Title :
A Comprehensive and Comparative Analysis of the Patching Behavior of Open Source and Closed Source Software Vendors
Author_Institution :
Inst. of Bus. Inf. Syst., RWTH Aachen Univ., Aachen, Germany
Abstract :
While many theoretical arguments against or in favor of open source and closed source software development have been presented, the empirical basis for the assessment of arguments is still weak. Addressing this research gap, this paper presents a comprehensive empirical investigation of the patching behavior of software vendors/communities of widely deployed open source and closed source software packages, including operating systems, database systems, web browsers, email clients, and office systems. As the value of any empirical study relies on the quality of data available, this paper also discusses in detail data issues, explains to what extent the empirical analysis can be based on vulnerability data contained in the NIST National Vulnerability Database, and shows how data on vulnerability patches was collected by the author to support this study. The results of the analysis suggest that it is not the particular software development style that determines patching behavior, but rather the policy of the particular software vendor.
Keywords :
public domain software; security of data; software development management; software maintenance; NIST National Vulnerability Database; Web browsers; closed source software vendor; comparative analysis; comprehensive analysis; database systems; email clients; office systems; open source software vendor; operating systems; patching behavior; software development; vulnerability data; vulnerability patch; Application software; Data security; Database systems; Electronic mail; Information security; Internet; Open source software; Operating systems; Programming; Software packages;
Conference_Titel :
IT Security Incident Management and IT Forensics, 2009. IMF '09. Fifth International Conference on
Conference_Location :
Stuttgart
Print_ISBN :
978-0-7695-3807-5
DOI :
10.1109/IMF.2009.15