UGC Approved Journal no 63975(19)
New UGC Peer-Reviewed Rules

ISSN: 2349-5162 | ESTD Year : 2014
Volume 13 | Issue 9 | September 2026

JETIREXPLORE- Search Thousands of research papers



WhatsApp Contact
Click Here

Published in:

Volume 13 Issue 9
September-2026
eISSN: 2349-5162

UGC and ISSN approved 7.95 impact factor UGC Approved Journal no 63975

7.95 impact factor calculated by Google scholar

Unique Identifier

Published Paper ID:
JETIR2609307


Registration ID:
586335

Page Number

d52-d59

Share This Article


Jetir RMS

Title

Moving Beyond Static Inventories: AST-Based Vulnerability Reachability Analysis for Software Supply Chain Security

Abstract

Modern software applications increasingly rely on third-party and open-source software components, making software supply chain security an important area of cybersecurity. Software Bill of Materials (SBOM) and dependency-based vulnerability management tools are commonly used to identify software components and match them with known vulnerabilities. However, traditional approaches primarily focus on determining whether a vulnerable component and version are present within an application. The presence of a vulnerable library does not necessarily indicate that the vulnerable functionality is actually used or reachable by the application. This research proposes an AST-Based Vulnerability Reachability Analysis approach to provide additional context for software supply chain vulnerability management. The proposed system combines dependency and SBOM information with Abstract Syntax Tree (AST)-based source code analysis. The system identifies third-party components and associated vulnerability information, analyzes Python source code to extract imported libraries, function calls, and API calls, and compares detected calls with known vulnerable APIs. Based on this comparison, vulnerabilities are classified as reachable or unreachable within the scope of the analyses source code. Reachable vulnerabilities are assigned higher priority, while vulnerabilities for which the mapped vulnerable API is not detected are assigned lower priority.

Key Words

Software Supply Chain Security, Software Bill of Materials (SBOM), Abstract Syntax Tree (AST), Vulnerability Reachability, CVE, Vulnerability Management, Static Analysis, Vulnerability Prioritization

Cite This Article

"Moving Beyond Static Inventories: AST-Based Vulnerability Reachability Analysis for Software Supply Chain Security", International Journal of Emerging Technologies and Innovative Research (www.jetir.org), ISSN:2349-5162, Vol.13, Issue 9, page no.d52-d59, September-2026, Available :http://www.jetir.org/papers/JETIR2609307.pdf

ISSN


2349-5162 | Impact Factor 7.95 Calculate by Google Scholar

An International Scholarly Open Access Journal, Peer-Reviewed, Refereed Journal Impact Factor 7.95 Calculate by Google Scholar and Semantic Scholar | AI-Powered Research Tool, Multidisciplinary, Monthly, Multilanguage Journal Indexing in All Major Database & Metadata, Citation Generator

Cite This Article

"Moving Beyond Static Inventories: AST-Based Vulnerability Reachability Analysis for Software Supply Chain Security", International Journal of Emerging Technologies and Innovative Research (www.jetir.org | UGC and issn Approved), ISSN:2349-5162, Vol.13, Issue 9, page no. ppd52-d59, September-2026, Available at : http://www.jetir.org/papers/JETIR2609307.pdf

Publication Details

Published Paper ID: JETIR2609307
Registration ID: 586335
Published In: Volume 13 | Issue 9 | Year September-2026
DOI (Digital Object Identifier):
Page No: d52-d59
Country: Thane, Maharashtra, India .
Area: Science & Technology
ISSN Number: 2349-5162
Publisher: IJ Publication


Preview This Article


Downlaod

Click here for Article Preview

Download PDF

Downloads

0007

Print This Page

Current Call For Paper

Jetir RMS