论文标题
什么是软件供应链安全?
What is Software Supply Chain Security?
论文作者
论文摘要
软件供应链涉及多种工具和流程,使软件开发人员能够编写,构建和运送应用程序。最近,对工具或流程的安全妥协导致了解决这些问题的提案的激增。但是,这些建议通常过于强调特定的解决方案或将目标混为一谈,从而导致意外后果或不清楚的定位和使用。 在本文中,我们表明,直到社区对安全问题有整体看法,就不可能开发实用解决方案。这种观点必须包括技术和程序方面。为此,我们检查了三种用例以确定共同的安全目标,并提出了现有解决方案的面向目标的分类法,以证明软件供应链安全的整体概述。
The software supply chain involves a multitude of tools and processes that enable software developers to write, build, and ship applications. Recently, security compromises of tools or processes has led to a surge in proposals to address these issues. However, these proposals commonly overemphasize specific solutions or conflate goals, resulting in unexpected consequences, or unclear positioning and usage. In this paper, we make the case that developing practical solutions is not possible until the community has a holistic view of the security problem; this view must include both the technical and procedural aspects. To this end, we examine three use cases to identify common security goals, and present a goal-oriented taxonomy of existing solutions demonstrating a holistic overview of software supply chain security.