Research on Open-source Software Supply Chain Attacks from Industrial R&D Perspective
Author:
Affiliation:

Clc Number:

TP311

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Open-source software is deeply embedded in enterprise product research, development, and delivery processes, shortening development cycles, reducing costs, and enhancing system compatibility. Meanwhile, attacks targeting the open-source software supply chain continue to increase and have become one of the most critical security threats to the software industry. From an industrial research and development (R&D) perspective, this study analyzes the inherent tension between R&D efficiency and software security and identifies an implicit consensus in industrial practice: under efficiency constraints imposed by process compliance, organizations tend to respond passively to open-source software supply chain security threats. Through representative real-world cases, it is demonstrated that security systems primarily driven by process compliance are insufficient to address open-source software supply chain attacks. From an industrial perspective, this study further proposes an evolutionary classification framework of open-source software supply chain attacks, in which attacks are categorized into three stages: threat emergence during open-source co-development, threat evolution during closed-source industrial R&D, and attack manifestation during product deployment and usage. For each stage, typical attack patterns and technical mechanisms are systematically summarized. Based on this analysis, a security rebalancing framework for the open-source software supply chain is proposed from three complementary dimensions: collaborative governance oriented toward the open-source ecosystem, continuous compliance, and attack-surface reduction oriented toward industrial R&D processes, and adaptive protection mechanisms oriented toward deployed products.

    Reference
    Related
    Cited by
Get Citation

胡帅,王海军,谢继刚,裴鹏飞,阿西伍合,马辰达,刘烃.产业研发视角下的开源软件供应链攻击问题研究.软件学报,2026,37(7):2766-2807

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:September 08,2025
  • Revised:October 20,2025
  • Adopted:
  • Online: December 26,2025
  • Published: July 06,2026
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-4
Address:4# South Fourth Street, Zhong Guan Cun, Beijing 100190,Postal Code:100190
Phone:010-62562563 Fax:010-62562533 Email:jos@iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063