The invention discloses an enterprise-level three-party dependency
package security management and
control system and method, and relates to the technical field of
software supply chain security, and the enterprise-level three-party dependency
package security management and
control system comprises the following modules: a timed task scheduling module, an external network
package pre-scanning module, a private service package monitoring module, a
dependency graph construction module, a product management and control module and a notification display module. By establishing an external
network packet pre-scanning mechanism, security scanning is performed and a blocking
list is generated before a dependent packet enters an enterprise private
server, and introduction of a packet containing high-risk vulnerabilities is blocked from the source; meanwhile, through the
continuous monitoring of the private
server package and the construction of the dependency relationship graph, the
vulnerability discovery and the accurate positioning of the influence range of the stored dependency package are realized; and finally, performing hierarchical management and control on the affected products based on
vulnerability levels, and realizing timely transmission and situation
visualization of risk information through a notification display module. According to the invention, full-life-cycle safety protection from an external network source to internal products of an enterprise is realized, and the safety
management level and risk response efficiency of the dependent package of the enterprise are effectively improved.