微型电脑应用2024,Vol.40Issue(8) :77-80.

基于AIGC的开源软件供应链风险识别

Risk Identification in Open-source Software Supply Chains Based on AIGC

钟浪辉 唐淑艳
微型电脑应用2024,Vol.40Issue(8) :77-80.

基于AIGC的开源软件供应链风险识别

Risk Identification in Open-source Software Supply Chains Based on AIGC

钟浪辉 1唐淑艳2
扫码查看

作者信息

  • 1. 上交所技术有限责任公司,上海 200127
  • 2. 东吴证券股份有限公司,江苏,苏州 215021
  • 折叠

摘要

开源软件作为现代信息产业的核心组成部分,不仅在促进技术共享、降低成本以及提升社会经济效益方面发挥重要作用,而且对信息技术的持续发展产生深远的影响.然而,随着开源软件生态的不断壮大,其供应链关系日趋复杂化,安全风险也随之显著增加.因此,识别和应对开源软件供应链中的风险变得尤为关键.通过文献调研和分析,系统地总结开源软件供应链中各个环节的典型风险点,将生成式人工智能(AIGC)技术应用于这些风险点的识别进行深入分析,为在AI时代开源软件供应链风险管理提供新的视角和方法.

Abstract

As a core component of the modern information industry,open-source software has significantly contributed to tech-nology sharing,cost reduction,and socio-economic benefits,while profoundly influencing the ongoing development of informa-tion technology.However,as the open-source software ecosystem continues to expand,its supply chain relationships have be-come increasingly complex,leading to a notable rise in security risks.Thus,identifying and addressing risks within the open-source software supply chain have become particularly crucial.Through a comprehensive literature review and analysis,this pa-per systematically summarizes the typical risk points at various stages of the open source software supply chain.It also provides an in-depth analysis of how Artificial Intelligence Generated Content(AIGC)technology can be applied to identify these risk points,offering new perspectives and methods for managing risks in the open source software supply chain in the AI era.

关键词

开源软件供应链/风险识别/生成式人工智能

Key words

open-source software supply chain/risk identification/AIGC

引用本文复制引用

基金项目

证券基金行业信息技术应用创新基地2023年行业共研课题(第26号)

出版年

2024
微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
参考文献量1
段落导航相关论文