• DocumentCode
    1642934
  • Title

    A Comprehensive and Comparative Analysis of the Patching Behavior of Open Source and Closed Source Software Vendors

  • Author

    Schryen, Guido

  • Author_Institution
    Inst. of Bus. Inf. Syst., RWTH Aachen Univ., Aachen, Germany
  • fYear
    2009
  • Firstpage
    153
  • Lastpage
    168
  • Abstract
    While many theoretical arguments against or in favor of open source and closed source software development have been presented, the empirical basis for the assessment of arguments is still weak. Addressing this research gap, this paper presents a comprehensive empirical investigation of the patching behavior of software vendors/communities of widely deployed open source and closed source software packages, including operating systems, database systems, web browsers, email clients, and office systems. As the value of any empirical study relies on the quality of data available, this paper also discusses in detail data issues, explains to what extent the empirical analysis can be based on vulnerability data contained in the NIST National Vulnerability Database, and shows how data on vulnerability patches was collected by the author to support this study. The results of the analysis suggest that it is not the particular software development style that determines patching behavior, but rather the policy of the particular software vendor.
  • Keywords
    public domain software; security of data; software development management; software maintenance; NIST National Vulnerability Database; Web browsers; closed source software vendor; comparative analysis; comprehensive analysis; database systems; email clients; office systems; open source software vendor; operating systems; patching behavior; software development; vulnerability data; vulnerability patch; Application software; Data security; Database systems; Electronic mail; Information security; Internet; Open source software; Operating systems; Programming; Software packages;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    IT Security Incident Management and IT Forensics, 2009. IMF '09. Fifth International Conference on
  • Conference_Location
    Stuttgart
  • Print_ISBN
    978-0-7695-3807-5
  • Type

    conf

  • DOI
    10.1109/IMF.2009.15
  • Filename
    5277883