EN
Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines
Abstract
The software bill of materials (SBOM) emerged in 2018 as an important component in software security and software supply chain management. SBOM is an inventory presented as a list of the components that make up software. In recent years, whether software products contain vulnerabilities is a phenomenon that should be checked regularly by the users of that product. This paper deals with the systematic identification and vulnerability analysis of software components based on the concept of software bill of materials. The fact that a software product itself does not contain vulnerabilities does not mean that the software product is secure. Even if software projects do not contain any vulnerabilities when examined alone, there may be vulnerabilities in their components. Vulnerabilities in the dependencies or components of the product may be sufficient for cyber attackers to exploit that product. Minimizing the damage caused by vulnerabilities in software components is the basis of cyber security efforts. In this study, the necessity of automatically generating software bill of materials in software development/deployment environments (CI/CD) and performing vulnerability analysis on this bill of materials is demonstrated and a suitable model is proposed.
Keywords
References
- [1] E. Peters and G. K. Aggrey, “An iso 25010 based quality model for erp systems,” Adv. Sci. Technol. Eng. Syst. J, vol. 5, no. 2, pp. 578–583, 2020.
- [2] A. A. Pratama and A. B. Mutiara, “Software quality analysis for halodoc application using iso 25010: 2011,” Int. J. Adv. Comput. Sci. Appl, vol. 12, no. 8, pp. 383–392, 2021.
- [3] A. Arora and C. Garman, “Analysis of software bill of materials tools,” Cyber Security: A Peer-Reviewed Journal, vol. 6, no. 4, pp. 334–355, 2023.
- [4] S. Butler, J. Gamalielsson, B. Lundell, C. Brax, A. Mattsson, T. Gustavsson, J. Feist, B. Kvarnstr¨om, and E. L¨onroth, “Considerations and challenges for the adoption of open source components in software-intensive businesses,” Journal of Systems and Software, vol. 186, p. 111152, 2022.
- [5] V. Axelsson and F. Larsson, “Understanding the software bill of material for supply-chain management in open source projects,” 2023.
- [6] A. Adewumi, S. Misra, and N. Omoregbe, “Evaluating open source software quality models against iso 25010,” in 2015 IEEE International Conference on Computer and Information Technology; Ubiquitous Computing and Communications; Dependable, Autonomic and Secure Computing; Pervasive Intelligence and Computing. IEEE, 2015, pp. 872–877.
- [7] J. T. Stoddard, M. A. Cutshaw, T. Williams, A. Friedman, and J. Murphy, “Software bill of materials (sbom) sharing lifecycle report,” Idaho National Lab.(INL), Idaho Falls, ID (United States), Tech. Rep., 2023.
- [8] L. J. Camp and V. Andalibi, “Sbom vulnerability assessment & corresponding requirements,” NTIA Response to Notice and Request for Comments on Software Bill of Materials Elements and Considerations, 2021.
Details
Primary Language
English
Subjects
Software and Application Security
Journal Section
Research Article
Publication Date
June 30, 2024
Submission Date
March 18, 2024
Acceptance Date
June 28, 2024
Published in Issue
Year 2024 Volume: 13 Number: 2
APA
Kağızmandere, Ö., & Arslan, H. (2024). Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. International Journal of Information Security Science, 13(2), 33-42. https://doi.org/10.55859/ijiss.1455039
AMA
1.Kağızmandere Ö, Arslan H. Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. IJISS. 2024;13(2):33-42. doi:10.55859/ijiss.1455039
Chicago
Kağızmandere, Ömercan, and Halil Arslan. 2024. “Vulnerability Analysis Based on SBOMs: A Model Proposal for Automated Vulnerability Scanning for CI CD Pipelines”. International Journal of Information Security Science 13 (2): 33-42. https://doi.org/10.55859/ijiss.1455039.
EndNote
Kağızmandere Ö, Arslan H (June 1, 2024) Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. International Journal of Information Security Science 13 2 33–42.
IEEE
[1]Ö. Kağızmandere and H. Arslan, “Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines”, IJISS, vol. 13, no. 2, pp. 33–42, June 2024, doi: 10.55859/ijiss.1455039.
ISNAD
Kağızmandere, Ömercan - Arslan, Halil. “Vulnerability Analysis Based on SBOMs: A Model Proposal for Automated Vulnerability Scanning for CI CD Pipelines”. International Journal of Information Security Science 13/2 (June 1, 2024): 33-42. https://doi.org/10.55859/ijiss.1455039.
JAMA
1.Kağızmandere Ö, Arslan H. Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. IJISS. 2024;13:33–42.
MLA
Kağızmandere, Ömercan, and Halil Arslan. “Vulnerability Analysis Based on SBOMs: A Model Proposal for Automated Vulnerability Scanning for CI CD Pipelines”. International Journal of Information Security Science, vol. 13, no. 2, June 2024, pp. 33-42, doi:10.55859/ijiss.1455039.
Vancouver
1.Ömercan Kağızmandere, Halil Arslan. Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. IJISS. 2024 Jun. 1;13(2):33-42. doi:10.55859/ijiss.1455039