Propagation Model for SSC attacks: Why SBOM (tools) don't tell the whole truth
arXiv:2609.05380 · doi:10.1007/978-3-032-35579-9_30
Abstract
Ensuring security of software supply chains (SSC) is indispensable in today's world of modern software practices. SBOM (tools) have been introduced as relevant building blocks to ensure the transparency of SSCs. However they have serious limitations in practices as their vulnerability detection and interpretation capacity is not sufficient to explain exploitability effects that can propagte through the whole chain. To address this gap, we propose a propagation-centred approach to SSC security and introduce a four-stage propagation model. We empirically evaluate four open-source SBOM tools against each stage using three projects and Log4j vulnerability as our test case. Our results show that current SBOM tools systematically support only Stage 1 (Structural Exposure) and Stage 2 (Vulnerability Class Presence) while Stage 3 (Code Reachability) and Stage 4 (Taint Path Analysis) require capabilities absent from the SBOM ecosystem. We argue that putting propagation effects at the centre of SSC security research is essential to prevent cyber risk evolving into systemic risks. Our research findings contribute to a future research and design of modern SSC security tools.
References in corpus (10)
- Challenges of Producing Software Bill Of Materials for Java
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road Ahead
- Supply Chain Insecurity: The Lack of Integrity Protection in SBOM Solutions
- Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment
- A Longitudinal Measurement Study of Log4Shell Exploitation from a Reactive Network Telescope
- Network Security under Heterogeneous Cyber-Risk Profiles and Contagion
- Hidden Dependencies and Component Variants in SBOM-Based Software Composition Analysis
- Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
- Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
- VDGraph: A Graph-Theoretic Approach to Unlock Insights from SBOM and SCA Data