The Impact of a Major Security Event on an Open Source Project: The Case of OpenSSL

The Impact of a Major Security Event on an Open Source Project: The Case of OpenSSL
复制标题

重大安全事件对开源项目的影响:以 OpenSSL 为例

DOI:
10.1145/3379597.3387465
复制
发表时间:
2020
期刊:
2020 IEEE/ACM 17th International Conference on Mining Software Repositories (MSR)
影响因子:
--
通讯作者:
J. Walden
J. Walden
中科院分区:
--
文献类型:
--
作者:
J. Walden

文献摘要

被引文献

相似文献

Heartbleed漏洞在2014年引起了OpenSSL的国际关注。这个几乎奄奄一息的项目是公共网络服务器和超过10亿台移动的设备的关键安全组件。这个漏洞导致了对OpenSSL的新投资。目的:本研究的目标是确定Heart-bleed漏洞如何改变OpenSSL的软件演变。我们研究漏洞,代码质量,项目活动和软件工程实践的变化。方法:我们使用混合方法,从网站收集多种类型的定量数据和定性数据,并采访了一位致力于Heartbleed后更改的开发人员。我们使用回归不连续性分析来确定Heartbleed导致的代码和项目活动指标的水平和斜率变化。结果:OpenSSL项目在Heartbleed之后对代码质量和安全性做出了巨大的改进。截至2016年底,OpenSSL每月提交数量增加了两倍,发现并修复了91个漏洞,代码复杂性显著降低,并获得了CII最佳实践徽章,证明其使用了良好的开源开发实践。结论:OpenSSL项目提供了一个开源项目在安全事件发生后如何适应和改进的模型。OpenSSL的发展表明,已知漏洞的数量并不是项目安全性的有用指标。少量的漏洞可能只是表明项目没有花费太多的精力来寻找漏洞。这项研究表明,项目活动和CII徽章最佳实践可能是比漏洞计数更好的代码质量和安全性指标。
Context: The Heartbleed vulnerability brought OpenSSL to international attention in 2014. The almost moribund project was a key security component in public web servers and over a billion mobile devices. This vulnerability led to new investments in OpenSSL. Objective: The goal of this study is to determine how the Heart-bleed vulnerability changed the software evolution of OpenSSL. We study changes in vulnerabilities, code quality, project activity, and software engineering practices. Method: We use a mixed methods approach, collecting multiple types of quantitative data and qualitative data from web sites and an interview with a developer who worked on post-Heartbleed changes. We use regression discontinuity analysis to determine changes in levels and slopes of code and project activity metrics resulting from Heartbleed. Results: The OpenSSL project made tremendous improvements to code quality and security after Heartbleed. By the end of 2016, the number of commits per month had tripled, 91 vulnerabilities were found and fixed, code complexity decreased significantly, and OpenSSL obtained a CII best practices badge, certifying its use of good open source development practices. Conclusions: The OpenSSL project provides a model of how an open source project can adapt and improve after a security event. The evolution of OpenSSL shows that the number of known vulnerabilities is not a useful indicator of project security. A small number of vulnerabilities may simply indicate that a project does not expend much effort to finding vulnerabilities. This study suggests that project activity and CII badge best practices may be better indicators of code quality and security than vulnerability counts.