Page 81 - 《软件学报》2026年第7期
P. 81
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
2026,37(7):2766−2807 [doi: 10.13328/j.cnki.jos.007589] [CSTR: 32375.14.jos.007589] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
*
产业研发视角下的开源软件供应链攻击问题研究
胡 帅 1,2 , 王海军 1 , 谢继刚 2 , 裴鹏飞 2 , 阿西伍合 1 , 马辰达 1 , 刘 烃 1
(西安交通大学 网络空间安全学院, 陕西 西安 710049)
1
2
(联通西部创新研究院, 陕西 西安 710021)
通信作者: 王海军, E-mail: haijunwang@xjtu.edu.cn
摘 要: 开源软件深度嵌入企业的产品研发与交付流程, 缩短了研发周期、降低了研发成本并增强了系统兼容性;
与此同时, 针对开源软件供应链的攻击事件也呈现上升态势, 已成为软件行业最重大的安全威胁之一. 从产业研发
视角分析研发效率与软件安全的内生矛盾, 发现产业组织以流程合规作为效率约束下, 被动应对开源软件供应链
安全威胁的隐性共识. 结合实际案例论证了基于流程合规的安全体系无法应对开源软件供应链攻击; 基于产业视
角提出了开源软件供应链攻击分类演化框架, 将开源软件供应链攻击分为 3 个阶段: 开源共建威胁产生、闭源研
发威胁演化、成品使用攻击发作, 对不同阶段的攻击模式、技术手段等进行总结; 从面向开源生态的协同治理、
面向产业研发的持续合规与攻击面收敛、面向成品使用的自适应防护这 3 个方面, 提出开源软件供应链的安全再
平衡体系.
关键词: 软件安全; 开源软件供应链; 产业研发视角; 产业研发流程; 开源软件供应链攻击防护
中图法分类号: TP311
中文引用格式: 胡帅, 王海军, 谢继刚, 裴鹏飞, 阿西伍合, 马辰达, 刘烃. 产业研发视角下的开源软件供应链攻击问题研究. 软件学
报, 2026, 37(7): 2766–2807. http://www.jos.org.cn/1000-9825/7589.htm
英文引用格式: Hu S, Wang HJ, Xie JG, Pei PF, Axi WH, Ma CD, Liu T. Research on Open-source Software Supply Chain Attacks
from Industrial R&D Perspective. Ruan Jian Xue Bao/Journal of Software, 2026, 37(7): 2766–2807 (in Chinese). http://www.jos.org.cn/
1000-9825/7589.htm
Research on Open-source Software Supply Chain Attacks from Industrial R&D Perspective
2
2
1
1
1,2
1
HU Shuai , WANG Hai-Jun , XIE Ji-Gang , PEI Peng-Fei , AXI Wu-He , MA Chen-Da , LIU Ting 1
1
(School of Cyber Science and Engineering, Xi’an Jiaotong University, Xi’an 710049, China)
2
(China Unicom Western Innovation Institute, Xi’an 710021, China)
Abstract: Open-source software is deeply embedded in enterprise product research, development, and delivery processes, shortening
development cycles, reducing costs, and enhancing system compatibility. Meanwhile, attacks targeting the open-source software supply
chain continue to increase and have become one of the most critical security threats to the software industry. From an industrial research
and development (R&D) perspective, this study analyzes the inherent tension between R&D efficiency and software security and identifies
an implicit consensus in industrial practice: under efficiency constraints imposed by process compliance, organizations tend to respond
passively to open-source software supply chain security threats. Through representative real-world cases, it is demonstrated that security
systems primarily driven by process compliance are insufficient to address open-source software supply chain attacks. From an industrial
perspective, this study further proposes an evolutionary classification framework of open-source software supply chain attacks, in which
attacks are categorized into three stages: threat emergence during open-source co-development, threat evolution during closed-source
* 基金项目: 国家自然科学基金 (62232014, 62372367); 陕西省重点研发计划 (2024GX-ZDCYL-02-19); 陕西省高层次科技人才项目 (QCYRCXM-
2022-345)
本文由“智能化基础软件可信构造和供应链安全”专题特约编辑王林章教授、司徒凌云研究员、钟浩研究员、 向剑文教授、张路教授
推荐.
收稿时间: 2025-09-08; 修改时间: 2025-10-20; 采用时间: 2025-12-08; jos 在线出版时间: 2025-12-26
CNKI 网络首发时间: 2026-06-02

