An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management

被引:0
|
作者
Nguyen Khoi Tran [1 ]
Pallewatta, Samodha [1 ]
Babar, M. Ali [2 ]
机构
[1] Univ Adelaide, Adelaide, SA, Australia
[2] Univ Adelaide, CREST, Cyber Secur Cooperat Res Ctr, Adelaide, SA, Australia
来源
PROCEEDINGS OF 2024 28TH INTERNATION CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, EASE 2024 | 2024年
关键词
Software Supply Chain; SSC Metadata; SBOM; Software Provenance; Reference Architecture; Systematisation of Knowledge; Empirically Grounded;
D O I
10.1145/3661167.3661212
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
With the rapid rise in Software Supply Chain (SSC) attacks, organisations need thorough and trustworthy visibility over the entire SSC of their software inventory to detect risks early and identify compromised assets rapidly in the event of an SSC attack. One way to achieve such visibility is through SSC metadata, machine-readable and authenticated documents describing an artefact's lifecycle. Adopting SSC metadata requires organisations to procure or develop a Software Supply Chain Metadata Management system (SCM2), a suite of software tools for performing life cycle activities of SSC metadata documents such as creation, signing, distribution, and consumption. Selecting or developing an SCM2 is challenging due to the lack of a comprehensive domain model and architectural blueprint to aid practitioners in navigating the vast design space of SSC metadata terminologies, frameworks, and solutions. This paper addresses the above-mentioned challenge by presenting an empirically grounded Reference Architecture (RA) comprising of a domain model and an architectural blueprint for SCM2 systems. Our proposed RA is constructed systematically on an empirical foundation built with industry-driven and peer-reviewed SSC security frameworks. Our theoretical evaluation, which consists of an architectural mapping of five prominent SSC security tools on the RA, ensures its validity and applicability, thus affirming the proposed RA as an effective framework for analysing existing SCM2 solutions and guiding the engineering of new SCM2 systems.
引用
收藏
页码:38 / 47
页数:10
相关论文
共 50 条
  • [21] A knowledge management architecture in collaborative supply chain
    Lin, Chinho
    Hung, Hsiang-Chin
    Wu, June-Yie
    Lin, Binshan
    Journal of Computer Information Systems, 2002, 42 (5 SPEC. ISS.) : 83 - 94
  • [22] Agent architecture and collaboration for supply chain management
    Gao, Lin
    Wang, Runxiao
    Sheng, Yijun
    Hu, Zhiqing
    Wuhan Ligong Daxue Xuebao/Journal of Wuhan University of Technology, 2006, 28 (SUPPL. 1): : 1140 - 1143
  • [23] An analysis of a supply chain management agent architecture
    Ivezic, N
    Barbacci, M
    Libes, D
    Potok, T
    Robert, J
    FOURTH INTERNATIONAL CONFERENCE ON MULTIAGENT SYSTEMS, PROCEEDINGS, 2000, : 401 - 402
  • [24] SUPPLY CHAIN MANAGEMENT AND EMPLOYEES' MENTAL HEALTH: VIEW OF GROUNDED THEORY
    Tao, Xiaobo
    Han, Zhifang
    MEDICINE, 2023, 102 (30) : 43 - 43
  • [25] Blockchain in supply chain management: a grounded theory-based analysis
    Rodrigues, Eladian Batista
    Lourenzani, Wagner Luiz
    Satolo, Eduardo Guilherme
    Braga Junior, Sergio Silva
    Anholon, Rosley
    Simon Rampasso, Izabela
    KYBERNETES, 2023, 52 (04) : 1425 - 1444
  • [26] Dynamic Capabilities in Operations Management: An Empirically Grounded Model
    Weber, Charles
    Fayed, Asser
    PROCEEDINGS OF PICMET 09 - TECHNOLOGY MANAGEMENT IN THE AGE OF FUNDAMENTAL CHANGE, VOLS 1-5, 2009, : 3141 - 3160
  • [27] An Empirically Grounded Search for a Typology of Project Management Offices
    Hobbs, Brian
    Aubry, Monique
    PROJECT MANAGEMENT JOURNAL, 2008, 39 : S69 - S82
  • [28] A reference-model for holonic Supply Chain management
    Peters, R
    Többen, H
    HOLONIC AND MULTI-AGENT SYSTEMS FOR MANUFACTURING, PROCEEDINGS, 2005, 3593 : 221 - 232
  • [29] A Reference Matrix for Information System in Supply Chain Management
    Scavarda, Luiz Felipe
    de Carvalho, Alessandro B.
    Vieira, Marcio da S.
    BRAZILIAN JOURNAL OF OPERATIONS & PRODUCTION MANAGEMENT, 2006, 3 (01): : 21 - 48
  • [30] Experiences with the use of supply chain management software in education
    Campbell, A
    Goentzel, J
    Savelsbergh, M
    PRODUCTION AND OPERATIONS MANAGEMENT, 2000, 9 (01) : 66 - 80