Journal of Information Security Reserach ›› 2024, Vol. 10 ›› Issue (9): 862-.

Previous Articles     Next Articles

Research on Risk Analysis of Opensource Software Supply Chain Security

Wang Jiang, Jiang Wei, and Zhang Can   

  1. (Chinese Academy of Cyberspace Studies, Beijing 100048)
  • Online:2024-09-25 Published:2024-09-29

开源软件供应链安全风险分析研究

王江姜伟张璨   

  1. (中国网络空间研究院北京100048)
  • 通讯作者: 姜伟 博士,研究员.主要研究方向为网络安全、数据安全、网络治理. jiangwei@cac.gov.cn
  • 作者简介:王江 硕士,高级工程师.主要研究方向为网络安全、信息化、数据治理. wangjiang@cac.gov.cn 姜伟 博士,研究员.主要研究方向为网络安全、数据安全、网络治理. jiangwei@cac.gov.cn 张璨 博士,助理研究员.主要研究方向为网络与信息安全、区块链隐私保护. zhangcan@cac.gov.cn

Abstract: Opensource software has become one of the most fundamental elements that support the operation of the digital society. It has also been penetrated to various industries and fields. As the opensource software supply chain becomes increasingly complex and diversified, the risks caused by security attacks on the opensource software supply chain are also intensified. This paper summarizes the current development of the opensource software supply chain ecosystem and the strategic layout of opensource software supply chain security in major countries. From the dimensions of development security, usage security, and operation security, this paper proposes an opensource software supply chain security risk analysis system. It identifies the major security risks currently faced by the opensource software supply chain. Besides, this paper constructs a security assurance model for the opensource software supply chain and offers countermeasures and suggestions for the security and development of China’s opensource software supply chain from the dimensions of supply chain phases, relevant entities, and safeguard measures.

Key words: network security, software security, opensource software, software supply chain, opensource software supply chain security

摘要: 开源软件已经成为支撑数字社会正常运转的最基本元素之一,渗透到各个行业和领域.随着开源软件供应链越发复杂多元,开源软件供应链安全攻击事件造成的危害也越发严重.梳理了开源软件供应链生态发展现状和世界主要国家开源软件供应链安全战略布局,从开源软件开发安全、使用安全和运营安全维度,提出了开源软件供应链安全风险分析体系,给出当前开源软件供应链面临的主要安全风险,构建了开源软件供应链安全保障模型,并从供应链环节、相关主体和保障措施3个维度提出我国开源软件供应链安全与发展对策建议.

关键词: 网络安全, 软件安全, 开源软件, 软件供应链, 开源软件供应链安全

CLC Number: