摘要
在维护软件供应链的安全性方面,软件成分安全分析(SCA)技术起到了至关重要的作用。通过建设SCA模型、基础设施与工具的部署、制定安全策略和合规要求等路径,能够显著增强软件的安全防护能力。该文深入剖析了SCA能力从起步阶段到现代化全面升级的整个演进过程,并对即将到来的创新机遇与挑战进行了展望。
Software component security analysis(SCA)technology plays a crucial role in maintaining the security of the software supply chain.By building SCA models,deploying infrastructure and tools,and formulating security policies and compliance requirements,the security protection capabilities of software can be significantly enhanced.This article deeply analyzes the entire evolution process of SCA capabilities from the initial stage to the modernization and comprehensive upgrade,and looks forward to the upcoming innovation opportunities and challenges.
作者
魏志超
高红
WEI Zhichao;GAO Hong(China Mobile Communications Group ShanxiCo.,Ltd.,Taiyuan 030000,China)
出处
《数字通信世界》
2024年第11期20-22,31,共4页
Digital Communication World
关键词
软件成分安全分析(SCA)
模型构建
建设路径
能力演进
software component security analysis(SCA)
model construction
construction path
capability Evolution