Urgent.News

What's breaking now, across thousands of outlets.

Science

Computer Security: The road to SBOM

The SBOM (short for “Software Bill of Materials”) gets a bad rap in IT. As full (and often enormous) inventories of components, libraries and packages, SBOMs are complicated to set up and therefore no one is a big fan of them. Instead, many IT managers try to avoid them altogether. This is unfortunate as SBOMs […]

The Software Bill of Materials (SBOM) is receiving negative attention in the IT community due to its complexity and the effort required to set up. Many IT managers avoid using SBOMs altogether. However, SBOMs offer numerous benefits, including strategic planning for upgrades, removal of unused libraries and packages, software licensing and export control compliance, and the ability to provide a machine-readable "ingredient list" of software components used in a system.

They can be automatically generated and analyzed, reducing the time spent on manual tasks and enhancing the reproducibility of experiments, which is crucial for open science.

CERN, a research institution, is taking steps towards understanding software component usage. They have several SBOM initiatives in place, such as GitLab dependency and security scans, and the listing of vulnerable components as part of OpenStack-managed containers. Additionally, the Accelerators and Technologies Sector uses advanced inventory for software succession and roll-out planning.

CERN is currently developing an overall SBOM strategy, and an external researcher from Ruhr University Bochum will inventory the different areas where SBOMs are or will be deployed. This study aims to understand the benefits and drawbacks of SBOMs and any support needed during deployment.

CERN has also hired a technical student to investigate technical means of creating SBOMs. Various tools can be used, including GitLab dependency-scanner, OpenStack registry, commercial tools like Artifactory, JFrog, Nexus and Snyk, or the open-source standard CycloneDX. A software gateway acting as a proxy could provide valuable insights by logging software component downloads, usage, and origin.

It could also act as a cache and introduce quarantines for certain time periods, providing initial analysis on dependencies, copyright issues, and security ratings. While SBOMs may seem like a nuisance, the benefits, such as better visibility of software components and additional information, outweigh the initial effort. For more information, interested parties are encouraged to contact CERN's Computer Security Office.

Written by urgent.news from CERN's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at home.cern →

More in Science

More from Wednesday 30 September →