"Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply Chain

"Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply Chain
复制标题

DOI:
10.1109/sp46215.2023.10179378
复制
发表时间:
2023-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Dominik Wermke;J. Klemmer;Noah Wöhler;Juliane Schmüser;Harshini Sri Ramulu;Y. Acar;S. Fahl
Dominik Wermke;J. Klemmer;Noah Wöhler;Juliane Schmüser;Harshini Sri Ramulu;Y. Acar;S. Fahl
中科院分区:
其他
文献类型:
--
作者:
Dominik Wermke;J. Klemmer;Noah Wöhler;Juliane Schmüser;Harshini Sri Ramulu;Y. Acar;S. Fahl

文献摘要

被引文献

相似文献

开源组件在公司的设置,流程和软件中无处不在,利用这些外部组件作为基础,使公司能够利用开源软件的好处但是,通过将这些组件引入其软件堆栈,公司继承了独特的安全挑战和攻击表面以及评估和减轻外部组件中脆弱性的影响的义务。在25个深入的,半结构化的访谈中,对软件开发人员,建筑师和工程师的访谈中,我们研究了他们的项目的过程,决策和考虑因素在外部开源代码中,我们发现开源组件在我们的许多参与者项目中都起着重要的作用练习包括外部代码,许多开发人员希望根据我们的发现,包括更多的开发人员小时,专门的团队或更好的审核对于公司而言,不将开源生态系统视为免费(软件)供应链,而是为他们受益并参与的整体软件生态系统的健康和安全做出贡献。
Open source components are ubiquitous in companies’ setups, processes, and software. Utilizing these external components as building blocks enables companies to leverage the benefits of open source software, allowing them to focus their efforts on features and faster delivery instead of writing their own components. But by introducing these components into their software stack, companies inherit unique security challenges and attack surfaces: including code from potentially unvetted contributors and obligations to assess and mitigate the impact of vulnerabilities in external components.In 25 in-depth, semi-structured interviews with software developers, architects, and engineers from industry projects, we investigate their projects’ processes, decisions, and considerations in the context of external open source code. We find that open source components play an important role in many of our participants’ projects, that most projects have some form of company policy or at least best practice for including external code, and that many developers wish for more developer-hours, dedicated teams, or tools to better audit included components. Based on our findings, we discuss implications for company stakeholders and the open source software ecosystem. Overall, we appeal to companies to not treat the open source ecosystem as a free (software) supply chain and instead to contribute towards the health and security of the overall software ecosystem they benefit from and are part of.