产业研发视角下的开源软件供应链攻击问题研究
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP311

基金项目:

国家自然科学基金 (62232014, 62372367); 陕西省重点研发计划 (2024GX-ZDCYL-02-19); 陕西省高层次科技人才项目 (QCYRCXM-2022-345)


Research on Open-source Software Supply Chain Attacks from Industrial R&D Perspective
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    开源软件深度嵌入企业的产品研发与交付流程, 缩短了研发周期、降低了研发成本并增强了系统兼容性; 与此同时, 针对开源软件供应链的攻击事件也呈现上升态势, 已成为软件行业最重大的安全威胁之一. 从产业研发视角分析研发效率与软件安全的内生矛盾, 发现产业组织以流程合规作为效率约束下, 被动应对开源软件供应链安全威胁的隐性共识. 结合实际案例论证了基于流程合规的安全体系无法应对开源软件供应链攻击; 基于产业视角提出了开源软件供应链攻击分类演化框架, 将开源软件供应链攻击分为3个阶段: 开源共建威胁产生、闭源研发威胁演化、成品使用攻击发作, 对不同阶段的攻击模式、技术手段等进行总结; 从面向开源生态的协同治理、面向产业研发的持续合规与攻击面收敛、面向成品使用的自适应防护这3个方面, 提出开源软件供应链的安全再平衡体系.

    Abstract:

    Open-source software is deeply embedded in enterprise product research, development, and delivery processes, shortening development cycles, reducing costs, and enhancing system compatibility. Meanwhile, attacks targeting the open-source software supply chain continue to increase and have become one of the most critical security threats to the software industry. From an industrial research and development (R&D) perspective, this study analyzes the inherent tension between R&D efficiency and software security and identifies an implicit consensus in industrial practice: under efficiency constraints imposed by process compliance, organizations tend to respond passively to open-source software supply chain security threats. Through representative real-world cases, it is demonstrated that security systems primarily driven by process compliance are insufficient to address open-source software supply chain attacks. From an industrial perspective, this study further proposes an evolutionary classification framework of open-source software supply chain attacks, in which attacks are categorized into three stages: threat emergence during open-source co-development, threat evolution during closed-source industrial R&D, and attack manifestation during product deployment and usage. For each stage, typical attack patterns and technical mechanisms are systematically summarized. Based on this analysis, a security rebalancing framework for the open-source software supply chain is proposed from three complementary dimensions: collaborative governance oriented toward the open-source ecosystem, continuous compliance, and attack-surface reduction oriented toward industrial R&D processes, and adaptive protection mechanisms oriented toward deployed products.

    参考文献
    相似文献
    引证文献
引用本文

胡帅,王海军,谢继刚,裴鹏飞,阿西伍合,马辰达,刘烃.产业研发视角下的开源软件供应链攻击问题研究.软件学报,2026,37(7):2766-2807

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-09-08
  • 最后修改日期:2025-10-20
  • 录用日期:
  • 在线发布日期: 2025-12-26
  • 出版日期: 2026-07-06
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号