New Article in heise iX magazine by key researcher Constanze Roedig
Constanze Roedig, key researcher at SBA Research, published an insightful article titled Software Supply Chain: “Bill of Behavior” as a Package Insert for Containers in heise magazine iX.
© Constanze Roedig
The article highlights the importance of research-driven approaches to cybersecurity and shows how innovative concepts can help address emerging challenges in modern software infrastructures:
- The Software Bill of Behavior (SBoB) complements the “ingredient list” provided by the Software Bill of Materials (SBOM) by describing software’s runtime behavior in Linux environments.
- For operators and manufacturers, the SBoB can help simplify compliance with European regulations such as the Cyber Resilience Act (CRA), the NIS2 Directive, and DORA.
- A reference implementation for the CNCF project Kubescape demonstrates how an SBoB can use eBPF to enable real-time detection of anomalies such as DNS spoofing, typosquatting, and exploits.
- The SBoB can provide a scalable approach to better detecting and classifying attacks that do not have a traditional CVE assignment.
Through her research, Constanze Roedig contributes to advancing software supply chain security and cybersecurity in Austria and to developing innovative approaches for secure digital infrastructures. Her work underlines the role of research and collaboration in building more trustworthy software ecosystems, from the initial stages of development through to deployment and runtime.
