Abstract
The software supply chain (SSC) continues to face cybersecurity threats. To assist in securingSSCs,SoftwareBillofMaterials(SBOM) has emerged as a pivotal technology. Despite the increasing use of SBOMs, the influence of SBOM generation on vulnerability detection was unaddressed. We created four corpora of SBOMs from 2,313 Docker images by varying SBOM generation tool (Syft, Trivy) and SBOMformat(CycloneDX, SPDX). Using three commonSBOM analysis tools (Trivy, Grype, CVE-bin-tool), we investigated how the reported vulnerabilities for the same software artifact varied whenwechangedonly the SBOMgeneration tool and format. With the complex nature of SBOM generation and analysis, we expected some variation in reported vulnerabilities. However, we found high variability in vulnerability reporting attributed to SBOM generation. The variation in the quantity of vulnerabilities discovered in the same software artifact highlights the need for rigorous validation and enhancement of SBOM technologies to best secure SSCs.
| Original language | American English |
|---|---|
| State | Published - Oct 18 2024 |
| Event | 2024 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses - Salt Lake City, United States Duration: Oct 18 2024 → Oct 18 2024 |
Conference
| Conference | 2024 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses |
|---|---|
| Abbreviated title | SCORED |
| Country/Territory | United States |
| City | Salt Lake City |
| Period | 10/18/24 → 10/18/24 |
INL Publication Number
- NA
Fingerprint
Dive into the research topics of 'Impacts of Software Bill of Materials (SBOM) Generation on Vulnerability Detection'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver