Page 121 - 《软件学报》2026年第7期
P. 121

2806                                                       软件学报  2026  年第  37  卷第  7  期


                      Diego: ACM, 2021. 458–463. [doi: 10.1109/MILCOM52596.2021.9652901]
                 [193]   Jiang WX, Synovic N, Sethi R, Indarapu A, Hyatt M, Schorlemmer TR, Thiruvathukal GK, Davis JC. An empirical study of artifacts
                      and security risks in the pre-trained model supply chain. In: Proc. of the 2022 ACM Workshop on Software Supply Chain Offensive
                      Research and Ecosystem Defenses. Los Angeles: ACM, 2022. 105–114. [doi: 10.1145/3560835.3564547]
                 [194]   Irungu J, Girma A. Analysis of baseline security standards and predictive analytics for cyber supply chain attacks and artificial neural
                      network as a proposed solution. In: Proc. of the 2023 Int’l Conf. on Electrical, Computer and Energy Technologies. Cape Town: IEEE,
                      2023. 1–6. [doi: 10.1109/ICECET58911.2023.10389476]
                 [195]   Ge LL, Shuai DX, Xie JY, Zhang YZ, Xue YC, Yang JY, Mi J, Lu Y. Review on exception analysis methods for software supply chain.
                      Ruan Jian Xue Bao/Journal of Software, 2023, 34(6): 2606–2627 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/
                      6850.htm [doi: 10.13328/j.cnki.jos.006850]
                 [196]   Zhang LY, Liu CW, Xu ZZ, Chen S, Fan LL, Zhao LD, Wu JH, Liu Y. Compatible remediation on vulnerabilities from third-party
                      libraries for Java projects. In: Proc. of the 45th IEEE/ACM Int’l Conf. on Software Engineering. Melbourne: IEEE, 2023. 1695–1707.
                      [doi: 10.1109/ICSE48619.2023.00212]
                 [197]   Fu M, Tantithamthavorn C, Le T, Nguyen V, Phung D. VulRepair: A T5-based automated software vulnerability repair. In: Proc. of the
                      30th ACM Joint European Software Engineering Conf. and Symp. on the Foundations of Software Engineering. Singapore: ACM, 2022.
                      935–947. [doi: 10.1145/3540250.3549098]
                 [198]   Zhang J, Wang C, Li AR, Wang WH, Li TL, Liu Y. VulAdvisor: Natural language suggestion generation for software vulnerability
                      repair. In: Proc. of the 39th IEEE/ACM Int’l Conf. on Automated Software Engineering. Sacramento: IEEE, 2024. 1932–1944.
                 [199]   Canonical Ltd. Linux Kernel Livepatch Mitigate Linux kernel exploits with Livepatch. 2025. https://ubuntu.com/security/livepatch
                 [200]   Salehi M, Pattabiraman K. AutoPatch: Automated generation of hotpatches for real-time embedded devices. In: Proc. of the 2024 ACM
                      SIGSAC Conf. on Computer and Communications Security. Salt Lake City: ACM, 2024. 2370–2384. [doi: 10.1145/3658644.3690255]
                 [201]   Duan RA, Bijlani A, Ji Y, Alrawi O, Xiong YY, Ike M, Saltaformaggio B, Lee W. Automating patching of vulnerable open-source
                      software versions in application binaries. In: Proc. of the 26th Annual Network and Distributed System Security Symp. San Diego: The
                      Internet Society, 2019.
                 [202]   Hanna  C,  Petke  J.  Hot  patching  hot  fixes:  Reflection  and  perspectives.  In:  Proc.  of  the  38th  IEEE/ACM  Int’l  Conf.  on  Automated
                      Software Engineering. Echternach: IEEE, 2023. 1781–1786. [doi: 10.1109/ASE56229.2023.00021.]
                 [203]   He RZ, Zhou MH. Countermeasures for software supply chain risks of the intelligent era. Computing Magazine of the CCF, 2025, 1(3):
                      59–66 (in Chinese with English abstract). [doi: 10.11991/cccf.202507009]
                 [204]   Li HP, Shan L. LLM-based vulnerability detection. In: Proc. of the 2023 Int’l Conf. on Human-centered Cognitive Systems. Cardiff:
                      IEEE, 2023. 1–4. [doi: 10.1109/HCCS59561.2023.10452613]
                 [205]   Chennabasappa S, Nikolaidis C, Song D, Molnar D, Ding S, Wan SY, Whitman S, Deason L, Doucette N, Montilla A, Gampa A, de
                      Paola B, Gabi D, Crnkovich J, Testud JC, He K, Chaturvedi R, Zhou W, Saxe J. LlamaFirewall: An open source guardrail system for
                      building secure ai agents. arXiv:2505.03574, 2025.
                 [206]   Yu H, Wang Y, Xu MQ, Yang B, Xu C, Zhu ZL. Measurement method for complexity of software library dependency graph and its
                      potential applications. Ruan Jian Xue Bao/Journal of Software, 2023, 34(11): 5282–5311 (in Chinese with English abstract). http://www.
                      jos.org.cn/1000-9825/6746.htm [doi: 10.13328/j.cnki.jos.006746]

                 附中文参考文献
                  [2]   纪守领, 王琴应, 陈安莹, 赵彬彬, 叶童, 张旭鸿, 吴敬征, 李昀, 尹建伟, 武延军. 开源软件供应链安全研究综述. 软件学报, 2023,
                      34(3): 1330–1364. http://www.jos.org.cn/1000-9825/6717.htm [doi: 10.13328/j.cnki.jos.006717]
                  [3]   罗丹, 吴荣春. 国内开源软件的发展现状与风险分析. 通信世界, 2022(15): 33–34. [doi: 10.13571/j.cnki.cww.2022.15.008]
                  [7]   高恺, 何昊, 谢冰, 周明辉. 开源软件供应链研究综述. 软件学报, 2024, 35(2): 581–603. http://www.jos.org.cn/1000-9825/6975.htm
                      [doi: 10.13328/j.cnki.jos.006975]
                  [8]   Synopsys. 2024  年开源安全和风险分析报告. 2024. https://www.blackduck.com/content/dam/black-duck/zh-cn/reports/rep-ossra-2024-
                      ch.pdf
                 [10]   孟迎霞, 隆云滔, 王伟, 孙启, 荆琦, 谭中意, 唐小引, 鞠东颖. 2024  中国开源发展现状. 2024. https://copu-oss.org.cn/download/
                      showdownload.php?id=32
                 [23]   王立敏, 卜磊, 马乐之, 于笑丰, 沈宁国. 基于指标依赖模型构建与监控的攻击检测方法. 软件学报, 2023, 34(6): 2641–2668. http://
                      www.jos.org.cn/1000-9825/6847.htm [doi: 10.13328/j.cnki.jos.006847]
                 [24]   詹奇, 潘圣益, 胡星, 鲍凌峰, 夏鑫. 开源软件漏洞感知技术综述. 软件学报, 2024, 35(1): 19–37. http://www.jos.org.cn/1000-9825/
   116   117   118   119   120   121   122   123   124   125   126