高级检索

智能时代的软件供应链风险及应对技术

Countermeasures for Software Supply Chain Risks of the Intelligent Era

  • 摘要: 为了降本增效,几乎所有的软件项目都大量依赖已有的第三方软件组件。这些组件本身,又往往依赖更底层的其他组件。如此叠加和嵌套,构成了一个庞大而复杂的“软件复用网络”,即“软件供应链”,一旦供应链中的任何一个环节出现漏洞或疏漏,将引发广泛影响。以人工智能为代表的新兴技术的兴起,为软件供应链风险提出了新解法、新挑战。本研究结合典型案例,讨论软件供应链风险形成与扩散的机制和核心挑战,并探讨学界、业界的应对方式和技术。

     

    Abstract: To reduce costs and enhance efficiency, nearly all the software projects rely on existing third-party software components heavily. These components, in turn, often depend on other lower-level components, forming a vast and intricate software reuse network—referred to as the software supply chain. Once a vulnerability or oversight emerges in any link of this supply chain, it can trigger widespread supply chain crises. The rise of artificial intelligence puts forth novel solutions and new challenges to supply chain risks. This article examines the mechanisms and core challenges of software supply chain risk formation and propagation through representative case studies, while also exploring the strategies and technologies employed by academia and industry to mitigate and address these risks.

     

/

返回文章
返回