computer security

The Distributed Open-Source Vulnerability Ecosystem

arXiv:2607.14900

summary

The paper proposes a conceptual framework for understanding how vulnerability information is created, standardized, enriched, and interpreted across the open‑source ecosystem, explaining why different scanners often report inconsistent results.

Abstract

Identifying known software vulnerabilities is a central task in software supply chain security management. Although publicly available vulnerability information is based on shared standards, different vulnerability scanners often report divergent results for identical software inventories. These differences do not arise solely from individual data sources or scanner implementations. They can emerge at several stages of the open-source vulnerability ecosystem. This paper presents a conceptual framework that describes vulnerability management as a distributed process of information exchange and transformation. It traces vulnerability information from its creation and standardization through enrichment to context-dependent interpretation. The analysis identifies heterogeneous information sources, divergent identity and version models, temporal change, and context-dependent assessment as major causes of inconsistent scanner findings. It then discusses the implications for interpreting analysis results, designing reproducible evaluation methods, and handling dynamic vulnerability knowledge in practice.

15 pages, 4 figures, 2 tables

Topics & keywords

The Distributed Open-Source Vulnerability Ecosystem · wovepaper