The application discloses a kind of based on SBOM's automobile
software supply chain security and
open source governance
system and method, by identifying the
bill of materials SBOM of automobile
software provided by supplier, obtain the basic information of
software containing multiple components, software extension information;
Software basic information in SBOM is matched with trusted
vulnerability library, obtain all known vulnerabilities of SBOM;According to the dependency in SBOM, the influence range of each
vulnerability is analyzed, and the affected software product and vehicle model are determined;According to the software product, vehicle model,
vulnerability hazard affected, determine vulnerability level;Known vulnerabilities of component and vulnerability level are bound with component in SBOM, form SBOM risk view, determine repair scheme based on risk view;From SBOM identification, vulnerability matching,
risk assessment, repair scheme determination to SBOM update, cover the whole process of supply chain
security management, form the closed-loop management from
vulnerability discovery to repair, ensure that the problem is solved.