Page 120 - 《软件学报》2026年第7期
P. 120
胡帅 等: 产业研发视角下的开源软件供应链攻击问题研究 2805
Workshop on Security and Cognitive Informatics for Homeland Defense. Fribourg: Springer, 2014. 79–93. [doi: 10.1007/978-3-319-
10975-6_6]
[171] Ansari TJ, Pandey D, Alenezi M. STORE: Security threat oriented requirements engineering methodology. Journal of King Saud
University—Computer and Information Sciences, 2022, 34(2): 191–203. [doi: 10.1016/j.jksuci.2018.12.005]
[172] Han S, Kim M, Kang J, Kim K, Lee S, Lee S. Similarity-based source code vulnerability detection leveraging Transformer architecture:
Harnessing cross-attention for hierarchical analysis. IEEE Access, 2024, 12: 150295–150307. [doi: 10.1109/ACCESS.2024.3474857]
[173] Barr-Smith F, Blazytko T, Baker R, Martinovic I. Exorcist: Automated differential analysis to detect compromises in closed-source
software supply chains. In: Proc. of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses.
Los Angeles; ACM, 2022. 1–11. [doi: 10.1145/3560835.3564550]
[174] Greco C, Ianni M, Guzzo A, Fortino G. Enabling obfuscation detection in binary software through explainable AI. IEEE Trans. on
Emerging Topics in Computing, 2024, 12(4): 1121–1132. [doi: 10.1109/TETC.2024.3439884]
[175] Jiang L, An JW, Huang HH, Tang QY, Nie S, Wu S, Zhang YQ. BinaryAI: Binary software composition analysis via intelligent binary
source code matching. In: Proc. of the 46th IEEE/ACM Int’l Conf. on Software Engineering. Lisbon: ACM, 2024. 224. [doi: 10.1145/
3597503.3639100]
[176] Vu DL, Massacci F, Pashchenko I, Plate H, Sabetta A. LastPyMile: Identifying the discrepancy between sources and packages. In: Proc.
of the 29th ACM Joint European Software Engineering Conf. and Symp. on the Foundations of Software Engineering. Athens: ACM,
2021. 780–792. [doi: 10.1145/3468264.3468592]
[177] Brady K, Moon S, Nguyen T, Coffman J. Docker container security in cloud computing. In: Proc. of the 10th Annual Computing and
Communication Workshop and Conf. Las Vegas: IEEE, 2020. 975–980. [doi: 10.1109/CCWC47524.2020.9031195]
[178] Rangnau T, Buijtenen R, Fransen F, Turkmen F. Continuous security testing: A case study on integrating dynamic security testing tools
in CI/CD pipelines. In: Proc. of the 24th IEEE Int’l Enterprise Distributed Object Computing Conf. Eindhoven: IEEE, 2020. 145–154.
[doi: 10.1109/EDOC49727.2020.00026]
[179] Bass L, Holz R, Rimba P, Tran AB, Zhu LM. Securing a deployment pipeline. In: Proc. of the 3rd IEEE/ACM Int’l Workshop on
Release Engineering. Florence: IEEE, 2015. 4–7. [doi: 10.1109/RELENG.2015.11]
[180] War A, Diallo A, Habib A, Klein J, Bissyandé TF. Vulnerabilities in infrastructure as code: What, how many, and who? Empirical
Software Engineering, 2025, 30(5): 120. [doi: 10.1007/s10664-025-10672-8]
[181] Zeini A, Lennon RG, Lennon P. Securing infrastructure as code (IaC) through DevSecOps: A comprehensive risk management
framework. In: Proc. of the 2023 Cyber Research Conf. Ireland. Letterkenny: IEEE, 2023. 1–11. [doi: 10.1109/Cyber-RCI59474.2023.
10671452]
[182] OWASP Foundation. Infrastructure as code security cheatsheet. 2024. https://cheatsheetseries.owasp.org/cheatsheets/Infrastructure_as_
Code_Security_Cheat_Sheet.html
[183] Vadalasetty SR. Security concerns in using open source software for enterprise requirements. 2003. https://www.sans.org/white-papers/
1305
[184] Edison H, Carroll N, Morgan L, Conboy K. Inner source software development: Current thinking and an agenda for future research.
Journal of Systems and Software, 2020, 163: 110520. [doi: 10.1016/j.jss.2020.110520]
[185] Neil L, Mittal S, Joshi A. Mining threat intelligence about open-source projects and libraries from code repository issues and bug
reports. In: Proc. of the 2018 IEEE Int’l Conf. on Intelligence and Security Informatics. Miami: IEEE, 2018. 7–14. [doi: 10.1109/ISI.
2018.8587375]
[186] Wang LM, Wu JZ, Wu YJ, Rui ZQ, Luo TY, Qu S, Yang MT. Intelligent perception for vulnerability threats in open-source software
supply chain. Ruan Jian Xue Bao/Journal of Software, 2025, 36(2): 511–536 (in Chinese with English abstract). http://www.jos.org.cn/
1000-9825/7163.htm [doi: 10.13328/j.cnki.jos.007163]
[187] GitHub Resources. What is runtime application self-protection (RASP)? 2024. https://github.com/resources/articles/what-is-rasp
[188] Wu B, Zou F, Huang M, et al. Enhancing runtime application self-protection with unsupervised deep learning. In: Proc. of the 2026 Int’l
Conf. on Security and Privacy in Communication Systems. Cham: Springer, 2026. [doi: 10.1007/978-3-031-94445-1_11]
[189] Baidu. Openrasp. 2025. https://github.com/baidu/openrasp
[190] He CG, Ding CHQ. SecRASP: Next generation Web application security protection methodology and framework. Computers &
Security, 2025, 154: 104445. [doi: 10.1016/j.cose.2025.104445]
[191] Ohm M, Sykosch A, Meier M. Towards detection of software supply chain attacks by forensic artifacts. In: Proc. of the 15th Int’l Conf.
on Availability, Reliability and Security. ACM, 2020. 65. [doi: 10.1145/3407023.3409183]
[192] Wang XY. On the feasibility of detecting software supply chain attacks. In: Proc. of the 2021 IEEE Military Communications Conf. San

