首页> 外文会议>Americas conference on information systems;AMCIS 2009 >Security of open source and closed source software: An empirical comparison of published vulnerabilities
【24h】

Security of open source and closed source software: An empirical comparison of published vulnerabilities

机译:开源软件和闭源软件的安全性:已发布漏洞的经验比较

获取原文

摘要

Reviewing literature on open source and closed source security reveals that the discussion is often determined by biased attitudes toward one of these development styles. The discussion specifically lacks appropriate metrics, methodology and hard data. This paper contributes to solving this problem by analyzing and comparing published vulnerabilities of eight open source software and nine closed source software packages, all of which are widely deployed. It provides an extensive empirical analysis of vulnerabilities in terms of the mean time between vulnerability disclosures, the development of disclosure over time, and the severity of vulnerabilities, and allows for validating models provided in the literature. The investigation reveals that (a) the mean time between vulnerability disclosures was lower for open source software in half of the cases, while the other cases showed no differences, (b) 14 out of 17 software packages showed a significant linear or piecewise linear correlation between the time and the number of published vulnerabilities, and (c) no significant differences in the severity of vulnerabilities were found between open source and closed source software.
机译:回顾有关开放源代码和封闭源代码安全性的文献后发现,讨论通常是由对这些开发风格之一的偏见所决定的。讨论特别缺乏适当的指标,方法和硬数据。本文通过分析和比较已广泛部署的八个开放源代码软件和九个封闭源代码软件包的已发布漏洞,为解决此问题做出了贡献。它根据漏洞披露之间的平均时间,随着时间的推移披露的发展以及漏洞的严重性,对漏洞进行了广泛的经验分析,并允许验证文献中提供的模型。调查显示(a)在一半的情况下,开源软件漏洞披露的平均时间较短,而其他案例则没有差异,(b)17个软件包中的14个显示出显着的线性或分段线性相关性时间与已发布漏洞的数量之间的关系;以及(c)在开源软件和闭源软件之间未发现漏洞的严重程度有显着差异。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号