An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management

被引:0
|
作者
Nguyen Khoi Tran [1 ]
Pallewatta, Samodha [1 ]
Babar, M. Ali [2 ]
机构
[1] Univ Adelaide, Adelaide, SA, Australia
[2] Univ Adelaide, CREST, Cyber Secur Cooperat Res Ctr, Adelaide, SA, Australia
来源
PROCEEDINGS OF 2024 28TH INTERNATION CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, EASE 2024 | 2024年
关键词
Software Supply Chain; SSC Metadata; SBOM; Software Provenance; Reference Architecture; Systematisation of Knowledge; Empirically Grounded;
D O I
10.1145/3661167.3661212
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
With the rapid rise in Software Supply Chain (SSC) attacks, organisations need thorough and trustworthy visibility over the entire SSC of their software inventory to detect risks early and identify compromised assets rapidly in the event of an SSC attack. One way to achieve such visibility is through SSC metadata, machine-readable and authenticated documents describing an artefact's lifecycle. Adopting SSC metadata requires organisations to procure or develop a Software Supply Chain Metadata Management system (SCM2), a suite of software tools for performing life cycle activities of SSC metadata documents such as creation, signing, distribution, and consumption. Selecting or developing an SCM2 is challenging due to the lack of a comprehensive domain model and architectural blueprint to aid practitioners in navigating the vast design space of SSC metadata terminologies, frameworks, and solutions. This paper addresses the above-mentioned challenge by presenting an empirically grounded Reference Architecture (RA) comprising of a domain model and an architectural blueprint for SCM2 systems. Our proposed RA is constructed systematically on an empirical foundation built with industry-driven and peer-reviewed SSC security frameworks. Our theoretical evaluation, which consists of an architectural mapping of five prominent SSC security tools on the RA, ensures its validity and applicability, thus affirming the proposed RA as an effective framework for analysing existing SCM2 solutions and guiding the engineering of new SCM2 systems.
引用
收藏
页码:38 / 47
页数:10
相关论文
共 50 条
  • [1] Software component architecture in supply chain management
    Verwijmeren, M
    COMPUTERS IN INDUSTRY, 2004, 53 (02) : 165 - 178
  • [2] Guest editorial: Empirically grounded research in logistics and supply chain management for a circular economy
    Zhang, Abraham
    Seuring, Stefan
    Hartley, Janet L.
    INTERNATIONAL JOURNAL OF LOGISTICS MANAGEMENT, 2023, 34 (03) : 517 - 522
  • [3] Modelling supply chain adaptation for disruptions: An empirically grounded complex adaptive systems approach
    Zhao, Kang
    Zuo, Zhiya
    Blackhurst, Jennifer, V
    JOURNAL OF OPERATIONS MANAGEMENT, 2019, 65 (02) : 190 - 212
  • [4] Design and Application on Metadata Management for Information Supply Chain
    Dong, Runsha
    Su, Fei
    Yang, Shan
    Xu, Lexi
    Cheng, Xinzhou
    Chen, Weiwei
    2016 16TH INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES (ISCIT), 2016, : 393 - 396
  • [5] Grounded theory analysis of municipal supply chain management
    Ambe, Intaher M.
    Badenhorst-Weiss, Johanna A.
    AFRICAN JOURNAL OF BUSINESS MANAGEMENT, 2011, 5 (29): : 11562 - 11571
  • [6] Software for supply chain management is improving
    Anon
    Elevator World, 2001, 49 (06): : 150 - 151
  • [7] Supply chain management and the software production
    Kuilboer, JP
    ASSOCIATION FOR INFORMATION SYSTEMS PROCEEDING OF THE AMERICAS CONFERENCE ON INFORMATION SYSTEMS, 1997, : 628 - 630
  • [8] New supply chain management software
    不详
    INTERNATIONAL SUGAR JOURNAL, 2001, 103 (1234): : 437 - 437
  • [9] An Empirically Grounded Conceptual Architecture for Applications on the Web of Data
    Heitmann, Benjamin
    Cyganiak, Richard
    Hayes, Conor
    Decker, Stefan
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS PART C-APPLICATIONS AND REVIEWS, 2012, 42 (01): : 51 - 60
  • [10] Performance analysis of Supply Chain Management with Supply Chain Operation reference model
    Hasibuan, Abdurrozzaq
    Arfah, Mahrani
    Parinduri, Luthfi
    Hernawati, Tri
    Suliawati
    Harahap, Bonar
    Sibuea, Siti Rahmah
    Sulaiman, Oris Krianto
    Purwadi, Adi
    INTERNATIONAL CONFERENCE ON MECHANICAL, ELECTRONICS, COMPUTER, AND INDUSTRIAL TECHNOLOGY, 2018, 1007