Page 113 - 《软件学报》2026年第7期
P. 113

2798                                                       软件学报  2026  年第  37  卷第  7  期


                  [8]   Synopsys. 2024 open source security and risk analysis report. Synopsys, 2024 (in Chinese). https://www.blackduck.com/content/dam/
                      black-duck/zh-cn/reports/rep-ossra-2024-ch.pdf
                  [9]   Chen LQ, Li NH, Liang KT, Schneider S. Computer Security—ESORICS 2020. Cham: Springer, 2020. [doi: 10.1007/978-3-030-59013-0]
                 [10]   Meng YX, Long YT, Wang W, Sun Q, Jing Q, Tan ZY, Tang XY, Ju DY. 2024 China open source development Status. COPU, 2024 (in
                      Chinese). https://copu-oss.org.cn/download/showdownload.php?id=32
                 [11]   Setitra MA, Fan MY, Benkhaddra I, Bensalem ZEA. DoS/DDoS attacks in software defined networks: Current situation, challenges and
                      future directions. Computer Communications, 2024, 222: 77–96. [doi: 10.1016/j.comcom.2024.04.035]
                 [12]   Ladisa P, Plate H, Martinez M, Barais O. SoK: Taxonomy of attacks on open-source software supply chains. In: Proc. of the 2023 IEEE
                      Symp. on Security and Privacy. San Francisco: IEEE, 2023. 1509–1526. [doi: 10.1109/SP46215.2023.10179304]
                 [13]   Betul G, Leonardo A, Basel H. Software supply chain: A taxonomy of attacks, mitigations and risk assessment strategies. Journal of
                      Information Security and Applications, 2026, 97: 104324. [doi: 10.1016/j.jisa.2025.104324]
                 [14]   Ladisa P, Ponta SE, Sabetta A, Martinez M, Barais O. Journey to the center of software supply chain attacks. IEEE Security & Privacy,
                      2023, 21(6): 34–49. [doi: 10.1109/MSEC.2023.3302066]
                 [15]   Siadati  H,  Jafarikhah  S,  Sahin  E,  Hernandez  TB,  Tripp  E,  Khryashchev  D,  Kharraz  A.  Devphish:  Exploring  social  engineering  in
                      software  supply  chain  attacks  on  developers.  In:  Proc.  of  the  15th  IEEE  Annual  Ubiquitous  Computing,  Electronics  &  Mobile
                      Communication Conf. Yorktown Heights: IEEE, 2024. 517–523. [doi: 10.1109/UEMCON62879.2024.10754708]
                 [16]   Kshetri N. Economics of supply chain cyberattacks. IT Professional, 2022, 24(3): 96–100. [doi: 10.1109/mitp.2022.3172877]
                 [17]   Levy E. Poisoning the software supply chain. IEEE Security & Privacy, 2003, 1(3): 70–73. [doi: 10.1109/MSECP.2003.1203227]
                 [18]   Alami A, Pardo R, Cohn ML, Wąsowski A. Pull request governance in open source communities. IEEE Trans. on Software Engineering,
                      2022, 48(12): 4838–4856. [doi: 10.1109/TSE.2021.3128356]
                 [19]   ReversingLabs. The state of software supply chain security 2024. 2024. https://www.reversinglabs.com/sscs-report-2024
                 [20]   Imtiaz N, Thorn S, Williams L. A comparative study of vulnerability reporting by software composition analysis tools. In: Proc. of the
                      15th  ACM/IEEE  Int’l  Symp.  on  Empirical  Software  Engineering  and  Measurement.  Bari:  ACM,  2021.  5.  [doi:  10.1145/3475716.
                      3475769]
                 [21]   Yang  BY,  Cai  ZJ,  Liu  FL,  Le  B,  Zhang  LM,  Bissyandé  TF,  Liu  Y,  Tian  HY.  A  survey  of  LLM-based  automated  program  repair:
                      Taxonomies, design paradigms, and applications. arXiv:2506.23749, 2025.
                 [22]   Li Y, Shezan FH, Wei BM, Wang G, Tian Y. SoK: Towards effective automated vulnerability repair. In: Proc. of the 34th USENIX
                      Security Symp. Seattle: USENIX Association, 2025. 4441–4462.
                 [23]   Wang LM, Bu L, Ma LZ, Yu XF, Shen NG. Attack detection method based on indicator dependence model construction and monitoring.
                      Ruan Jian Xue Bao/Journal of Software, 2023, 34(6): 2641–2668 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/
                      6847.htm [doi: 10.13328/j.cnki.jos.006847]
                 [24]   Zhan Q, Pan SY, Hu X, Bao LF, Xia X. Survey on vulnerability awareness of open source software. Ruan Jian Xue Bao/Journal of
                      Software, 2024, 35(1): 19–37 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/6935.htm [doi: 10.13328/j.cnki.jos.
                      006935]
                 [25]   Wang  Y,  Wu  YX,  Gao  T,  Chen  ZY,  Xu  C,  Yu  H,  Zhang  CZ.  Survey  on  governance  technology  of  open-source  software  library
                      ecosystem: Twenty years of progress. Ruan Jian Xue Bao/Journal of Software, 2024, 35(2): 629–674 (in Chinese with English abstract).
                      http://www.jos.org.cn/1000-9825/6983.htm [doi: 10.13328/j.cnki.jos.006983]
                 [26]   Wen  XC,  Gao  CY,  Ye  JX,  Li  YC,  Tian  ZH,  Jia  Y,  Wang  X.  Meta-path  based  attentional  graph  learning  model  for  vulnerability
                      detection. IEEE Trans. on Software Engineering, 2024, 50(3): 360–375. [doi: 10.1109/TSE.2023.3340267]
                 [27]   Zhang  CY,  Liu  B,  Xin  Y,  Yao  LW.  CPVD:  Cross  project  vulnerability  detection  based  on  graph  attention  network  and  domain
                      adaptation. IEEE Trans. on Software Engineering, 2023, 49(8): 4152–4168. [doi: 10.1109/TSE.2023.3285910]
                 [28]   Zhang  WX,  Kong  XR,  Dewitt  C,  Braunl  T,  Hong  JB.  A  study  on  prompt  injection  attack  against  LLM-integrated  mobile  robotic
                      systems.  In:  Proc.  of  the  35th  IEEE  Int’l  Symp.  on  Software  Reliability  Engineering  Workshops.  Tsukuba:  IEEE,  2024.  361–368.
                      [doi: 10.1109/ISSREW63542.2024.00103]
                 [29]   Pasini  S,  Kim  J,  Aiello  T,  Lozoya  RC,  Sabetta  A,  Tonella  P.  Evaluating  and  improving  the  robustness  of  security  attack  detectors
                      generated by LLMs. arXiv:2411.18216, 2024.
                 [30]   Bandara E, Shetty S, Mukkamala R, Rahman A, Foytik P, Liang XP, de Zoysa K, Keong NW. DevSec-GPT—Generative-AI (with
                      custom-trained  meta’s  Llama2  LLM),  blockchain,  NFT  and  PBOM  enabled  cloud  native  container  vulnerability  management  and
                      pipeline  verification  platform.  In:  Proc.  of  the  2024  IEEE  Cloud  Summit.  Washington:  IEEE,  2024.  28–35.  [doi: 10.1109/Cloud-
                      Summit61220.2024.00012]
   108   109   110   111   112   113   114   115   116   117   118