Software Security in Open Source Development: A Systematic Literature Review

被引:0
|
作者
Wen, Shao-Fang [1 ]
机构
[1] Norwegian Univ Sci & Technol, Gjovik, Norway
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Despite the security community's emphasis on the importance of building secure open source software (OSS), the number of new vulnerabilities found in OSS is increasing. In addition, software security is about the people that develop and use those applications and how their vulnerable behaviors can lead to exploitation. This leads to a need for reiteration of software security studies for OSS developments to understand the existing security practices and the security weakness among them. In this paper, a systematic review method with a socio-technical analysis approach is applied to identify, extract and analyze the security studies conducted in the context of open source development. The findings include: (1) System verification is the most cited security area in OSS research; (2) The socio-technical perspective has not gained much attention in this research area; and (3) No research has been conducted focusing on the aspects of security knowledge management in OSS development.
引用
收藏
页码:364 / 373
页数:10
相关论文
共 50 条
  • [1] Software Architecture Degradation in Open Source Software: A Systematic Literature Review
    Baabad, Ahmed
    Zulzalil, Hazura Binti
    Hassan, Sa'adah
    Baharom, Salmi Binti
    [J]. IEEE ACCESS, 2020, 8 : 173681 - 173709
  • [2] Open Source Software Development Process: A Systematic Review
    Napoleao, Bianca M.
    Petrillo, Fabio
    Halle, Sylvain
    [J]. 2020 IEEE 24TH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE (EDOC 2020), 2020, : 135 - 144
  • [3] Open Source Software Evaluation, Selection, and Adoption: a Systematic Literature Review
    Lenarduzzi, Valentina
    Taibi, Davide
    Tosi, Davide
    Lavazza, Luigi
    Morasca, Sandro
    [J]. 2020 46TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2020), 2020, : 437 - 444
  • [4] A business model for commercial open source software: A systematic literature review
    Shahrivar, Shahrokh
    Elahi, Shaban
    Hassanzadeh, Alireza
    Montazer, Gholamali
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2018, 103 : 202 - 214
  • [5] A systematic literature review of open source software quality assessment models
    Adewumi, Adewole
    Misra, Sanjay
    Omoregbe, Nicholas
    Crawford, Broderick
    Soto, Ricardo
    [J]. SPRINGERPLUS, 2016, 5
  • [6] Maintenance Effort Estimation for Open Source Software: A Systematic Literature Review
    Wu, Hong
    Shi, Lin
    Chen, Celia
    Wang, Qing
    Boehm, Barry
    [J]. 32ND IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME 2016), 2016, : 32 - 43
  • [7] Adoption of open source software in software-intensive organizations - A systematic literature review
    Hauge, Oyvind
    Ayala, Claudia
    Conradi, Reidar
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2010, 52 (11) : 1133 - 1154
  • [8] A systematic review of research on open source software in commercial software product development
    Host, Martin
    Orucevic-Alagic, Alma
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2011, 53 (06) : 616 - 624
  • [9] Quality evaluation models or frameworks for open source software: A systematic literature review
    Yilmaz, Nebi
    Tarhan, Ayca Kolukisa
    [J]. JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2022, 34 (06)
  • [10] A systematic literature review on the barriers faced by newcomers to open source software projects
    Steinmacher, Igor
    Graciotto Silva, Marco Aurelio
    Gerosa, Marco Aurelio
    Redmiles, David F.
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2015, 59 : 67 - 85