PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 1, 2026Programming and Computer Software2 citations

Securing the Software Supply Chain with Software Bill of Materials (SBOMs): An Empirical Evaluation of Open-Source Tools in Enterprise IT Environments

View Full Paper
OSO. SoroceanAPA. Omar Portillo-DominguezVAVanessa Ayala-Rivera

Key Points

  • This research aims to evaluate open-source SBOM tools in enhancing visibility and managing the software supply chain.
  • Empirical evaluation of SBOM generation tools
  • Assessment across diverse enterprise IT environments
  • Identification of OSS components outside package managers
  • Analysis of hidden dependencies and system compatibility
  • Highlights trade-offs between accuracy and resource consumption
  • Demonstrates capabilities of SBOM tools in modern and legacy systems
  • Suggests leveraging existing software inventory data for SBOM creation

Abstract

The growing adoption of open source software (OSS) has transformed modern software development but has also introduced significant challenges in managing the security and transparency of the software supply chain. Traditional software asset inventories often fail to detect complex and dynamically integrated components. Software bill of materials (SBOMs) has emerged as a promising solution, offering greater visibility into software components and their dependencies. This study presents an empirical evaluation of open-source SBOM generation tools across diverse enterprise IT environments. The evaluation explores their ability to enhance visibility, identify OSS components installed outside package managers, capture hidden dependencies, and operate across modern and legacy systems. Our findings highlight the trade-offs between accuracy, system compatibility, and resource consumption (CPU, RAM, and execution time). Our study also examines the feasibility of leveraging existing software inventory data to streamline SBOM creation. By providing actionable insights into the effectiveness and limitations of SBOM tools, our work contributes to the ongoing efforts to secure the software supply chain through increased transparency and automation.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Sorocean et al. (2025) studied this question.

synapsesocial.com/papers/69a3d79dec16d51705d2de51https://doi.org/10.1134/s0361768825700598
Ask AI
Helpful
Bookmark
Share
View Full Paper