An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management

被引:0
|
作者
Nguyen Khoi Tran [1 ]
Pallewatta, Samodha [1 ]
Babar, M. Ali [2 ]
机构
[1] Univ Adelaide, Adelaide, SA, Australia
[2] Univ Adelaide, CREST, Cyber Secur Cooperat Res Ctr, Adelaide, SA, Australia
来源
PROCEEDINGS OF 2024 28TH INTERNATION CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, EASE 2024 | 2024年
关键词
Software Supply Chain; SSC Metadata; SBOM; Software Provenance; Reference Architecture; Systematisation of Knowledge; Empirically Grounded;
D O I
10.1145/3661167.3661212
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
With the rapid rise in Software Supply Chain (SSC) attacks, organisations need thorough and trustworthy visibility over the entire SSC of their software inventory to detect risks early and identify compromised assets rapidly in the event of an SSC attack. One way to achieve such visibility is through SSC metadata, machine-readable and authenticated documents describing an artefact's lifecycle. Adopting SSC metadata requires organisations to procure or develop a Software Supply Chain Metadata Management system (SCM2), a suite of software tools for performing life cycle activities of SSC metadata documents such as creation, signing, distribution, and consumption. Selecting or developing an SCM2 is challenging due to the lack of a comprehensive domain model and architectural blueprint to aid practitioners in navigating the vast design space of SSC metadata terminologies, frameworks, and solutions. This paper addresses the above-mentioned challenge by presenting an empirically grounded Reference Architecture (RA) comprising of a domain model and an architectural blueprint for SCM2 systems. Our proposed RA is constructed systematically on an empirical foundation built with industry-driven and peer-reviewed SSC security frameworks. Our theoretical evaluation, which consists of an architectural mapping of five prominent SSC security tools on the RA, ensures its validity and applicability, thus affirming the proposed RA as an effective framework for analysing existing SCM2 solutions and guiding the engineering of new SCM2 systems.
引用
收藏
页码:38 / 47
页数:10
相关论文
共 50 条
  • [31] Towards An Analysis of Software Supply Chain Risk Management
    Du, Shixian
    Lu, Tianbo
    Zhao, Lingling
    Xu, Bing
    Guo, Xiaobo
    Yang, Hongyu
    WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, WCECS 2013, VOL I, 2013, I : 162 - +
  • [32] Achieving success in supply chain management software by agility
    Mishra, Deepti
    Mishra, Alok
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROCEEDINGS, 2007, 4589 : 237 - +
  • [33] Supply Chain Risk Management Using Software Tool
    Marija, Matotek
    Ivan, Barac
    Dusan, Regodic
    Gojko, Grubor
    ACTA POLYTECHNICA HUNGARICA, 2015, 12 (04) : 167 - 182
  • [34] A Semantic Web Service Architecture for Supply Chain Management
    Pal, Kamalendu
    8TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT-2017) AND THE 7TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT 2017), 2017, 109 : 999 - 1004
  • [35] High Level Architecture education in Supply Chain Management
    Bruzzone, AG
    Revetria, R
    Briano, C
    6TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL XII, PROCEEDINGS: INDUSTRIAL SYSTEMS AND ENGINEERING II, 2002, : 352 - 356
  • [36] An Integrated Forecasting DSS Architecture in Supply Chain Management
    Wang, Tien-You
    Yeh, Din-Horng
    OPERATIONS AND SUPPLY CHAIN MANAGEMENT-AN INTERNATIONAL JOURNAL, 2009, 2 (01): : 24 - 41
  • [37] A Secure Architecture for IoT with Supply Chain Risk Management
    Hiromoto, Robert E.
    Haney, Michael
    Vakanski, Aleksandar
    PROCEEDINGS OF THE 2017 9TH IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS), VOL 1, 2017, : 431 - 435
  • [38] Metadata analysis of knowledge management in supply chain Investigating the past and predicting the future
    Bhosale, Vishal Ashok
    Kant, Ravi
    BUSINESS PROCESS MANAGEMENT JOURNAL, 2016, 22 (01) : 140 - 172
  • [39] An empirically-grounded study on the effective use of social software in education
    Minocha, Shailey
    EDUCATION AND TRAINING, 2009, 51 (5-6): : 381 - 394
  • [40] The Research of Global Food Supply Chain Management - The USA Supply Chain Operation and the Reference to China
    Sun, Bo
    Zeng, Zijing
    2014 2ND INTERNATIONAL CONFERENCE ON PSYCHOLOGY, MANAGEMENT AND SOCIAL SCIENCE (PMSS 2014), PT 1, 2014, 49 : 63 - 68