纵向
计算机科学
脆弱性(计算)
计算机安全
威胁模型
软件
透视图(图形)
领域(数学分析)
事件(粒子物理)
人工智能
物理
程序设计语言
艺术
数学分析
量子力学
艺术史
数学
作者
Maoyang Wang,Peng Wu,Qi Luo
出处
期刊:Mathematics
[MDPI AG]
日期:2023-12-02
卷期号:11 (23): 4856-4856
摘要
With the rapid growth of the software industry, the software supply chain (SSC) has become the most intricate system in the complete software life cycle, and the security threat situation is becoming increasingly severe. For the description of the SSC, the relevant research mainly focuses on the perspective of developers, lacking a comprehensive understanding of the SSC. This paper proposes a chain portrait framework of the SSC based on a resource perspective, which comprehensively depicts the threat model and threat surface indicator system of the SSC. The portrait model includes an SSC threat model and an SSC threat indicator matrix. The threat model has 3 levels and 32 dimensions and is based on a generative artificial intelligence model. The threat indicator matrix is constructed using the Attack Net model comprising 14-dimensional attack strategies and 113-dimensional attack techniques. The proposed portrait model’s effectiveness is verified through existing SSC security events, domain experts, and event visualization based on security analysis models.
科研通智能强力驱动
Strongly Powered by AbleSci AI