首页> 外文会议>International Conference on Security for Information Technology and Communications >Security Knowledge Management in Open Source Software Communities
【24h】

Security Knowledge Management in Open Source Software Communities

机译:开源软件社区中的安全知识管理

获取原文

摘要

Open source software (OSS) communities are groups of individuals, technical or non-technical, interacting with collaborating peers in online communities of practices to develop OSS, solve particular software problems and exchange ideas. People join OSS communities with a different level of programming skills and experience and might lack formal, college-level software security training. There remains a lot of confusion in participants' mind as to what is secured code and what the project wants. Another problem is that the huge amount of available software security information nowadays has resulted in a form of information overload to software engineers, who usually finish studying it with no clue about how to apply those principles properly to their own applications. This leads to a knowledge gap between knowledge available and knowledge required to build secure applications in the context of software projects. Given the increased importance and complexity of OSS in today's world, lacking proper security knowledge to handle vulnerabilities in OSS development will result in breaches that are more serious in the future. The goal of this research work is to fill the knowledge gap by providing an artifact that would facilitate the effective security-knowledge transferring and learning in the context of OSS development. In this work-in-progress paper, we present our ongoing research work following design science research methodology on the domain problem identification and the development of the artifact.
机译:开源软件(OSS)社区是个人,技术或非技术群体,与在线社区的合作同行互动,以开发OSS,解决特定软件问题和交换思想。人们加入OSS社区,具有不同的编程技巧和经验,可能缺乏正式的大学软件安全培训。参与者的思想仍然存在很大的困惑,即如何获得守则和项目想要的东西。另一个问题是,现在的大量可用软件安全信息已经为软件工程师产生了一种信息过载,他们通常完成学习它没有关于如何正确应用这些原则的线索。这导致知识与在软件项目的上下文中建立安全应用所需的知识和知识之间的知识差距。鉴于当今世界中OS的重要性和复杂性增加,缺乏适当的安全知识来处理OSS开发中的漏洞将导致未来更严重的违规行为。这项研究工作的目标是通过提供一个工件来填补知识差距,这将促进在OSS开发的背景下有效的安全知识转移和学习。在这份工作论文中,我们在设计科学研究方法上展示了我们正在进行的研究工作,在域问题识别和伪影的发展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号