Journal of Information Security Reserach ›› 2026, Vol. 12 ›› Issue (7): 586-597.

   

Survey of Software Supply Chain Security Detection and Assessment Technologies

Hu Bin, Huang Chuanlin, Wu Tiejun, Liu Wenzhong, Xu Zhen, and Zheng Kaifa   

  • Published:2026-07-24

软件供应链安全检测评估技术综述

胡斌, 黄传林, 吴铁军, 郑开发, 刘文忠, 刘志全, 周迪   

Abstract: In the context of the digital era, software supply chain has become a critical component supporting the stable and healthy development of the digital economy. It is an indispensable part of the nation’s key information infrastructure and economic and social systems. The security of software supply chain directly determines the security of the key businesses carried by the software supply chain. Therefore, based on the development needs of the digital age, this article summarizes the current technologies, methods, and development trends related to software supply chain security detection and evaluation, providing reference and guidance for industry insiders, researchers, and decisionmakers. It includes a review and detailed explanation of the background and methods of software supply chain security detection and evaluation technology, detailing the principles of mainstream technologies such as component analysis, vulnerability scanning, code review, runtime monitoring, threat modeling, and fuzz testing, and comparing and analyzing the advantages and disadvantages of various technologies; Analyze the current technical challenges and countermeasures faced by technology; And propose ten major trends for the development of this field in the next decade, in order to improve the security level of the software supply chain and promote the development of the software industry.

Key words: software supply chain security; component analysis; vulnerability assessment; code audit; threat modeling; fuzzy testing

摘要: 数字化浪潮下,软件供应链安全成为支撑数字经济安全稳定发展的必要环节.系统综述软件供应链安全检测评估技术体系,从软件成分分析(software component analysis, SCA)、软件物料清单(software bill of material, SBOM)、依赖关系追溯等核心技术出发,针对软件检测和评价中关键的技术——组件分析、漏洞扫描、代码审查等,分析当前面临的问题与解决思路,再通过国内外最新的研究成果和应用案例进行对比论述,结合兴业证券SCA治理平台、中国电信SBOM管理平台等典型实践,并就SLSA框架、GitHub依赖图谱等新兴前沿技术发展状况进行分析.在此基础上针对该领域的技术发展现状及产业需要展望技术融合与协同、智能化与自动化、全生命周期覆盖等未来10年发展10大趋势.

关键词: 软件供应链安全;软件成分分析;软件物料清单;依赖图谱;漏洞检测;安全评估

CLC Number: