| Download ( PDF | 594kB) |
A comprehensive and comparative analysis of the patching behavior of open source and closed source software vendors
Schryen, Guido (2009) A comprehensive and comparative analysis of the patching behavior of open source and closed source software vendors. In: 5th International Conference on IT Security Incident Management & IT Forensics, 15-17 September 2009, Stuttgart, Germany.Veröffentlichungsdatum dieses Volltextes: 27 Jun 2011 07:35
Konferenz- oder Workshop-Beitrag
DOI zum Zitieren dieses Dokuments: 10.5283/epub.21294
Zusammenfassung
While many theoretical arguments against or in favor of open source and closed source software development have been presented, the empirical basis for the assessment of arguments is still weak. Addressing this research gap, this paper presents a comprehensive empirical investigation of the patching behavior of software vendors/communities of widely deployed open source and closed source software ...
While many theoretical arguments against or in favor of open source and closed source software development have been presented, the empirical basis for the assessment of arguments is still weak. Addressing this research gap, this paper presents a comprehensive empirical investigation of the patching behavior of software vendors/communities of widely deployed open source and closed source software packages, including operating systems, database systems, web browsers, email clients, and office systems. As the value of any empirical study relies on the quality of data available, this paper also discusses in detail data issues, explains to what extent the empirical analysis can be based on vulnerability data contained in the NIST National Vulnerability Database, and shows how data on vulnerability patches was collected by the author to support this study. The results of the analysis suggest that it is not the particular software development style that determines patching behavior, but rather the policy of the particular software vendor.
Beteiligte Einrichtungen
Details
| Dokumentenart | Konferenz- oder Workshop-Beitrag (Nicht ausgewählt) |
| Datum | 2009 |
| Institutionen | Wirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Entpflichtete oder im Ruhestand befindliche Professoren > Professur für Wirtschaftsinformatik (Prof. Dr. Guido Schryen) |
| Dewey-Dezimal-Klassifikation | 300 Sozialwissenschaften > 330 Wirtschaft 000 Informatik, Informationswissenschaft, allgemeine Werke > 000 Allgemeines, Wissenschaft |
| Status | Veröffentlicht |
| Begutachtet | Ja, diese Version wurde begutachtet |
| An der Universität Regensburg entstanden | Nein |
| URN der UB Regensburg | urn:nbn:de:bvb:355-epub-212940 |
| Dokumenten-ID | 21294 |
Downloadstatistik
Downloadstatistik