A Landscape Study of Open-Source Tools for Software Bill of Materials (SBOM) for Supply Chain Security
Modern software applications heavily rely on diverse third-party components, libraries, and frameworks sourced from various vendors and open source repositories. This presents a complex challenge for securing the software supply chain. To address this complexity, the adoption of a Software Bill of Materials (SBOM) has emerged as a promising solution, offering a unifying standard that inventories all third-party components and dependencies used in an application. Recent supply chain breaches, exemplified by the SolarWinds attack, underscore the urgent need to enhance software security and mitigate vulnerability risks. SBOMs play a pivotal role in this endeavor by revealing potential vulnerabilities, outdated components, and unsupported elements. This research paper conducts an extensive empirical analysis to assess the current landscape of open-source tools related to SBOM. We investigate emerging use cases in software supply chain security and identify gaps in SBOM technologies. Our analysis encompasses 84 tools, providing a snapshot of the current market and highlighting areas for improvement.
Sat 3 MayDisplayed time zone: Eastern Time (US & Canada) change
11:00 - 12:30 | |||
11:00 20mTalk | A Landscape Study of Open-Source Tools for Software Bill of Materials (SBOM) for Supply Chain Security SVM Derek Garcia University of Hawaii at Manoa, Mehdi Mirakhorli University of Hawaii at Manoa, Schuyler Dillon Rochester Institute of Technology, Kevin Laporte Rochester Institute of Technology, Matthew Morrison Rochester Institute of Technology, Henry Lu Rochester Institute of Technology, Viktoria Koscinski Rochester Institute of Technology, Christopher Enoch Rochester Institute of Technology, Mohamad Fazelnia University of Hawaii at Manoa, Roger Chen University of Hawaii at Manoa | ||
11:20 20mTalk | A Multi-Dimensional Visual Analytics Tool for the Security Posture of Open-Source Software SVM Tianyu Li DistriNet Group-T, KU Leuven, Chaomeng Lu DistriNet Group-T, KU Leuven, Bert Lagaisse DistriNet Group-T, KU Leuven | ||
11:40 50mMeeting | Round-table discussion on “SVM in the era of (Gen)AI” SVM |