What You See Is Not What You Execute: Memory-Based Runtime SBOM Generation for Supply Chain Security
A memory-based runtime SBOM generation approach addresses the gap between declared dependencies and actually loaded components—critical for accurate supply-chain risk assessment under CRA and NIS2.
Summary written by editorial AI · Source link below
arXiv:2606.22827v2 Announce Type: replace Abstract: Modern software development relies heavily on third-party components from public repositories, expanding the software supply chain attack surface. In response to these growing risks, federal initiatives have advanced the Software Bill of Materials (SBOM) as a standardized mechanism for improving transparency by describing software components, dependencies, and their relationships. However, SBOMs built from metadata or filesystem artifacts fail
Editorial Analysis
Static SBOMs often miss dynamically loaded or phantom dependencies; runtime-generated SBOMs give defenders a ground-truth view essential for meeting upcoming EU supply-chain mandates.
Evaluate runtime SBOM generation tooling to complement static manifests, especially for applications subject to CRA reporting requirements.
Runtime software inventories close a blind spot in supply-chain transparency that upcoming EU regulation will demand.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Research Desk
- Is That Really My X-Ray? Measuring Internet-Exposed DICOM Services in the Presence of Deception20 Jul
- Characterizing Phishing Pages by JavaScript Capabilities20 Jul
- Intentional Electromagnetic Interference Attacks on Facial Recognition20 Jul
- DoSQ: A Cross-Layer Denial of Service Quality Attack by Exploiting Side Channels in 5G NR20 Jul
- Vogls: a Fast Interactive Full-timing Simulator for Pre-silicon Power Side-Channel Analysis20 Jul