首页> 外文会议>Association for Computing Machinery Conference on Computer and Communications Security >Secure Open Source Collaboration An Empirical Study of Linus' Law
【24h】

Secure Open Source Collaboration An Empirical Study of Linus' Law

机译:安全开源合作Linus法律的实证研究

获取原文

摘要

Open source software is often considered to be secure. One factor in this confidence in the security of open source software lies in leveraging large developer communities to find vulnerabilities in the code. Eric Raymond declares Linus' Law "Given enough eyeballs, all bugs are shallow." Does Linus' Law hold up ad infinitum? Or, can the multitude of developers become "too many cooks in the kitchen", causing the system's security to suffer as a result? In this study, we examine the security of an open source project in the context of developer collaboration. By analyzing version control logs, we quantified notions of Linus' Law as well as the "too many cooks in the kitchen" viewpoint into developer activity metrics. We performed an empirical case study by examining correlations between the known security vulnerabilities in the open source Red Hat Enterprise Linux 4 kernel and developer activity metrics. Files developed by otherwise-independent developer groups were more likely to have a vulnerability, supporting Linus' Law. However, files with changes from nine or more developers were 16 times more likely to have a vulnerability than files changed by fewer than nine developers, indicating that many developers changing code may have a detrimental effect on the system's security. Categories and Subject Descriptors
机译:开源软件通常被认为是安全的。对开源软件安全性的这种信心的一个因素在于利用大型开发人员社区来查找代码中的漏洞。 Eric Raymond宣称Linus的法律“给予足够的眼球,所有的虫子都很浅。” Linus的法律是否持有AD Infinitum?或者,众多的开发人员可以成为“厨房里过多的厨师”,导致系统的安全性受到影响?在这项研究中,我们在开发人员协作的背景下检查开源项目的安全性。通过分析版本控制日志,我们量化了Linus Law的概念以及厨房中的太多厨师“观点进入开发人员活动指标。我们通过检查开源Red Hat Enterprise Linux 4内核和开发人员活动指标中已知的安全漏洞之间的相关性进行了实证案例研究。由其他独立的开发人员组开发的文件更有可能具有漏洞,支持Linus的法律。但是,来自九个或更多开发人员的更改的文件比较少于九个开发人员的更改,这是一个漏洞的可能性比更改的文件更少16倍,这表明许多开发人员更改代码可能对系统的安全性有不利影响。类别和主题描述符

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号