Open Source Vulnerability Notification

Open Source Vulnerability Notification
复制标题

开源漏洞通知

DOI:
10.1007/978-3-030-20883-7_2
复制
发表时间:
2019
期刊:
Lenarduzzi V. (eds
影响因子:
--
通讯作者:
Prakash, Atul
Prakash, Atul
中科院分区:
--
文献类型:
--
作者:
Carlson, Brandon;Leach, Kevin;Marinov, Darko;Nagappan, Meiyappan;Prakash, Atul

文献摘要

参考文献

相似文献

使用第三方库来管理软件复杂性可能会使开源软件项目暴露于漏洞之中。然而,项目所有者目前还没有一种标准的方法来启用潜在安全漏洞的私有披露。造成这种忽视的部分原因可能是没有可遵循的模板来披露此类漏洞。我们分析了600个GitHub项目,以确定有多少项目包含易受攻击的依赖项,以及这些项目是否有适当的流程来私下沟通安全问题。我们发现600个开源Java项目中有385个包含至少一个易受攻击的依赖项,而这385个项目中只有13个具有安全漏洞报告流程。也就是说,96.6%的有漏洞的项目没有适当的安全通知流程来允许私人披露。在确定项目是否有公开的联系信息时,我们发现19.8%的项目没有公开的联系信息,更不用说安全漏洞报告过程了。我们建议两种方法允许社区成员私下披露潜在的安全漏洞。
The use of third-party libraries to manage software complexity can expose open source software projects to vulnerabilities. However, project owners do not currently have a standard way to enable private disclosure of potential security vulnerabilities. This neglect may be caused in part by having no template to follow for disclosing such vulnerabilities. We analyzed 600 GitHub projects to determine how many projects contained a vulnerable dependency and whether the projects had a process in place to privately communicate security issues. We found that 385 out of 600 open source Java projects contained at least one vulnerable dependency, and only 13 of those 385 projects had a security vulnerability reporting process. That is, 96.6% of the projects with a vulnerability didnothave a security notification process in place to allow for private disclosure. In determining whether the projects even had contact information publicly available, we found that 19.8% had no contact information publicly available, let alone a security vulnerability reporting process. We suggest two methods to allow for community members to privately disclose potential security vulnerabilities.
常用服务、角色和功能的邮箱名称
DOI: --
发表时间: 1997
期刊: Request for Comments
影响因子: --
作者:
D. Crocker
通讯作者: D. Crocker
一种Web安全策略方法
DOI: --
发表时间: 2019
期刊:
影响因子: --
作者:
Y. Shafranovich;Edwin Foudil
通讯作者: Edwin Foudil