Industry-Wide Analysis of Open Source Security.

Yiming Zhang,Baljeet Malhotra,Cheng Chen
DOI: https://doi.org/10.1109/pst.2018.8514185
2018-01-01
Abstract:Open Source Software (OSS) has become de-facto industry standard for developing software solutions and services. Either it's Telecommunication industry or Aerospace or Health Care or Media and Entertainment, OSS is widely used because of its benefits and community based support. Regardless of the benefits, OSS continues to attract security vulnerabilities due to its inherent open nature. Because of the security vulnerabilities industries need to constantly evaluate security posture of OSS projects. Unfortunately, there are no readily available studies that have analyzed the security posture of various OSS projects with respect to various industries. This is the precise goal of this research, which not only analyzes the popularity of various OSS projects among various industries but also provides insights into the security vulnerabilities and their impact on various industries that consume those OSS projects. Toward that end this paper makes the following contributions. (1) We evaluated the OSS usage trends across various categories of industries, which has never been attempted before. (2) We proposed two metrics to quantify the impact of security vulnerabilities in OSS projects that are used by various categories of industries. (3) We conducted a detailed set of analysis using real datasets to evaluate the proposed metrics and their impact on various industries. We have concluded this paper with some future
What problem does this paper attempt to address?