Netinfo Security ›› 2023, Vol. 23 ›› Issue (5): 50-61.doi: 10.3969/j.issn.1671-1122.2023.05.006

Previous Articles     Next Articles

Research on the Supply Chain Security Risk Assessment Methods for Mixed Source Operating System

ZHAO Jun, REN Yi(), LI Bao, TAN Yusong   

  1. College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China
  • Received:2022-12-27 Online:2023-05-10 Published:2023-05-15
  • Contact: REN Yi E-mail:renyi@nudt.edu.cn

Abstract:

At present, software supply chain security incidents occur frequently, and conducting security risk assessments can identify potential risks. This is an important method to manage security risks and prevent security incidents. As the core foundational software of information systems, the mixed source operating system (MSOS) is widely used in the government, power, finance, communication and other important fields, and its supply chain should be paid more attention to. Due to the diverse code sources, large code scale, and complex structure and component dependencies of MSOS, existing software supply chain security risk assessment methods are not fully applicable to MSOS in terms of ensuring goals and indicator systems. To address this issue, the article proposed traceability, availability and security assurance objectives for supply chain security. Based on these assurance objectives, risk factors affecting the supply chain security of MSOS was analyzed, and a measurable indicator system was designed to evaluate its security risk. The effectiveness of the indicator system was verified through examples, and some relevant technical means and tools that can be used to evaluate important indicators were summarized and elaborated.

Key words: mixed source, operating system, security of supply chain, risk factors

CLC Number: