Direkt zum Inhalt

Schryen, Guido ; Eliot, Rich

Increasing software security through open source or closed source development? Empirics suggest that we have asked the wrong question

Schryen, Guido und Eliot, Rich (2010) Increasing software security through open source or closed source development? Empirics suggest that we have asked the wrong question. In: 43rd Annual Hawaii International Conference on System Sciences, 2010, Kauai.

Veröffentlichungsdatum dieses Volltextes: 27 Jun 2011 07:35
Konferenz- oder Workshop-Beitrag
DOI zum Zitieren dieses Dokuments: 10.5283/epub.21293


Zusammenfassung

While many theoretical arguments against or in favor of open source and closed source software development have been presented, the empirical basis for the assessment of arguments and the development of models is still weak. Addressing this research gap, this paper presents the first comprehensive empirical investigation of published vulnerabilities and patches of 17 widely deployed open source ...

While many theoretical arguments against or in favor of open source and closed source software development have been presented, the empirical basis for the assessment of arguments and the development of models is still weak. Addressing this research gap, this paper presents the first comprehensive empirical investigation of published vulnerabilities and patches of 17 widely deployed open source and closed source software packages, including operating systems, database systems, web browsers, email clients, and office systems. The empirical analysis uses comprehensive vulnerability data contained in the NIST National Vulnerability Database and a newly compiled data set of vulnerability patches. The results suggest that it is not the particular software development style that determines the severity of vulnerabilities and vendors’ patching behavior, but rather the specific application type and the policy of the particular development community, respectively.


Beteiligte Einrichtungen


Details

DokumentenartKonferenz- oder Workshop-Beitrag (Nicht ausgewählt)
Datum2010
InstitutionenWirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Entpflichtete oder im Ruhestand befindliche Professoren > Professur für Wirtschaftsinformatik (Prof. Dr. Guido Schryen)
Dewey-Dezimal-Klassifikation300 Sozialwissenschaften > 330 Wirtschaft
000 Informatik, Informationswissenschaft, allgemeine Werke > 000 Allgemeines, Wissenschaft
StatusVeröffentlicht
BegutachtetJa, diese Version wurde begutachtet
An der Universität Regensburg entstandenNein
URN der UB Regensburgurn:nbn:de:bvb:355-epub-212937
Dokumenten-ID21293

Bibliographische Daten exportieren

Nur für Besitzer und Autoren: Kontrollseite des Eintrags

nach oben