Page 113 - 《软件学报》2026年第7期
P. 113
2798 软件学报 2026 年第 37 卷第 7 期
[8] Synopsys. 2024 open source security and risk analysis report. Synopsys, 2024 (in Chinese). https://www.blackduck.com/content/dam/
black-duck/zh-cn/reports/rep-ossra-2024-ch.pdf
[9] Chen LQ, Li NH, Liang KT, Schneider S. Computer Security—ESORICS 2020. Cham: Springer, 2020. [doi: 10.1007/978-3-030-59013-0]
[10] Meng YX, Long YT, Wang W, Sun Q, Jing Q, Tan ZY, Tang XY, Ju DY. 2024 China open source development Status. COPU, 2024 (in
Chinese). https://copu-oss.org.cn/download/showdownload.php?id=32
[11] Setitra MA, Fan MY, Benkhaddra I, Bensalem ZEA. DoS/DDoS attacks in software defined networks: Current situation, challenges and
future directions. Computer Communications, 2024, 222: 77–96. [doi: 10.1016/j.comcom.2024.04.035]
[12] Ladisa P, Plate H, Martinez M, Barais O. SoK: Taxonomy of attacks on open-source software supply chains. In: Proc. of the 2023 IEEE
Symp. on Security and Privacy. San Francisco: IEEE, 2023. 1509–1526. [doi: 10.1109/SP46215.2023.10179304]
[13] Betul G, Leonardo A, Basel H. Software supply chain: A taxonomy of attacks, mitigations and risk assessment strategies. Journal of
Information Security and Applications, 2026, 97: 104324. [doi: 10.1016/j.jisa.2025.104324]
[14] Ladisa P, Ponta SE, Sabetta A, Martinez M, Barais O. Journey to the center of software supply chain attacks. IEEE Security & Privacy,
2023, 21(6): 34–49. [doi: 10.1109/MSEC.2023.3302066]
[15] Siadati H, Jafarikhah S, Sahin E, Hernandez TB, Tripp E, Khryashchev D, Kharraz A. Devphish: Exploring social engineering in
software supply chain attacks on developers. In: Proc. of the 15th IEEE Annual Ubiquitous Computing, Electronics & Mobile
Communication Conf. Yorktown Heights: IEEE, 2024. 517–523. [doi: 10.1109/UEMCON62879.2024.10754708]
[16] Kshetri N. Economics of supply chain cyberattacks. IT Professional, 2022, 24(3): 96–100. [doi: 10.1109/mitp.2022.3172877]
[17] Levy E. Poisoning the software supply chain. IEEE Security & Privacy, 2003, 1(3): 70–73. [doi: 10.1109/MSECP.2003.1203227]
[18] Alami A, Pardo R, Cohn ML, Wąsowski A. Pull request governance in open source communities. IEEE Trans. on Software Engineering,
2022, 48(12): 4838–4856. [doi: 10.1109/TSE.2021.3128356]
[19] ReversingLabs. The state of software supply chain security 2024. 2024. https://www.reversinglabs.com/sscs-report-2024
[20] Imtiaz N, Thorn S, Williams L. A comparative study of vulnerability reporting by software composition analysis tools. In: Proc. of the
15th ACM/IEEE Int’l Symp. on Empirical Software Engineering and Measurement. Bari: ACM, 2021. 5. [doi: 10.1145/3475716.
3475769]
[21] Yang BY, Cai ZJ, Liu FL, Le B, Zhang LM, Bissyandé TF, Liu Y, Tian HY. A survey of LLM-based automated program repair:
Taxonomies, design paradigms, and applications. arXiv:2506.23749, 2025.
[22] Li Y, Shezan FH, Wei BM, Wang G, Tian Y. SoK: Towards effective automated vulnerability repair. In: Proc. of the 34th USENIX
Security Symp. Seattle: USENIX Association, 2025. 4441–4462.
[23] Wang LM, Bu L, Ma LZ, Yu XF, Shen NG. Attack detection method based on indicator dependence model construction and monitoring.
Ruan Jian Xue Bao/Journal of Software, 2023, 34(6): 2641–2668 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/
6847.htm [doi: 10.13328/j.cnki.jos.006847]
[24] Zhan Q, Pan SY, Hu X, Bao LF, Xia X. Survey on vulnerability awareness of open source software. Ruan Jian Xue Bao/Journal of
Software, 2024, 35(1): 19–37 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/6935.htm [doi: 10.13328/j.cnki.jos.
006935]
[25] Wang Y, Wu YX, Gao T, Chen ZY, Xu C, Yu H, Zhang CZ. Survey on governance technology of open-source software library
ecosystem: Twenty years of progress. Ruan Jian Xue Bao/Journal of Software, 2024, 35(2): 629–674 (in Chinese with English abstract).
http://www.jos.org.cn/1000-9825/6983.htm [doi: 10.13328/j.cnki.jos.006983]
[26] Wen XC, Gao CY, Ye JX, Li YC, Tian ZH, Jia Y, Wang X. Meta-path based attentional graph learning model for vulnerability
detection. IEEE Trans. on Software Engineering, 2024, 50(3): 360–375. [doi: 10.1109/TSE.2023.3340267]
[27] Zhang CY, Liu B, Xin Y, Yao LW. CPVD: Cross project vulnerability detection based on graph attention network and domain
adaptation. IEEE Trans. on Software Engineering, 2023, 49(8): 4152–4168. [doi: 10.1109/TSE.2023.3285910]
[28] Zhang WX, Kong XR, Dewitt C, Braunl T, Hong JB. A study on prompt injection attack against LLM-integrated mobile robotic
systems. In: Proc. of the 35th IEEE Int’l Symp. on Software Reliability Engineering Workshops. Tsukuba: IEEE, 2024. 361–368.
[doi: 10.1109/ISSREW63542.2024.00103]
[29] Pasini S, Kim J, Aiello T, Lozoya RC, Sabetta A, Tonella P. Evaluating and improving the robustness of security attack detectors
generated by LLMs. arXiv:2411.18216, 2024.
[30] Bandara E, Shetty S, Mukkamala R, Rahman A, Foytik P, Liang XP, de Zoysa K, Keong NW. DevSec-GPT—Generative-AI (with
custom-trained meta’s Llama2 LLM), blockchain, NFT and PBOM enabled cloud native container vulnerability management and
pipeline verification platform. In: Proc. of the 2024 IEEE Cloud Summit. Washington: IEEE, 2024. 28–35. [doi: 10.1109/Cloud-
Summit61220.2024.00012]

