42
55
55
55
55
42
35
42
60
60
42
42
42
55
42
42
55
42
55
55
42
55
55
42
42
55
42
55
42
42
55
42
60
55
Propagation Model for SSC attacks: Why SBOM (tools) don't tell the whole truth
Study shows open-source SBOM tools only cover structural exposure and vulnerability presence, missing code reachability and taint-path analysis stages.
An arXiv paper proposes a four-stage propagation model for software supply chain attack effects and empirically evaluates four open-source SBOM tools against it using three projects and the Log4j vulnerability as the test case. Current SBOM tools systematically support only Stage 1 (structural exposure) and Stage 2 (vulnerability class presence), while Stage 3 (code reachability) and Stage 4 (taint path analysis) require capabilities absent from the SBOM ecosystem. The authors argue propagation-centred SSC security research is needed to prevent cyber risk from evolving into systemic risk.
38
42
60
55
55
42