首页> 外文会议>Conference of Open Innovations Association >Software security in open source development: A systematic literature review
【24h】

Software security in open source development: A systematic literature review

机译:开源开发中的软件安全性:系统文献综述

获取原文

摘要

Despite the security community's emphasis on the importance of building secure open source software (OSS), the number of new vulnerabilities found in OSS is increasing. In addition, software security is about the people that develop and use those applications and how their vulnerable behaviors can lead to exploitation. This leads to a need for reiteration of software security studies for OSS developments to understand the existing security practices and the security weakness among them. In this paper, a systematic review method with a sociotechnical analysis approach is applied to identify, extract and analyze the security studies conducted in the context of open source development. The findings include: (1) System verification is the most cited security area in OSS research; (2) The socio-technical perspective has not gained much attention in this research area; and (3) No research has been conducted focusing on the aspects of security knowledge management in OSS development.
机译:尽管安全社区强调构建安全开源软件(OSS)的重要性,但是OSS中发现的新漏洞的数量正在增加。此外,软件安全性涉及开发和使用这些应用程序的人员,以及他们的易受攻击的行为如何导致利用。这导致需要针对OSS开发重申软件安全性研究,以了解现有的安全性实践及其间的安全性弱点。本文采用一种具有社会技术分析方法的系统评价方法来识别,提取和分析在开源开发环境下进行的安全性研究。研究结果包括:(1)系统验证是OSS研究中引用最多的安全领域; (2)在这个研究领域中,社会技术的观点没有引起足够的重视; (3)尚未针对OSS开发中的安全知识管理方面进行任何研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号