{"id":"https://openalex.org/W4400976823","doi":"https://doi.org/10.1145/3664476.3669975","title":"SBOM Ouverture: What We Need and What We Have","display_name":"SBOM Ouverture: What We Need and What We Have","publication_year":2024,"publication_date":"2024-07-25","ids":{"openalex":"https://openalex.org/W4400976823","doi":"https://doi.org/10.1145/3664476.3669975"},"language":"en","primary_location":{"id":"doi:10.1145/3664476.3669975","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3664476.3669975","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3664476.3669975","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5105094249","display_name":"Gregorio Dalia","orcid":null},"institutions":[{"id":"https://openalex.org/I16337185","display_name":"University of Sannio","ror":"https://ror.org/04vc81p87","country_code":"IT","type":"education","lineage":["https://openalex.org/I16337185"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Gregorio Dalia","raw_affiliation_strings":["University of Sannio, Italy"],"affiliations":[{"raw_affiliation_string":"University of Sannio, Italy","institution_ids":["https://openalex.org/I16337185"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048951071","display_name":"Corrado Aaron Visaggio","orcid":"https://orcid.org/0000-0002-0558-4450"},"institutions":[{"id":"https://openalex.org/I16337185","display_name":"University of Sannio","ror":"https://ror.org/04vc81p87","country_code":"IT","type":"education","lineage":["https://openalex.org/I16337185"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Corrado Aaron Visaggio","raw_affiliation_strings":["University of Sannio, Italy"],"affiliations":[{"raw_affiliation_string":"University of Sannio, Italy","institution_ids":["https://openalex.org/I16337185"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043960445","display_name":"Andrea Di Sorbo","orcid":"https://orcid.org/0000-0002-3192-739X"},"institutions":[{"id":"https://openalex.org/I16337185","display_name":"University of Sannio","ror":"https://ror.org/04vc81p87","country_code":"IT","type":"education","lineage":["https://openalex.org/I16337185"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Andrea Di Sorbo","raw_affiliation_strings":["University of Sannio, Italy"],"affiliations":[{"raw_affiliation_string":"University of Sannio, Italy","institution_ids":["https://openalex.org/I16337185"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5006915371","display_name":"Gerardo Canfora","orcid":"https://orcid.org/0000-0003-0049-1279"},"institutions":[{"id":"https://openalex.org/I16337185","display_name":"University of Sannio","ror":"https://ror.org/04vc81p87","country_code":"IT","type":"education","lineage":["https://openalex.org/I16337185"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Gerardo Canfora","raw_affiliation_strings":["University of Sannio, Italy"],"affiliations":[{"raw_affiliation_string":"University of Sannio, Italy","institution_ids":["https://openalex.org/I16337185"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5105094249"],"corresponding_institution_ids":["https://openalex.org/I16337185"],"apc_list":null,"apc_paid":null,"fwci":3.7072,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.94235801,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11675","display_name":"Open Source Software Innovations","score":0.9736999869346619,"subfield":{"id":"https://openalex.org/subfields/1706","display_name":"Computer Science Applications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11675","display_name":"Open Source Software Innovations","score":0.9736999869346619,"subfield":{"id":"https://openalex.org/subfields/1706","display_name":"Computer Science Applications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10430","display_name":"Software Engineering Techniques and Practices","score":0.9714999794960022,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T14147","display_name":"Innovative Approaches in Technology and Social Development","score":0.953000009059906,"subfield":{"id":"https://openalex.org/subfields/1405","display_name":"Management of Technology and Innovation"},"field":{"id":"https://openalex.org/fields/14","display_name":"Business, Management and Accounting"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5996863842010498}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5996863842010498}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3664476.3669975","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3664476.3669975","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3664476.3669975","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3664476.3669975","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":13,"referenced_works":["https://openalex.org/W3177301840","https://openalex.org/W3198845576","https://openalex.org/W4226410005","https://openalex.org/W4296949995","https://openalex.org/W4297648349","https://openalex.org/W4313563522","https://openalex.org/W4362704894","https://openalex.org/W4365505517","https://openalex.org/W4384345766","https://openalex.org/W4385208592","https://openalex.org/W4386977908","https://openalex.org/W4389544232","https://openalex.org/W4405098043"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052","https://openalex.org/W2382290278","https://openalex.org/W4395014643"],"abstract_inverted_index":{"A":[0],"Software":[1],"Bill":[2],"of":[3,9,31,49,57,86,130],"Materials":[4],"(SBOM)":[5],"is":[6],"an":[7,42],"inventory":[8],"the":[10,26,38,47,50,55,58,63,84,92,97,110,117,131,139],"software":[11,51,60,87],"components":[12],"used":[13],"to":[14,45,72,75,79,99,113,134],"build":[15],"a":[16,127],"product,":[17],"which":[18],"can":[19],"help":[20,76,91],"customers":[21],"track":[22],"security":[23,48,85],"risks":[24,81],"throughout":[25],"development":[27],"lifecycle.":[28],"The":[29],"popularity":[30],"SBOMs":[32],"grew":[33],"in":[34,66,103,105],"May":[35],"2021":[36],"when":[37],"White":[39],"House":[40],"issued":[41],"executive":[43],"order":[44],"improve":[46],"supply":[52,88],"chain":[53],"and":[54,82,94,116,148],"transparency":[56],"government\u2019s":[59],"inventory.":[61],"Although":[62],"growing":[64],"interest":[65],"SBOM,":[67],"many":[68],"open":[69,118],"challenges":[70,111],"need":[71],"be":[73],"addressed":[74],"reduce":[77],"exposure":[78],"cyber":[80],"enhance":[83],"chains.":[89],"To":[90],"industry":[93],"research":[95,121],"assemble":[96],"roadmap":[98],"achieve":[100],"SBOM":[101],"adoption":[102],"practice,":[104],"this":[106],"paper,":[107],"we":[108,125],"analyze":[109],"related":[112],"enabling":[114,140],"technologies":[115,141],"issues":[119],"that":[120,138],"must":[122],"investigate.":[123],"Furthermore,":[124],"perform":[126],"comparative":[128],"analysis":[129],"existing":[132],"tools":[133],"generate":[135],"SBOMs,":[136],"demonstrating":[137],"have":[142],"not":[143],"yet":[144],"reached":[145],"full":[146],"automation":[147],"maturity.":[149]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":7}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
