Analyzing Software Supply Chain Security Risks in Industrial Control System Protocols: An OpenSSF Scorecard Approach

2023 10th International Conference on Dependable Systems and Their Applications (DSA)(2023)

引用 0|浏览0
暂无评分
摘要
With a significant annual increase in software supply chain attacks over the past three years, concerns arise regarding the vulnerability of Industrial Control Systems (ICS) environments, especially given the growing use of open-source protocols’ implementations. Therefore, it is essential to assess the software supply chain security risks associated with these protocols. This study investigates the prevalent software supply chain security risks in open source protocol implementations used in ICS, compares software supply chain security risks between ICS and non-ICS protocols, evaluates assessed protocols’ strengths and weaknesses in terms of software supply chain security risks, and identifies opportunities to enhance their security. Using the Open Source Security Foundation (OpenSSF) Scorecard, the study analyzes nine ICS and five non-ICS protocols, highlighting strengths, weaknesses, and potential improvements. The study also identifies opportunities to enhance protocol and software supply chain security.
更多
查看译文
关键词
Industrial Control Systems (ICS),Open Source Protocols Implementations,Cybersecurity,Software Supply Chain,Software Composition Analysis,OpenSSF Scorecard
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要