EconPapers    
Economics at your fingertips  
 

Construction of Software Supply Chain Threat Portrait Based on Chain Perspective

Maoyang Wang, Peng Wu () and Qin Luo
Additional contact information
Maoyang Wang: School of Computer Science, Southwest Petroleum University, Chengdu 610500, China
Peng Wu: School of Information and Engineering, Sichuan Tourism University, Chengdu 610100, China
Qin Luo: School of Computer Science, Southwest Petroleum University, Chengdu 610500, China

Mathematics, 2023, vol. 11, issue 23, 1-26

Abstract: With the rapid growth of the software industry, the software supply chain (SSC) has become the most intricate system in the complete software life cycle, and the security threat situation is becoming increasingly severe. For the description of the SSC, the relevant research mainly focuses on the perspective of developers, lacking a comprehensive understanding of the SSC. This paper proposes a chain portrait framework of the SSC based on a resource perspective, which comprehensively depicts the threat model and threat surface indicator system of the SSC. The portrait model includes an SSC threat model and an SSC threat indicator matrix. The threat model has 3 levels and 32 dimensions and is based on a generative artificial intelligence model. The threat indicator matrix is constructed using the Attack Net model comprising 14-dimensional attack strategies and 113-dimensional attack techniques. The proposed portrait model’s effectiveness is verified through existing SSC security events, domain experts, and event visualization based on security analysis models.

Keywords: software supply chain; software supply chain threat model; attack technique matrix; software supply chain portrait (search for similar items in EconPapers)
JEL-codes: C (search for similar items in EconPapers)
Date: 2023
References: View complete reference list from CitEc
Citations:

Downloads: (external link)
https://www.mdpi.com/2227-7390/11/23/4856/pdf (application/pdf)
https://www.mdpi.com/2227-7390/11/23/4856/ (text/html)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:gam:jmathe:v:11:y:2023:i:23:p:4856-:d:1292981

Access Statistics for this article

Mathematics is currently edited by Ms. Emma He

More articles in Mathematics from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().

 
Page updated 2025-03-19
Handle: RePEc:gam:jmathe:v:11:y:2023:i:23:p:4856-:d:1292981