首页> 外文会议>Hawaii International Conference on System Sciences >Increasing software security through open source or closed source development? Empirics suggest that we have asked the wrong question
【24h】

Increasing software security through open source or closed source development? Empirics suggest that we have asked the wrong question

机译:通过开源或封闭来源开发增加软件安全性?经验证明我们已经问过错误的问题

获取原文

摘要

While many theoretical arguments against or in favor of open source and closed source software development have been presented, the empirical basis for the assessment of arguments and the development of models is still weak. Addressing this research gap, this paper presents the first comprehensive empirical investigation of published vulnerabilities and patches of 17 widely deployed open source and closed source software packages, including operating systems, database systems, web browsers, email clients, and office systems. The empirical analysis uses comprehensive vulnerability data contained in the NIST National Vulnerability Database and a newly compiled data set of vulnerability patches. The results suggest that it is not the particular software development style that determines the severity of vulnerabilities and vendors' patching behavior, but rather the specific application type and the policy of the particular development community, respectively.
机译:虽然已经提出了对抗或有利于开源和封闭来源软件开发的许多理论论点,但评估论证和模型的发展的实证基础仍然薄弱。解决这一研究差距,本文提出了发表的发布漏洞和17个广泛部署的开源和封闭源软件包的漏洞和补丁的第一个全面的实证调查,包括操作系统,数据库系统,Web浏览器,电子邮件客户端和办公系统。实证分析使用NIST国家漏洞数据库中包含的全面漏洞数据和新编译的漏洞修补程序集。结果表明它不是特定的软件开发方式,可以分别确定漏洞和供应商的修补行为的严重性,而是分别是特定的应用程序类型和特定开发社区的策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号