Page 120 - 《软件学报》2026年第7期
P. 120

胡帅 等: 产业研发视角下的开源软件供应链攻击问题研究                                                     2805


                      Workshop on Security and Cognitive Informatics for Homeland Defense. Fribourg: Springer, 2014. 79–93. [doi: 10.1007/978-3-319-
                      10975-6_6]
                 [171]   Ansari  TJ,  Pandey  D,  Alenezi  M.  STORE:  Security  threat  oriented  requirements  engineering  methodology.  Journal  of  King  Saud
                      University—Computer and Information Sciences, 2022, 34(2): 191–203. [doi: 10.1016/j.jksuci.2018.12.005]
                 [172]   Han S, Kim M, Kang J, Kim K, Lee S, Lee S. Similarity-based source code vulnerability detection leveraging Transformer architecture:
                      Harnessing cross-attention for hierarchical analysis. IEEE Access, 2024, 12: 150295–150307. [doi: 10.1109/ACCESS.2024.3474857]
                 [173]   Barr-Smith F, Blazytko T, Baker R, Martinovic I. Exorcist: Automated differential analysis to detect compromises in closed-source
                      software supply chains. In: Proc. of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses.
                      Los Angeles; ACM, 2022. 1–11. [doi: 10.1145/3560835.3564550]
                 [174]   Greco C, Ianni M, Guzzo A, Fortino G. Enabling obfuscation detection in binary software through explainable AI. IEEE Trans. on
                      Emerging Topics in Computing, 2024, 12(4): 1121–1132. [doi: 10.1109/TETC.2024.3439884]
                 [175]   Jiang L, An JW, Huang HH, Tang QY, Nie S, Wu S, Zhang YQ. BinaryAI: Binary software composition analysis via intelligent binary
                      source code matching. In: Proc. of the 46th IEEE/ACM Int’l Conf. on Software Engineering. Lisbon: ACM, 2024. 224. [doi: 10.1145/
                      3597503.3639100]
                 [176]   Vu DL, Massacci F, Pashchenko I, Plate H, Sabetta A. LastPyMile: Identifying the discrepancy between sources and packages. In: Proc.
                      of the 29th ACM Joint European Software Engineering Conf. and Symp. on the Foundations of Software Engineering. Athens: ACM,
                      2021. 780–792. [doi: 10.1145/3468264.3468592]
                 [177]   Brady K, Moon S, Nguyen T, Coffman J. Docker container security in cloud computing. In: Proc. of the 10th Annual Computing and
                      Communication Workshop and Conf. Las Vegas: IEEE, 2020. 975–980. [doi: 10.1109/CCWC47524.2020.9031195]
                 [178]   Rangnau T, Buijtenen R, Fransen F, Turkmen F. Continuous security testing: A case study on integrating dynamic security testing tools
                      in CI/CD pipelines. In: Proc. of the 24th IEEE Int’l Enterprise Distributed Object Computing Conf. Eindhoven: IEEE, 2020. 145–154.
                      [doi: 10.1109/EDOC49727.2020.00026]
                 [179]   Bass L, Holz R, Rimba P, Tran AB, Zhu LM. Securing a deployment pipeline. In: Proc. of the 3rd IEEE/ACM Int’l Workshop on
                      Release Engineering. Florence: IEEE, 2015. 4–7. [doi: 10.1109/RELENG.2015.11]
                 [180]   War A, Diallo A, Habib A, Klein J, Bissyandé TF. Vulnerabilities in infrastructure as code: What, how many, and who? Empirical
                      Software Engineering, 2025, 30(5): 120. [doi: 10.1007/s10664-025-10672-8]
                 [181]   Zeini  A,  Lennon  RG,  Lennon  P.  Securing  infrastructure  as  code  (IaC)  through  DevSecOps:  A  comprehensive  risk  management
                      framework. In: Proc. of the 2023 Cyber Research Conf. Ireland. Letterkenny: IEEE, 2023. 1–11. [doi: 10.1109/Cyber-RCI59474.2023.
                      10671452]
                 [182]   OWASP Foundation. Infrastructure as code security cheatsheet. 2024. https://cheatsheetseries.owasp.org/cheatsheets/Infrastructure_as_
                      Code_Security_Cheat_Sheet.html
                 [183]   Vadalasetty SR. Security concerns in using open source software for enterprise requirements. 2003. https://www.sans.org/white-papers/
                      1305
                 [184]   Edison H, Carroll N, Morgan L, Conboy K. Inner source software development: Current thinking and an agenda for future research.
                      Journal of Systems and Software, 2020, 163: 110520. [doi: 10.1016/j.jss.2020.110520]
                 [185]   Neil  L,  Mittal  S,  Joshi  A.  Mining  threat  intelligence  about  open-source  projects  and  libraries  from  code  repository  issues  and  bug
                      reports. In: Proc. of the 2018 IEEE Int’l Conf. on Intelligence and Security Informatics. Miami: IEEE, 2018. 7–14. [doi: 10.1109/ISI.
                      2018.8587375]
                 [186]   Wang LM, Wu JZ, Wu YJ, Rui ZQ, Luo TY, Qu S, Yang MT. Intelligent perception for vulnerability threats in open-source software
                      supply chain. Ruan Jian Xue Bao/Journal of Software, 2025, 36(2): 511–536 (in Chinese with English abstract). http://www.jos.org.cn/
                      1000-9825/7163.htm [doi: 10.13328/j.cnki.jos.007163]
                 [187]   GitHub Resources. What is runtime application self-protection (RASP)? 2024. https://github.com/resources/articles/what-is-rasp
                 [188]   Wu B, Zou F, Huang M, et al. Enhancing runtime application self-protection with unsupervised deep learning. In: Proc. of the 2026 Int’l
                      Conf. on Security and Privacy in Communication Systems. Cham: Springer, 2026. [doi: 10.1007/978-3-031-94445-1_11]
                 [189]   Baidu. Openrasp. 2025. https://github.com/baidu/openrasp
                 [190]   He  CG,  Ding  CHQ.  SecRASP:  Next  generation  Web  application  security  protection  methodology  and  framework.  Computers  &
                      Security, 2025, 154: 104445. [doi: 10.1016/j.cose.2025.104445]
                 [191]   Ohm M, Sykosch A, Meier M. Towards detection of software supply chain attacks by forensic artifacts. In: Proc. of the 15th Int’l Conf.
                      on Availability, Reliability and Security. ACM, 2020. 65. [doi: 10.1145/3407023.3409183]
                 [192]   Wang XY. On the feasibility of detecting software supply chain attacks. In: Proc. of the 2021 IEEE Military Communications Conf. San
   115   116   117   118   119   120   121   122   123   124   125