2025³â 06¿ù 16ÀÏ ¿ù¿äÀÏ
 
 
  ÇöÀçÀ§Ä¡ > ´º½ºÁö´åÄÄ > Science & Technology

·£¼¶¿þ¾îºÎÅÍ µÅÁöµµ»ì±îÁö... ³ë·ÃÇØÁø »ç±âÇà°¢

 

Á¤Ä¡

 

°æÁ¦

 

»çȸ

 

»ýȰ

 

¹®È­

 

±¹Á¦

 

°úÇбâ¼ú

 

¿¬¿¹

 

½ºÆ÷Ã÷

 

ÀÚµ¿Â÷

 

ºÎµ¿»ê

 

°æ¿µ

 

¿µ¾÷

 

¹Ìµð¾î

 

½Å»óǰ

 

±³À°

 

ÇÐȸ

 

½Å°£

 

°øÁö»çÇ×

 

Ä®·³

 

Ä·ÆäÀÎ
Çѻ츲 ¡®¿ì¸®´Â ÇѽҸ²¡¯ ½Ò ¼Òºñ Ä·ÆäÀÎ ½Ã...
1000¸¸¿øÂ¥¸® Àΰø¿Í¿ì, °Ç°­º¸Çè Áö¿ø ¡®Æò...
- - - - - - -
 

Strengthening the Software Supply Chain With SBOM

´º½ºÀÏÀÚ: 2024-08-13

[Executive Corner] Approximately 70 percent of South Korean companies involved in software development use open-source software (OSS), according to the Korea National IT Industry Promotion Agency. OSS is easily accessible and can be utilized by users worldwide through online platforms like GitHub, enabling developers to create, develop, manage and share code. While OSS offers numerous benefits – from cost effectiveness to customizability and flexibility – it also presents significant drawbacks, including the prevalence of malicious code and security vulnerabilities that can spread rapidly.

The global use of OSS has increased, not only on the web and in various applications but also in software embedded in home appliances and telecommunications equipment. As its adoption has spread, new threats to digital products and online services have emerged and multiplied. Cybersecurity incidents now occur daily, with the software supply chain being a common target for cyberattacks. According to PwC’s 2024 Global Digital Trust Insights survey, the proportion of companies experiencing data breaches costing more than USD one million has risen from 27 percent to 36 percent year-over-year.*

To prevent and defend against cyberattacks, various efforts are being made to ramp up software supply chain security, particularly in the U.S. and Europe. The U.S. government has mandated that any company contracted to supply software to a federal agency must submit a self-attestation form confirming compliance with safe software development practices. Similarly, the European Union has proposed a bill mandating the submission of a “software bill of materials” (SBOM). An SBOM is a comprehensive list of the components within a software resource and has emerged as an effective means to enhance supply chain security.

The Korean government is also actively responding to the rise in advanced cyberattacks targeting software supply chains. Earlier this year, Korea’s Digital Platform Government Committee, along with the Ministry of Science and ICT and the National Intelligence Service, created the ‘Software Supply Chain Security Guidelines 1.0.’

These guidelines contain detailed information on minimum SBOM requirements, software security vulnerability inspection criteria, the use of government-supported test beds, and how to specify and utilize software components. Easy to use and follow, the guidelines also include cases verified through last year’s demonstration project for field application, organized by the Korean government.

Large companies, including LG Electronics, are addressing software security vulnerabilities with their own SBOM tools and management procedures. In today’s business environment, software development typically involves the use of OSS and a collaborative system involving multiple partner companies. To ensure the security of the entire software supply chain, it is crucial that each participant plays their role well – taking all necessary steps and using all available tools to prevent security breaches.

For this reason, LG is helping other companies to effectively manage SBOM by releasing the source code of FOSSLight – LG’s in-house developed SBOM tool. FOSSLight can accurately detect a specific piece of OSS, monitor it for security vulnerabilities and retrieve any associated licenses. As the project for open source governance, FOSSLight consists of FOSSLight Hub, an integrated system that can manage open source, and FOSSLight Scanner, which can analyze open source.

LG’s commitment to ensuring security isn’t anything new. At CES 2024, LG CEO William Cho redefined AI as ‘Affectionate Intelligence’ and shared the company’s aspiration to pursue Responsible Intelligence. LG Shield, the company’s AI-based security system, will be applied to every aspect of customer-data collection, storage and usage, and will also be used to protect the software supply chain.

Ultimately, SBOM enhances an organization’s ability to identify and respond to software security vulnerabilities in advance. In addition to preventing organizational information, digital infrastructure, and customer data from being compromised, SBOM can also improve the overall quality of the software used by companies. Furthermore, because it promotes greater transparency in the software supply chain, SBOM is expected to play an important role in strengthening reliability in overseas markets.

This effort was prominently featured in a panel discussion at the OECD Global Forum on Digital Security for Prosperity in July. The panel, titled “Open-source software and vulnerability treatment,” delved into the specific challenges and solutions related to open source software vulnerabilities. The discussion highlighted how both proprietary and open-source software are affected by the reality that increased code complexity often results in more vulnerabilities. The session provided an in-depth exploration of the unique aspects of open-source software and its ecosystem in addressing these issues.

In the future, we hope that the adoption of SBOM will increase throughout the ICT industry, bringing about a safer and more transparent OSS ecosystem that benefits all companies.

By Kim Kyoung-ae, Open Source Task Leader of Software Engineering R&D Lab. at LG Electronics



 Àüü´º½º¸ñ·ÏÀ¸·Î

Lenovo and Bellevue University Team Up to Offer Supply Chain and Logistics Education to Deliver ¡°Smarter Technology for All¡±
Byondis Doses First Patient in Phase 1 Trial of Novel SIRP¥á-Directed Antibody BYON4228 for Advanced or Metastatic Solid Tumors
GCT Semiconductor and Iridium Sign MOU to Collaborate on Integrating Iridium NTN Direct℠ Service into GCT Chipset
Agenus and Zydus Lifesciences Enter $141M Strategic Collaboration to Advance BOT/BAL, Expand Zydus¡¯ Biologics Manufacturing in the US
Biocytogen Secures Japan Patent for RenMab Platform, Expands Global Patent Portfolio for RenMice Fully Human Antibody/TCR Platform
Takeda and Nature Announce Call for Applications Now Open for 2026 Innovators in Science Award
Protagonist & Takeda Reveal ASCO Plenary Results From VERIFY Phase 3 Study Of Rusfertide, Showing Reduced Phlebotomy & Improved Hematocrit Control in

 

Seventh and Eighth O3b mPOWER Satellites to Start Delivering Connectiv...
Textron Aviation European Distribution Center Celebrates 10 Years as I...
Kinaxis Brings AI-Powered Supply Chain Breakthroughs to Tokyo at Kinex...
OpenGMSL¢â Association Announces Formation to Revolutionize the Future...
GCT Semiconductor Celebrates Major Milestone with Delivery of 5G Chips...
FDA Grants Priority Review for Zoliflodacin NDA to Treat Uncomplicated...
Rubedo¡¯s ALEMBIC¢â identifies senescent ¡°zombie¡± neurons linked to ...

 


°øÁö»çÇ×
´º½ºÁö ÇÑÀÚ Ç¥±â¿¡ ´ë¸¸½Ä À½Â÷ Ç¥±â '纽ÞÙó¢ ´Ï¿ì½ÃÁö' º´±â
º£³×ÇÁ·Ò º£³×ÀÎÅõ Áß¹® Ç¥±â 宝Ò¬ÜØÙÌ 宝Ò¬ì×öõ(ÜÄÒ¬ÜØÙÌ ÜÄ...
¹Ìµð¾î¾Æ¿ì¾î Mediaour ØÚ体ä²们 ØÚô÷ä²Ùú MO ¿¥¿À ØÚä² ØÚä²
¾Ë¸®¿ìºê Alliuv ä¹备: ä¹联êó备, ¾Ë¶ã Althle ä¹÷åìÌ
¾Ë¸®¾Ë Allial Áß¹® Ç¥±â ä¹××尔 ä¹××ì³
´ºÆÛ½ºÆ® New1st Áß¹® Ç¥±â 纽ììãæ(¹øÃ¼ Òïììãæ), N1 纽1
¿£ÄÚ½º¸ð½º : À̾¾ 'EnCosmos : EC' Áß¹® Ç¥±â ì¤ñµ
¾ÆÀ̵ð¾î·Ð Idearon Áß¹® Ç¥±â ì¤îè论 ì¤îèÖå
¹ÙÀÌ¿ÀÀÌ´Ï Bioini Áß¹® Ç¥±â ù±药研 ù±å·æÚ
¿À½ºÇÁ·Ò Ausfrom 奥ÞÙÜØÙÌ, À£ÇÁ·Ò Welfrom 卫ÜØÙÌ
¿¡³ÊÇÁ·Ò Enerfrom 额ÒöÜØÙÌ ¿¡³ÊÀ¯ºñ Eneruv 额Òöêó备
¾ËÇÁ·Ò Alfrom Áß¹® Ç¥±â ä¹尔ÜØÙÌ ä¹ì³ÜØÙÌ

 

ȸ»ç¼Ò°³ | ÀÎÀçä¿ë | ÀÌ¿ë¾à°ü | °³ÀÎÁ¤º¸Ãë±Þ¹æÄ§ | û¼Ò³âº¸È£Á¤Ã¥ | Ã¥ÀÓÇѰè¿Í ¹ýÀû°íÁö | À̸ÞÀÏÁÖ¼Ò¹«´Ü¼öÁý°ÅºÎ | °í°´¼¾ÅÍ

±â»çÁ¦º¸ À̸ÞÀÏ news@newsji.com, ÀüÈ­ 050 2222 0002, ÆÑ½º 050 2222 0111, ÁÖ¼Ò : ¼­¿ï ±¸·Î±¸ °¡¸¶»ê·Î 27±æ 60 1-37È£

ÀÎÅͳݴº½º¼­ºñ½º»ç¾÷µî·Ï : ¼­¿ï ÀÚ00447, µî·ÏÀÏÀÚ : 2013.12.23., ´º½º¹è¿­ ¹× û¼Ò³âº¸È£ÀÇ Ã¥ÀÓ : ´ëÇ¥ CEO

Copyright ¨Ï All rights reserved..