SBOM-BASED VULNERABILITY PRIORITIZATION IN SOFTWARE SUPPLY CHAIN USING MACHINE LEARNING

Authors

  • Denys SHTOMA, Student Taras Shevchenko National University of Kyiv, Kyiv, Ukraine Author
  • Volodymyr PETRIVSKYI, PhD Taras Shevchenko National University of Kyiv, Kyiv, Ukraine Author

DOI:

https://doi.org/10.17721/AIT.2025.2.04

Keywords:

software supply chain, SBOM, vulnerability prioritization, machine learning, DevSecOps, CVSS, EPSS.

Abstract

The article is presented in the OnlineFirst format, which involves early posting of materials on the journal website before their final printing in paper form.

The article has passed the review procedure and has been accepted for publication.

The article is available for search and citation by its DOI, which remains unchanged. After the issue is printed in the printing house, a new citation can be made using information about the volume number and page number, using the same DOI reference.

Background. Modern software systems heavily rely on open-source components, creating complex software supply chains. Regulatory requirements, including Executive Order 14028, NIST standards, and the EU Cyber Resilience Act, mandate organizations to use Software Bill of Materials (SBOM) for dependency transparency. However, the number of identified CVE vulnerabilities far exceeds security team remediation capabilities, and traditional CVSS-based sorting does not account for actual exploitation probability. Critical incidents such as Log4Shell demonstrate the need for automated vulnerability prioritization systems.

Methods. Building SBOM in CycloneDX format for target applications with component correlation to National Vulnerability Database and CISA Known Exploited Vulnerabilities catalog. Feature set formation based on Common Vulnerability Scoring System metrics, vulnerability age, exploit presence, and SBOM context. LambdaMART machine learning model based on LightGBM Ranker is applied for vulnerability ranking by expected risk reduction. The problem is formulated as an optimization task with patching budget constraints.

Results. Comparison with baseline strategies (CVSS sorting, EPSS sorting, and their combinations) demonstrated that the proposed machine learning approach covers a larger proportion of actually exploited vulnerabilities with a fixed patch budget. The model shows a 23% increase in NDCG@10 metric and a 31% increase in KEV vulnerability coverage in top-10 compared to CVSS baseline.

Сonclusions. The proposed framework enables SBOM and exploitability assessment integration into DevSecOps processes. Problem formalization as optimization and learning-to-rank model application provides measurable advantage in focusing efforts on the most critical vulnerabilities.

Downloads

Download data is not yet available.

Author Biographies

  • Denys SHTOMA, Student, Taras Shevchenko National University of Kyiv, Kyiv, Ukraine

    ORCID ID: 0009-0009-8942-3088

  • Volodymyr PETRIVSKYI, PhD, Taras Shevchenko National University of Kyiv, Kyiv, Ukraine

    ORCID ID: 0000-0001-9298-8244

References

Burges, C. J. C. (2010). From RankNet to LambdaRank to LambdaMART: An overview (Technical Report MSR-TR-2010-82). Microsoft Research.

Cybersecurity and Infrastructure Security Agency. (n.d.). Known exploited vulnerabilities catalog. https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Biden, J. R., Jr. (2021, May 17). Executive Order 14028 – Improving the nation’s cybersecurity. Federal Register, 86(93), 26633–26647. https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity

Jacobs, J., Romanosky, S., Edwards, B., Roytman, M., & Adjerid, I. (2019). Exploit prediction scoring system (EPSS). arXiv. https://doi.org/10.48550/arXiv.1908.04856

Jacobs, J., Romanosky, S., Adjerid, I., & Baker, W. (2020). Improving vulnerability remediation through better exploit prediction. Journal of Cybersecurity, 6(1), tyaa015. https://doi.org/10.1093/cybsec/tyaa015

Ke, G., Meng, Q., Finley, T., Wang, T., Chen, W., Ma, W., Ye, Q., & Liu, T.-Y. (2017). LightGBM: A highly efficient gradient boosting decision tree. In I. Guyon, U. von Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, & R. Garnett (Eds.), Advances in Neural Information Processing Systems (Vol. 30, pp. 3149–3157). Curran Associates, Inc. https://proceedings.neurips.cc/paper_files/paper/2017/hash/6449f44a102fde848669bdd9eb6b76fa-Abstract.html

Ladisa, P., Plate, H., Martinez, M., & Barais, O. (2023). SoK: Taxonomy of attacks on open-source software supply chains. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP) (pp. 1509–1526). IEEE. https://doi.org/10.1109/SP46215.2023.10179304

Le, T. H. M., Chen, H., & Babar, M. A. (2022). A survey on data-driven software vulnerability assessment and prioritization. ACM Computing Surveys, 55(5), Article 100, 1–39. https://doi.org/10.1145/3529757

O’Donoghue, E., Boles, B., Izurieta, C., & Reinhold, A. M. (2024). Impacts of software bill of materials (SBOM) generation on vulnerability detection. In Proceedings of the 2024 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED ’24) (pp. 67–76). Association for Computing Machinery. https://doi.org/10.1145/3689944.3696164

O’Donoghue, E., Hastings, Y., Ortiz, E., & Manzi Muneza, A. R. (2025). Software bill of materials in software supply chain security: A systematic literature review. arXiv. https://doi.org/10.48550/arXiv.2506.03507

Stalnaker, T., Wintersgill, N., Chaparro, O., Di Penta, M., German, D. M., & Poshyvanyk, D. (2024). BOMs away! Inside the minds of stakeholders: A comprehensive study of bills of materials for software systems. In Proceedings of the IEEE/ACM 46th International Conference on Software Engineering (ICSE ’24) (pp. 517–529). Association for Computing Machinery. https://doi.org/10.1145/3597503.3623347

Synopsys. (2024). Open Source Security and Risk Analysis Report 2024. https://www.synopsys.com/software-integrity/resources/analyst-reports/open-source-security-risk-analysis.html

Williams, L., Benedetti, G., Hamer, S., Paramitha, R., Rahman, I., Tamanna, M., Tystahl, G., Zahan, N., Morrison, P., Acar, Y., Cukier, M., Kästner, C., Kapravelos, A., Wermke, D., & Enck, W. (2025). Research directions in software supply chain security. ACM Transactions on Software Engineering and Methodology, 34(5), Article 146, 1–38. https://doi.org/10.1145/3714464

Wirth, A. (2022). Log jam: Lesson learned from the Log4Shell vulnerability. Biomedical Instrumentation & Technology, 56(3), 72–76. https://doi.org/10.2345/0899-8205-56.3.72

Published

2026-05-06

Issue

Section

Artificial and computational intelligence

How to Cite

SBOM-BASED VULNERABILITY PRIORITIZATION IN SOFTWARE SUPPLY CHAIN USING MACHINE LEARNING. (2026). Advanced Information Technology, 1(2(5). https://doi.org/10.17721/AIT.2025.2.04