Modern vehicles are integral components of our daily lives, crucial for transportation and logistics. As such, ensuring cybersecurity in embedded vehicle systems is essential. Software Bills of Materials (SBOMs) are increasingly recognized as a valuable tool for enhancing software supply chain security. By providing transparency and traceability of software components, SBOMs facilitate the rapid identification and mitigation of vulnerabilities. Despite their benefits, implementing SBOMs for embedded vehicle systems presents unique challenges. This study investigates the challenges involved in the management of SBOMs for embedded vehicle systems, particularly focusing on a custom Yocto Linux distribution for a diagnostic platform in heavy-duty trucks. We highlight key issues and propose potential solutions. Our findings underscore the necessity for specialized tools and frameworks to effectively integrate SBOMs in embedded systems, thereby strengthening the cybersecurity posture of these critical systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Short Paper: Software Bill of Materials Management for Embedded Vehicle Systems

  • Teddy Nyambe,
  • Rik Chatterjee,
  • Jeremy Daily

摘要

Modern vehicles are integral components of our daily lives, crucial for transportation and logistics. As such, ensuring cybersecurity in embedded vehicle systems is essential. Software Bills of Materials (SBOMs) are increasingly recognized as a valuable tool for enhancing software supply chain security. By providing transparency and traceability of software components, SBOMs facilitate the rapid identification and mitigation of vulnerabilities. Despite their benefits, implementing SBOMs for embedded vehicle systems presents unique challenges. This study investigates the challenges involved in the management of SBOMs for embedded vehicle systems, particularly focusing on a custom Yocto Linux distribution for a diagnostic platform in heavy-duty trucks. We highlight key issues and propose potential solutions. Our findings underscore the necessity for specialized tools and frameworks to effectively integrate SBOMs in embedded systems, thereby strengthening the cybersecurity posture of these critical systems.