Research Article

Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines

Volume: 13 Number: 2 June 30, 2024
EN

Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines

Abstract

The software bill of materials (SBOM) emerged in 2018 as an important component in software security and software supply chain management. SBOM is an inventory presented as a list of the components that make up software. In recent years, whether software products contain vulnerabilities is a phenomenon that should be checked regularly by the users of that product. This paper deals with the systematic identification and vulnerability analysis of software components based on the concept of software bill of materials. The fact that a software product itself does not contain vulnerabilities does not mean that the software product is secure. Even if software projects do not contain any vulnerabilities when examined alone, there may be vulnerabilities in their components. Vulnerabilities in the dependencies or components of the product may be sufficient for cyber attackers to exploit that product. Minimizing the damage caused by vulnerabilities in software components is the basis of cyber security efforts. In this study, the necessity of automatically generating software bill of materials in software development/deployment environments (CI/CD) and performing vulnerability analysis on this bill of materials is demonstrated and a suitable model is proposed.

Keywords

References

  1. [1] E. Peters and G. K. Aggrey, “An iso 25010 based quality model for erp systems,” Adv. Sci. Technol. Eng. Syst. J, vol. 5, no. 2, pp. 578–583, 2020.
  2. [2] A. A. Pratama and A. B. Mutiara, “Software quality analysis for halodoc application using iso 25010: 2011,” Int. J. Adv. Comput. Sci. Appl, vol. 12, no. 8, pp. 383–392, 2021.
  3. [3] A. Arora and C. Garman, “Analysis of software bill of materials tools,” Cyber Security: A Peer-Reviewed Journal, vol. 6, no. 4, pp. 334–355, 2023.
  4. [4] S. Butler, J. Gamalielsson, B. Lundell, C. Brax, A. Mattsson, T. Gustavsson, J. Feist, B. Kvarnstr¨om, and E. L¨onroth, “Considerations and challenges for the adoption of open source components in software-intensive businesses,” Journal of Systems and Software, vol. 186, p. 111152, 2022.
  5. [5] V. Axelsson and F. Larsson, “Understanding the software bill of material for supply-chain management in open source projects,” 2023.
  6. [6] A. Adewumi, S. Misra, and N. Omoregbe, “Evaluating open source software quality models against iso 25010,” in 2015 IEEE International Conference on Computer and Information Technology; Ubiquitous Computing and Communications; Dependable, Autonomic and Secure Computing; Pervasive Intelligence and Computing. IEEE, 2015, pp. 872–877.
  7. [7] J. T. Stoddard, M. A. Cutshaw, T. Williams, A. Friedman, and J. Murphy, “Software bill of materials (sbom) sharing lifecycle report,” Idaho National Lab.(INL), Idaho Falls, ID (United States), Tech. Rep., 2023.
  8. [8] L. J. Camp and V. Andalibi, “Sbom vulnerability assessment & corresponding requirements,” NTIA Response to Notice and Request for Comments on Software Bill of Materials Elements and Considerations, 2021.

Details

Primary Language

English

Subjects

Software and Application Security

Journal Section

Research Article

Publication Date

June 30, 2024

Submission Date

March 18, 2024

Acceptance Date

June 28, 2024

Published in Issue

Year 2024 Volume: 13 Number: 2

APA
Kağızmandere, Ö., & Arslan, H. (2024). Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. International Journal of Information Security Science, 13(2), 33-42. https://doi.org/10.55859/ijiss.1455039
AMA
1.Kağızmandere Ö, Arslan H. Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. IJISS. 2024;13(2):33-42. doi:10.55859/ijiss.1455039
Chicago
Kağızmandere, Ömercan, and Halil Arslan. 2024. “Vulnerability Analysis Based on SBOMs: A Model Proposal for Automated Vulnerability Scanning for CI CD Pipelines”. International Journal of Information Security Science 13 (2): 33-42. https://doi.org/10.55859/ijiss.1455039.
EndNote
Kağızmandere Ö, Arslan H (June 1, 2024) Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. International Journal of Information Security Science 13 2 33–42.
IEEE
[1]Ö. Kağızmandere and H. Arslan, “Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines”, IJISS, vol. 13, no. 2, pp. 33–42, June 2024, doi: 10.55859/ijiss.1455039.
ISNAD
Kağızmandere, Ömercan - Arslan, Halil. “Vulnerability Analysis Based on SBOMs: A Model Proposal for Automated Vulnerability Scanning for CI CD Pipelines”. International Journal of Information Security Science 13/2 (June 1, 2024): 33-42. https://doi.org/10.55859/ijiss.1455039.
JAMA
1.Kağızmandere Ö, Arslan H. Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. IJISS. 2024;13:33–42.
MLA
Kağızmandere, Ömercan, and Halil Arslan. “Vulnerability Analysis Based on SBOMs: A Model Proposal for Automated Vulnerability Scanning for CI CD Pipelines”. International Journal of Information Security Science, vol. 13, no. 2, June 2024, pp. 33-42, doi:10.55859/ijiss.1455039.
Vancouver
1.Ömercan Kağızmandere, Halil Arslan. Vulnerability analysis based on SBOMs: A model proposal for automated vulnerability scanning for CI/CD pipelines. IJISS. 2024 Jun. 1;13(2):33-42. doi:10.55859/ijiss.1455039