DocumentCode :
260271
Title :
Security vulnerabilities in open source projects: An India perspective
Author :
Achuthan, Krishnashree ; SudhaRavi, Sreekutty ; Kumar, Ravindra ; Raman, Raghu
Author_Institution :
Amrita Center for Cybersecurity Syst. & Networks, Amrita Vishwa Vidyapeetham, Kollam, India
fYear :
2014
fDate :
28-30 May 2014
Firstpage :
18
Lastpage :
23
Abstract :
Educational and governmental organizations are heavy users of Free and Open Source Software (FOSS) due to the numerous economic advantages it offers. But because of the lack of formal notification of vulnerabilities in them these users are left with exploitable risks in their systems with known vulnerabilities which could completely offset the economic gains and lead to unrecoverable losses. India is one of the largest consumers of Free and Open Source Software (FOSS) though in the last few years there has been concerted effort to contribute to the movement as well as create its own FOSS to support local languages. This paper compares and analyses the public disclosure of vulnerabilities in Free and Open Source Software (FOSS) to those of non-open source systems. Our case study with (N=218) Information Technology (IT) professionals working in computer systems, networks and application development areas indicates an urgent need to enhance vulnerability handling practices for Free and Open Source Software based applications. This study has interesting implications for Information and Communications Technology (ICT) policy makers in the government as well as private sector who are increasingly advocating the use of FOSS.
Keywords :
information technology; security of data; software engineering; Free and Open Source Software; ICT policy makers; IT professionals; India perspective; application development; computer networks; computer systems; economic gains; educational organizations; governmental organizations; information and communications technology; information technology professionals; nonopen source systems; open source projects; public disclosure; security vulnerabilities; Databases; Government; Open source software; Security; Standards organizations; Cybersecurity threats; Free and Open Source Software; National Vulnerability Database; Open Source Vulnerability Database; Vulnerability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information and Communication Technology (ICoICT), 2014 2nd International Conference on
Conference_Location :
Bandung
Type :
conf
DOI :
10.1109/ICoICT.2014.6914033
Filename :
6914033
Link To Document :
بازگشت