首页|基于AIGC的开源软件供应链风险识别

基于AIGC的开源软件供应链风险识别

扫码查看
开源软件作为现代信息产业的核心组成部分,不仅在促进技术共享、降低成本以及提升社会经济效益方面发挥重要作用,而且对信息技术的持续发展产生深远的影响.然而,随着开源软件生态的不断壮大,其供应链关系日趋复杂化,安全风险也随之显著增加.因此,识别和应对开源软件供应链中的风险变得尤为关键.通过文献调研和分析,系统地总结开源软件供应链中各个环节的典型风险点,将生成式人工智能(AIGC)技术应用于这些风险点的识别进行深入分析,为在AI时代开源软件供应链风险管理提供新的视角和方法.
Risk Identification in Open-source Software Supply Chains Based on AIGC
As a core component of the modern information industry,open-source software has significantly contributed to tech-nology sharing,cost reduction,and socio-economic benefits,while profoundly influencing the ongoing development of informa-tion technology.However,as the open-source software ecosystem continues to expand,its supply chain relationships have be-come increasingly complex,leading to a notable rise in security risks.Thus,identifying and addressing risks within the open-source software supply chain have become particularly crucial.Through a comprehensive literature review and analysis,this pa-per systematically summarizes the typical risk points at various stages of the open source software supply chain.It also provides an in-depth analysis of how Artificial Intelligence Generated Content(AIGC)technology can be applied to identify these risk points,offering new perspectives and methods for managing risks in the open source software supply chain in the AI era.

open-source software supply chainrisk identificationAIGC

钟浪辉、唐淑艳

展开 >

上交所技术有限责任公司,上海 200127

东吴证券股份有限公司,江苏,苏州 215021

开源软件供应链 风险识别 生成式人工智能

证券基金行业信息技术应用创新基地2023年行业共研课题

第26号

2024

微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
年,卷(期):2024.40(8)
  • 1