Skip to main navigation Skip to search Skip to main content

Impacts of Software Bill of Materials (SBOM) Generation on Vulnerability Detection

  • Eric O’Donoghue
  • , Brittany Boles
  • , Clemente Izurieta
  • , Ann Marie Reinhold

Research output: Contribution to conferencePaperpeer-review

Abstract

The software supply chain (SSC) continues to face cybersecurity threats. To assist in securingSSCs,SoftwareBillofMaterials(SBOM) has emerged as a pivotal technology. Despite the increasing use of SBOMs, the influence of SBOM generation on vulnerability detection was unaddressed. We created four corpora of SBOMs from 2,313 Docker images by varying SBOM generation tool (Syft, Trivy) and SBOMformat(CycloneDX, SPDX). Using three commonSBOM analysis tools (Trivy, Grype, CVE-bin-tool), we investigated how the reported vulnerabilities for the same software artifact varied whenwechangedonly the SBOMgeneration tool and format. With the complex nature of SBOM generation and analysis, we expected some variation in reported vulnerabilities. However, we found high variability in vulnerability reporting attributed to SBOM generation. The variation in the quantity of vulnerabilities discovered in the same software artifact highlights the need for rigorous validation and enhancement of SBOM technologies to best secure SSCs.
Original languageAmerican English
StatePublished - Oct 18 2024
Event2024 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses - Salt Lake City, United States
Duration: Oct 18 2024Oct 18 2024

Conference

Conference2024 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses
Abbreviated titleSCORED
Country/TerritoryUnited States
CitySalt Lake City
Period10/18/2410/18/24

INL Publication Number

  • NA

Fingerprint

Dive into the research topics of 'Impacts of Software Bill of Materials (SBOM) Generation on Vulnerability Detection'. Together they form a unique fingerprint.

Cite this