Author
Listed:
- Bamidele Samuel Adelusi
- Abel Chukwuemeke Uzoka
- Yewande Goodness Hassan
- Favour Uche Ojika
Abstract
As the software supply chain becomes increasingly decentralized, ensuring the integrity and security of software components has become a critical priority. This paper presents a blockchain-integrated Software Bill of Materials (SBOM) framework designed to facilitate real-time vulnerability detection across decentralized package repositories. By leveraging blockchain’s immutable ledger and decentralized consensus mechanisms, the proposed solution enhances transparency, automates component verification, and provides a tamper-resistant audit trail for all software artifacts. The architecture incorporates smart contracts to enable automatic alerts for security vulnerabilities, expired components, and compliance violations based on real-time threat intelligence and CVE databases. A layered design approach is employed, incorporating system modeling, integration strategies, and a performance assessment conducted through simulation of real-world distributed repositories. Evaluation metrics include latency reduction, detection accuracy, and scalability under distributed workloads. This framework aligns with emerging software supply chain security mandates, including SBOM adoption in accordance with global cybersecurity policies. By synthesizing contributions from over 80 peer-reviewed studies between 2019 and 2023, the paper offers a comprehensive and future-proof strategy for enhancing the trustworthiness of software ecosystems in decentralized environments.
Suggested Citation
Bamidele Samuel Adelusi & Abel Chukwuemeke Uzoka & Yewande Goodness Hassan & Favour Uche Ojika, 2023.
"Blockchain-Integrated Software Bill of Materials (SBOM) for Real-Time Vulnerability Detection in Decentralized Package Repositories,"
Int J Sci Res Civil Engg, International Journal of Scientific Research in Civil Engineering, vol. 7(3), pages 102-116, June.
Handle:
RePEc:jcq:ijsrce:v7:y2023:i3:id:656
DOI: 10.32628/IJSRCE237314
Note: Article URL: https://ijsrce.com/home/article/view/IJSRCE237314
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:jcq:ijsrce:v7:y2023:i3:id:656. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Pankaj Sharma (email available below). General contact details of provider: https://ijsrce.com/home .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.