Security Evaluation Criteria of Open-Source Libraries

被引:0
|
作者
Mills, Vivian [1 ]
Butakov, Sergey [1 ]
机构
[1] Concordia Univ Edmonton, Ada Blvd, Edmonton, AB AB 7128, Canada
关键词
Software security; Risk management; Supply chain attacks; Modern code review; Vulnerability management;
D O I
10.1007/978-3-031-10548-7_31
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The use of freely available, open-source code to reduce the time needed to create new software or add functionality to existing software is a common practice. With analysis of recent high-profile cases of open-source software packages being corrupted by the original developer, or the introduction of remote backdoor functionality by malicious actors, it has been shown that there is much that can be done to help with simplifying the decision-making process of using any open-source code. This paper provides the basis for a simple-to-use checklist that can be used to quickly analyze open-source libraries for its suitability within an individual's or organization's code base. Fourteen projects were selected at random from a popular code hosting site that made use of specific biometric security libraries. The conclusions derived from the use of the checklist and the analysis of the selected projects will help with simplifying the decision-making process of using open-source code for software projects.
引用
收藏
页码:422 / 435
页数:14
相关论文
共 50 条
  • [1] Evaluation of Open-Source Linear Algebra Libraries in Embedded Applications
    Fibich, Christian
    Tauner, Stefan
    Roessler, Peter
    Horauer, Martin
    Krapfenbauer, Markus
    Linauer, Martin
    Matschnig, Martin
    Taucher, Herbert
    2019 8TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2019, : 228 - 233
  • [2] Evaluation of Open-Source IDE Plugins for Detecting Security Vulnerabilities
    Li, Jingyue
    Beba, Sindre
    Karlsen, Magnus Melseth
    PROCEEDINGS OF EASE 2019 - EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, 2019, : 200 - 209
  • [3] PyGlaucoMetrics: An Open-Source Multi-Criteria Glaucoma Defect Evaluation
    Moradi, Mousa
    Eslami, Mohammad
    Hashemabad, Saber Kazeminasab
    Friedman, David S.
    Boland, Michael V.
    Wang, Mengyu
    Elze, Tobias
    Zebardast, Nazlee
    INVESTIGATIVE OPHTHALMOLOGY & VISUAL SCIENCE, 2024, 65 (07)
  • [4] Bitcoin's APIs in Open-Source Projects: Security Usability Evaluation
    Tschannen, Philipp
    Ahmed, Ali
    ELECTRONICS, 2020, 9 (07) : 1 - 36
  • [5] Open-Source MQTT Evaluation
    Bender, Melvin
    Kirdan, Erkin
    Pahl, Marc-Oliver
    Carle, Georg
    2021 IEEE 18TH ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2021,
  • [6] Impact Assessment for Vulnerabilities in Open-Source Software Libraries
    Plate, Henrik
    Ponta, Serena Elisa
    Sabetta, Antonino
    2015 31ST INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME) PROCEEDINGS, 2015, : 411 - 420
  • [7] An Open-Source Cloud Testbed for Security Experimentation
    Minna, Francesco
    Massacci, Fabio
    2022 22ND IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING (CCGRID 2022), 2022, : 756 - 759
  • [8] Top open-source security tools for Unix
    Gaur, Nalneesh
    Unix Review, 1999, 17 (08):
  • [9] Open-Source OPC UA Security and Scalability
    Muehlbauer, Nikolas
    Kirdan, Erkin
    Pahl, Marc-Oliver
    Carle, Georg
    2020 25TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2020, : 262 - 269
  • [10] OSLDetector: Identifying Open-Source Libraries through Binary Analysis
    Zhang, Dan
    Luo, Ping
    Tang, Wei
    Zhou, Min
    2020 35TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE 2020), 2020, : 1312 - 1315