What You See Is Not What You Execute: Memory-Based Runtime SBOM Generation for Supply Chain Security
Summary
This research paper proposes a method for creating an accurate software inventory by analyzing what a program actually does in memory at runtime, rather than relying on static files. This approach helps detect supply chain attacks (where malicious code enters software through its dependencies) by catching discrepancies between what the software claims to contain and what it really executes.
Classification
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.sciencedirect.com/science/article/pii/S0167404826003019?dgcid=rss_sd_all
First tracked: September 26, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 72%