Page 81 - 《软件学报》2026年第7期
P. 81

软件学报 ISSN 1000-9825, CODEN RUXUEW                                        E-mail: jos@iscas.ac.cn
                 2026,37(7):2766−2807 [doi: 10.13328/j.cnki.jos.007589] [CSTR: 32375.14.jos.007589]  http://www.jos.org.cn
                 ©中国科学院软件研究所版权所有.                                                          Tel: +86-10-62562563



                                                                            *
                 产业研发视角下的开源软件供应链攻击问题研究

                 胡    帅  1,2 ,    王海军  1 ,    谢继刚  2 ,    裴鹏飞  2 ,    阿西伍合  1 ,    马辰达  1 ,    刘    烃  1


                  (西安交通大学 网络空间安全学院, 陕西 西安        710049)
                 1
                 2
                  (联通西部创新研究院, 陕西 西安 710021)
                 通信作者: 王海军, E-mail: haijunwang@xjtu.edu.cn

                 摘 要: 开源软件深度嵌入企业的产品研发与交付流程, 缩短了研发周期、降低了研发成本并增强了系统兼容性;
                 与此同时, 针对开源软件供应链的攻击事件也呈现上升态势, 已成为软件行业最重大的安全威胁之一. 从产业研发
                 视角分析研发效率与软件安全的内生矛盾, 发现产业组织以流程合规作为效率约束下, 被动应对开源软件供应链
                 安全威胁的隐性共识. 结合实际案例论证了基于流程合规的安全体系无法应对开源软件供应链攻击; 基于产业视
                 角提出了开源软件供应链攻击分类演化框架, 将开源软件供应链攻击分为                         3  个阶段: 开源共建威胁产生、闭源研
                 发威胁演化、成品使用攻击发作, 对不同阶段的攻击模式、技术手段等进行总结; 从面向开源生态的协同治理、
                 面向产业研发的持续合规与攻击面收敛、面向成品使用的自适应防护这                         3  个方面, 提出开源软件供应链的安全再
                 平衡体系.
                 关键词: 软件安全; 开源软件供应链; 产业研发视角; 产业研发流程; 开源软件供应链攻击防护
                 中图法分类号: TP311

                 中文引用格式: 胡帅, 王海军, 谢继刚, 裴鹏飞, 阿西伍合, 马辰达, 刘烃. 产业研发视角下的开源软件供应链攻击问题研究. 软件学
                 报, 2026, 37(7): 2766–2807. http://www.jos.org.cn/1000-9825/7589.htm
                 英文引用格式: Hu S, Wang HJ, Xie JG, Pei PF, Axi WH, Ma CD, Liu T. Research on Open-source Software Supply Chain Attacks
                 from Industrial R&D Perspective. Ruan Jian Xue Bao/Journal of Software, 2026, 37(7): 2766–2807 (in Chinese). http://www.jos.org.cn/
                 1000-9825/7589.htm

                 Research on Open-source Software Supply Chain Attacks from Industrial R&D Perspective
                                                            2
                                                 2
                                      1
                                                                                 1
                        1,2
                                                                      1
                 HU Shuai , WANG Hai-Jun , XIE Ji-Gang , PEI Peng-Fei , AXI Wu-He , MA Chen-Da , LIU Ting 1
                 1
                 (School of Cyber Science and Engineering, Xi’an Jiaotong University, Xi’an 710049, China)
                 2
                 (China Unicom Western Innovation Institute, Xi’an 710021, China)
                 Abstract:  Open-source  software  is  deeply  embedded  in  enterprise  product  research,  development,  and  delivery  processes,  shortening
                 development  cycles,  reducing  costs,  and  enhancing  system  compatibility.  Meanwhile,  attacks  targeting  the  open-source  software  supply
                 chain  continue  to  increase  and  have  become  one  of  the  most  critical  security  threats  to  the  software  industry.  From  an  industrial  research
                 and  development  (R&D)  perspective,  this  study  analyzes  the  inherent  tension  between  R&D  efficiency  and  software  security  and  identifies
                 an  implicit  consensus  in  industrial  practice:  under  efficiency  constraints  imposed  by  process  compliance,  organizations  tend  to  respond
                 passively  to  open-source  software  supply  chain  security  threats.  Through  representative  real-world  cases,  it  is  demonstrated  that  security
                 systems  primarily  driven  by  process  compliance  are  insufficient  to  address  open-source  software  supply  chain  attacks.  From  an  industrial
                 perspective,  this  study  further  proposes  an  evolutionary  classification  framework  of  open-source  software  supply  chain  attacks,  in  which
                 attacks  are  categorized  into  three  stages:  threat  emergence  during  open-source  co-development,  threat  evolution  during  closed-source


                 *    基金项目: 国家自然科学基金 (62232014, 62372367); 陕西省重点研发计划 (2024GX-ZDCYL-02-19); 陕西省高层次科技人才项目 (QCYRCXM-
                  2022-345)
                  本文由“智能化基础软件可信构造和供应链安全”专题特约编辑王林章教授、司徒凌云研究员、钟浩研究员、 向剑文教授、张路教授
                  推荐.
                  收稿时间: 2025-09-08; 修改时间: 2025-10-20; 采用时间: 2025-12-08; jos 在线出版时间: 2025-12-26
                  CNKI 网络首发时间: 2026-06-02
   76   77   78   79   80   81   82   83   84   85   86