A Reality Check on SBOM-based Vulnerability Management: An Empirical Study and A Path Forward
Fuente:
arXiv
Saved in:
| Main Authors: | Zhou, Li, Dacier, Marc, Konstantinou, Charalambos |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
ReGraph: A Tool for Binary Similarity Identification
by: Zhou, Li, et al.
Published: (2025)
by: Zhou, Li, et al.
Published: (2025)
Event-Triggered Islanding in Inverter-Based Grids
by: Zografopoulos, Ioannis, et al.
Published: (2023)
by: Zografopoulos, Ioannis, et al.
Published: (2023)
A Modular End-to-End Framework for Secure Firmware Updates on Embedded Systems
by: Falas, Solon, et al.
Published: (2020)
by: Falas, Solon, et al.
Published: (2020)
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
by: Rosso, Martin, et al.
Published: (2025)
by: Rosso, Martin, et al.
Published: (2025)
Physics-Informed Neural Networks for Securing Water Distribution Systems
by: Falas, Solon, et al.
Published: (2020)
by: Falas, Solon, et al.
Published: (2020)
The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach
by: Benedetti, Giacomo, et al.
Published: (2024)
by: Benedetti, Giacomo, et al.
Published: (2024)
Trustworthy and Confidential SBOM Exchange
by: Ishgair, Eman Abu, et al.
Published: (2025)
by: Ishgair, Eman Abu, et al.
Published: (2025)
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
by: Sorger, Tom, et al.
Published: (2026)
by: Sorger, Tom, et al.
Published: (2026)
VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs
by: Castiglione, Gianpietro, et al.
Published: (2026)
by: Castiglione, Gianpietro, et al.
Published: (2026)
Supply Chain Insecurity: The Lack of Integrity Protection in SBOM Solutions
by: Ozkan, Can, et al.
Published: (2024)
by: Ozkan, Can, et al.
Published: (2024)
Virtual Reality and Augmented Reality Security: A Reconnaissance and Vulnerability Assessment Approach
by: Dastgerdy, Sarina
Published: (2024)
by: Dastgerdy, Sarina
Published: (2024)
An Empirical Study on Virtual Reality Software Security Weaknesses
by: Xu, Yifan, et al.
Published: (2025)
by: Xu, Yifan, et al.
Published: (2025)
Reality Check for Tor Website Fingerprinting in the Open World
by: Shadbeh, Mohammadhamed, et al.
Published: (2026)
by: Shadbeh, Mohammadhamed, et al.
Published: (2026)
Path-wise Vulnerability Mitigation
by: Huang, Zhen, et al.
Published: (2024)
by: Huang, Zhen, et al.
Published: (2024)
An Empirical Study on the Security Vulnerabilities of GPTs
by: Wu, Tong, et al.
Published: (2025)
by: Wu, Tong, et al.
Published: (2025)
Automating SBOM Generation with Zero-Shot Semantic Similarity
by: Pereira, Devin, et al.
Published: (2024)
by: Pereira, Devin, et al.
Published: (2024)
SBOM Generation Tools in the Python Ecosystem: an In-Detail Analysis
by: Cofano, Serena, et al.
Published: (2024)
by: Cofano, Serena, et al.
Published: (2024)
If LLMs Would Just Look: Simple Line-by-line Checking Improves Vulnerability Localization
by: Li, Yue, et al.
Published: (2024)
by: Li, Yue, et al.
Published: (2024)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026)
by: Chen, Zirui, et al.
Published: (2026)
An Empirical Study of Vulnerability Handling Times in CPython
by: Ruohonen, Jukka
Published: (2024)
by: Ruohonen, Jukka
Published: (2024)
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
by: Safronov, Vadim, et al.
Published: (2025)
by: Safronov, Vadim, et al.
Published: (2025)
VDGraph: A Graph-Theoretic Approach to Unlock Insights from SBOM and SCA Data
by: Xia, Howell, et al.
Published: (2025)
by: Xia, Howell, et al.
Published: (2025)
Cyber-Physical Co-Simulation of Load Frequency Control under Load-Altering Attacks
by: Forystek, Michał, et al.
Published: (2025)
by: Forystek, Michał, et al.
Published: (2025)
Exploring the Effects of Load Altering Attacks on Load Frequency Control through Python and RTDS
by: Forystek, Michał, et al.
Published: (2025)
by: Forystek, Michał, et al.
Published: (2025)
Cross-Ecosystem Vulnerability Analysis for Python Applications
by: Alexopoulos, Georgios, et al.
Published: (2026)
by: Alexopoulos, Georgios, et al.
Published: (2026)
Characterizing Trust Boundary Vulnerabilities in TEE Containers: An Empirical Study
by: Liu, Weijie, et al.
Published: (2025)
by: Liu, Weijie, et al.
Published: (2025)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
Bridging the Gap: A Study of AI-based Vulnerability Management between Industry and Academia
by: Wan, Shengye, et al.
Published: (2024)
by: Wan, Shengye, et al.
Published: (2024)
Hardware Design and Security Needs Attention: From Survey to Path Forward
by: Ghimire, Sujan, et al.
Published: (2025)
by: Ghimire, Sujan, et al.
Published: (2025)
Cybersecurity Issues in Local Energy Markets
by: Dabashi, Al Hussein, et al.
Published: (2025)
by: Dabashi, Al Hussein, et al.
Published: (2025)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
An Empirical Study of Vulnerabilities in Python Packages and Their Detection
by: Quan, Haowei, et al.
Published: (2025)
by: Quan, Haowei, et al.
Published: (2025)
Port Forwarding Services Are Forwarding Security Risks
by: Wang, Haoyuan, et al.
Published: (2024)
by: Wang, Haoyuan, et al.
Published: (2024)
An Empirical Study of Vulnerability Detection using Federated Learning
by: Zhou, Peiheng, et al.
Published: (2024)
by: Zhou, Peiheng, et al.
Published: (2024)
Exploiting Cross-Layer Vulnerabilities: Off-Path Attacks on the TCP/IP Protocol Suite
by: Feng, Xuewei, et al.
Published: (2024)
by: Feng, Xuewei, et al.
Published: (2024)
"Oh, sh*t! I actually opened the document!": An Empirical Study of the Experiences with Suspicious Emails in Virtual Reality Headsets
by: Sharevski, Filipo, et al.
Published: (2024)
by: Sharevski, Filipo, et al.
Published: (2024)
Vulnerability, Where Art Thou? An Investigation of Vulnerability Management in Android Smartphone Chipsets
by: Klischies, Daniel, et al.
Published: (2024)
by: Klischies, Daniel, et al.
Published: (2024)
Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems
by: Koscinski, Viktoria, et al.
Published: (2025)
by: Koscinski, Viktoria, et al.
Published: (2025)
Are Latent Vulnerabilities Hidden Gems for Software Vulnerability Prediction? An Empirical Study
by: Le, Triet H. M., et al.
Published: (2024)
by: Le, Triet H. M., et al.
Published: (2024)
Similar Items
-
ReGraph: A Tool for Binary Similarity Identification
by: Zhou, Li, et al.
Published: (2025) -
Event-Triggered Islanding in Inverter-Based Grids
by: Zografopoulos, Ioannis, et al.
Published: (2023) -
A Modular End-to-End Framework for Secure Firmware Updates on Embedded Systems
by: Falas, Solon, et al.
Published: (2020) -
A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
by: Rosso, Martin, et al.
Published: (2025) -
Physics-Informed Neural Networks for Securing Water Distribution Systems
by: Falas, Solon, et al.
Published: (2020)