THCON 2025 — Software Bill of Materials

THCON 2025 — Vulnerability tracking of offline systems using SBOM

Featured image

A Look Back at THCON 2025: Tracking Offline Vulnerabilities Using SBOMs

In April 2025, I had the pleasure of taking the stage at THCON alongside Benoît Guillon (Viveris) to present a talk on securing the software supply chain in constrained environments.

Our presentation, titled “Software Bill of Materials: Vulnerability tracking of offline systems using SBOM,” highlighted a major challenge for critical industries: how to maintain an accurate map of software vulnerabilities when systems are completely isolated from the Internet (offline)?

💡 Context and Challenge

In the space sector and critical infrastructure industries, many projects run on disconnected systems for obvious security reasons. Tracking vulnerabilities (CVEs) for these products quickly becomes a major headache.

Before industrializing our approach, we relied on an internal Proof of Concept (PoC) solution. While useful, it had significant limitations:

🛠️ Our Solution: Automation via SBOM

The goal of our presentation was to demonstrate how adopting SBOMs (Software Bill of Materials), combined with a suitable vulnerability management tool, can completely flip this paradigm.

We shared insights from implementing a workflow that enables us to:

  1. Generate a comprehensive SBOM (the “list of ingredients” for our software), including all dependencies and component sources.
  2. Automate end-to-end analysis, eliminating error-prone manual interventions.
  3. Operate entirely offline, ensuring the sovereignty and security of our project data.

The result? A dynamic, visual, and instant map of a project’s security status at any given moment, without ever opening an external data connection.