错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Security Risk Indicator for Open Source Software to Measure Software Development Status

  • Hiroki Kuzuno,
  • Tomohiko Yano,
  • Kazuki Omo,
  • Jeroen van der Ham,
  • Toshihiro Yamauchi

摘要

Recently, open source software (OSS) has become more mainstream. Therefore, the security of OSS is an important topic in information systems that use OSS. When vulnerabilities are discovered in OSS, it is difficult to fix or address for each information system developer or administrator. Existing security studies propose classifying vulnerabilities, estimating vulnerability risks, and analyzing exploitable vulnerabilities. However, it is still difficult to understand the threat of exploited vulnerabilities, and the development status of OSS used in information system operations. Determining whether vulnerabilities and the OSS development status are security risks is challenging. In this study, we propose a security risk indicator for OSS to address these problems. The proposed method calculates security risk indicators by combining vulnerability information with the development status of OSS. The proposed security risk indicator of OSS is a criterion for security measures during the operation of information systems. In the evaluation, we verified whether the proposed security risk indicator can be used to identify the threats of multiple OSS and the calculation cost of the security risk indicators.