On the Security Cost of Using a Free and Open Source Component in a Proprietary Product.

ESSoS(2016)

引用 9|浏览84
暂无评分
摘要
The work presented in this paper is motivated by the need to estimate the security effort of consuming Free and Open Source Software FOSS components within a proprietary software supply chain of a large European software vendor. To this extent we have identified three different cost models: centralized the company checks each component and propagates changes to the different product groups, distributed each product group is in charge of evaluating and fixing its consumed FOSS components, and hybrid only the least used components are checked individually by each development team. We investigated publicly available factors e.﾿g., development activity such as commits, code size, or fraction of code size in different programming languages to identify which one has the major impact on the security effort of using a FOSS component in a larger software product.
更多
查看译文
关键词
Free and open source software usage, Free and open source software vulnerabilities, Security maintenance costs
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要