Dashevskyi, S., Brucker, A.D. and Massacci, F. (2016) On the Security Cost of Using a Free and Open Source Component in a Proprietary Product. In: Caballero, J., Bodden, E. and Athanasopoulos, E., (eds.) Engineering Secure Software and Systems. ESSoS, 06-08 Apr 2016, London, UK. Lecture Notes in Computer Science (9639 ). Springer Verlag (Germany) , pp. 190-206. ISBN 978-3-642-11746-6
Abstract
The work presented in this paper is motivated by the need to estimate the security effort of consuming Free and Open Source Software (FOSS) components within a proprietary software supply chain of a large European software vendor. To this extent we have identified three different cost models: centralized (the company checks each component and propagates changes to the different product groups), distributed (each product group is in charge of evaluating and fixing its consumed FOSS components), and hybrid (only the least used components are checked individually by each development team). We investigated publicly available factors (\eg, development activity such as commits, code size, or fraction of code size in different programming languages) to identify which one has the major impact on the security effort of using a FOSS component in a larger software product.
Metadata
Item Type: | Proceedings Paper |
---|---|
Authors/Creators: |
|
Editors: |
|
Copyright, Publisher and Additional Information: | © 2016 Springer International Publishing Switzerland. This is an author produced version of a paper subsequently published in Lecture Notes in Computer Science. Uploaded in accordance with the publisher's self-archiving policy. |
Dates: |
|
Institution: | The University of Sheffield |
Academic Units: | The University of Sheffield > Faculty of Engineering (Sheffield) > Department of Computer Science (Sheffield) |
Depositing User: | Symplectic Sheffield |
Date Deposited: | 01 Jun 2016 14:00 |
Last Modified: | 16 Apr 2017 15:43 |
Published Version: | http://dx.doi.org/10.1007/978-3-319-30806-7_12 |
Status: | Published |
Publisher: | Springer Verlag (Germany) |
Series Name: | Lecture Notes in Computer Science |
Refereed: | Yes |
Identification Number: | 10.1007/978-3-319-30806-7_12 |
Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:95555 |