Security Evaluation Criteria of Open-Source Libraries

被引:0
|
作者
Mills, Vivian [1 ]
Butakov, Sergey [1 ]
机构
[1] Concordia Univ Edmonton, Ada Blvd, Edmonton, AB AB 7128, Canada
关键词
Software security; Risk management; Supply chain attacks; Modern code review; Vulnerability management;
D O I
10.1007/978-3-031-10548-7_31
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The use of freely available, open-source code to reduce the time needed to create new software or add functionality to existing software is a common practice. With analysis of recent high-profile cases of open-source software packages being corrupted by the original developer, or the introduction of remote backdoor functionality by malicious actors, it has been shown that there is much that can be done to help with simplifying the decision-making process of using any open-source code. This paper provides the basis for a simple-to-use checklist that can be used to quickly analyze open-source libraries for its suitability within an individual's or organization's code base. Fourteen projects were selected at random from a popular code hosting site that made use of specific biometric security libraries. The conclusions derived from the use of the checklist and the analysis of the selected projects will help with simplifying the decision-making process of using open-source code for software projects.
引用
收藏
页码:422 / 435
页数:14
相关论文
共 50 条
  • [41] Robots Security Assessment and Analysis Using Open-Source Tools
    Yankson, Benjamin
    Loucks, Tyler
    Sampson, Andrea
    Lojano, Chelsea
    PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY ICCWS, 2023, : 449 - 456
  • [42] Towards a Security Requirements Management Framework for Open-Source Software
    Wang, Wentao
    2018 IEEE 26TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE 2018), 2018, : 478 - 483
  • [43] An Approach to Characterize the Security of Open-Source Functions using LSP
    Pereira, Jose D'Ahruzzo
    Vieira, Marco
    2023 IEEE 34TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, ISSRE, 2023, : 137 - 147
  • [44] Security Evaluation of Open Source Clouds
    Ristov, Sasko
    Gusev, Marjan
    2013 IEEE EUROCON, 2013, : 73 - 79
  • [45] Evaluation of Language Runtimes in Open-source Serverless Platforms
    Djemame, Karim
    Datsev, Daniel
    Kelefouras, Vasilios
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE (CLOSER), 2022, : 123 - 132
  • [46] FOSSES: Framework for open-source software evaluation and selection
    Adewumi, Adewole
    Misra, Sanjay
    Omoregbe, Nicholas
    Fernandez Sanz, Luis
    SOFTWARE-PRACTICE & EXPERIENCE, 2019, 49 (05): : 780 - 812
  • [47] Open-source Serverless Architectures: an Evaluation of Apache OpenWhisk
    Djemame, Karim
    Parker, Matthew
    Datsev, Daniel
    2020 IEEE/ACM 13TH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC 2020), 2020, : 329 - 335
  • [48] An Automated, Open-Source Workflow for the Generation of (3D) Fragment Libraries
    Dekker, Tom
    Janssen, Mathilde A. C. H.
    Sutherland, Christina
    Aben, Rene W. M.
    Scheeren, Hans W.
    Blanco-Ania, Daniel
    Rutjes, Floris P. J. T.
    Wijtmans, Maikel
    de Esch, Iwan J. P.
    ACS MEDICINAL CHEMISTRY LETTERS, 2023, 14 (05): : 583 - 590
  • [49] Parallelization and performance evaluation of open-source HEVC codecs
    Garcia-Lucas, David
    Cebrian-Marquez, Gabriel
    Cuenca, Pedro
    JOURNAL OF SUPERCOMPUTING, 2017, 73 (01): : 495 - 513
  • [50] ChemT, an open-source software for building template-based chemical libraries
    Abreu, R. M. V.
    Froufe, H. J. C.
    Daniel, P. O. M.
    Queiroz, M. J. R. P.
    Ferreira, I. C. F. R.
    SAR AND QSAR IN ENVIRONMENTAL RESEARCH, 2011, 22 (5-6) : 603 - 610