A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhou, Li, Dacier, Marc, Konstantinou, Charalambos
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917414880411648
author Zhou, Li
Dacier, Marc
Konstantinou, Charalambos
author_facet Zhou, Li
Dacier, Marc
Konstantinou, Charalambos
contents The Software Bill of Materials (SBOM) is a critical tool for securing the software supply chain (SSC), but its practical utility is undermined by inaccuracies in both its generation and its application in vulnerability scanning. This paper presents a large-scale empirical study on 2,414 open-source repositories to address these issues from a practical standpoint. First, we demonstrate that using lock files with strong package managers enables the generation of accurate and consistent SBOMs, establishing a reliable foundation for security analysis. Using this high-fidelity foundation, however, we expose a more fundamental flaw in practice: downstream vulnerability scanners produce a staggering 92.0\% false positive rate in our case study. We pinpoint the primary cause as the flagging of vulnerabilities within unreachable code. We then demonstrate that function call analysis can effectively prune 61.9\% of these false alarms. Our work validates a practical, two-stage approach for SSC security: first, generate an accurate SBOM using lock files and strong package managers, and second, enrich it with function call analysis to produce actionable, low-noise vulnerability reports that alleviate developers' alert fatigue.
format Preprint
id arxiv_https___arxiv_org_abs_2511_20313
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward
Zhou, Li
Dacier, Marc
Konstantinou, Charalambos
Cryptography and Security
The Software Bill of Materials (SBOM) is a critical tool for securing the software supply chain (SSC), but its practical utility is undermined by inaccuracies in both its generation and its application in vulnerability scanning. This paper presents a large-scale empirical study on 2,414 open-source repositories to address these issues from a practical standpoint. First, we demonstrate that using lock files with strong package managers enables the generation of accurate and consistent SBOMs, establishing a reliable foundation for security analysis. Using this high-fidelity foundation, however, we expose a more fundamental flaw in practice: downstream vulnerability scanners produce a staggering 92.0\% false positive rate in our case study. We pinpoint the primary cause as the flagging of vulnerabilities within unreachable code. We then demonstrate that function call analysis can effectively prune 61.9\% of these false alarms. Our work validates a practical, two-stage approach for SSC security: first, generate an accurate SBOM using lock files and strong package managers, and second, enrich it with function call analysis to produce actionable, low-noise vulnerability reports that alleviate developers' alert fatigue.
title A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward
topic Cryptography and Security
url https://arxiv.org/abs/2511.20313