA HUNGARICA, 2015, 12 (04) : 167 - 182
  • [2] Software Supply Chain Risk Assessment Framework
    Zahan, Nusrat
    [J]. 2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS, ICSE-COMPANION, 2023, : 251 - 255
  • [3] An Adaptive Model for Assessing Supply Chain Risk
    Kenyon, George
    Neureuther, Brian D.
    [J]. JOURNAL OF MARKETING CHANNELS, 2012, 19 (02) : 156 - 170
  • [4] Assessing and managing risks using the Supply Chain Risk Management Process (SCRMP)
    Tummala, Rao
    Schoenherr, Tobias
    [J]. SUPPLY CHAIN MANAGEMENT-AN INTERNATIONAL JOURNAL, 2011, 16 (06) : 474 - 483
  • [5] Assessing the efficiency of supply chain scheduling algorithms using data envelopment analysis
    Ching-Chin Chern
    Tzi-Yuan Chou
    Bo Hsiao
    [J]. Information Systems and e-Business Management, 2016, 14 : 823 - 856
  • [6] Assessing the efficiency of supply chain scheduling algorithms using data envelopment analysis
    Chern, Ching-Chin
    Chou, Tzi-Yuan
    Hsiao, Bo
    [J]. INFORMATION SYSTEMS AND E-BUSINESS MANAGEMENT, 2016, 14 (04) : 823 - 856
  • [7] Towards An Analysis of Software Supply Chain Risk Management
    Du, Shixian
    Lu, Tianbo
    Zhao, Lingling
    Xu, Bing
    Guo, Xiaobo
    Yang, Hongyu
    [J]. WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, WCECS 2013, VOL I, 2013, I : 162 - +
  • [9] Supply chain software
    Anon
    [J]. Modern Materials Handling, 2001, 56 (09)
  • [10] Public risk perception in the total meat supply chain
    Zingg, Alexandra
    Cousin, Marie-Eve
    Connor, Melanie
    Siegrist, Michael
    [J]. JOURNAL OF RISK RESEARCH, 2013, 16 (08) : 1005 - 1020