Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software Projects

被引:0
|
作者
Wermke, Dominik [1 ]
Woehler, Noah [1 ]
Klemmer, Jan H. [2 ]
Fourne, Marcel [3 ]
Acar, Yasemin [4 ]
Fahl, Sascha [1 ]
机构
[1] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[2] Leibniz Univ Hannover, Hannover, Germany
[3] Max Planck Inst Secur & Privacy, Bochum, Germany
[4] George Washington Univ, Washington, DC 20052 USA
关键词
D O I
10.1109/SP46214.2022.00143
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Open Source Software plays an important role in many software ecosystems. Whether in operating systems, network stacks, or as low-level system drivers, software we encounter daily is permeated with code contributions from open source projects. Decentralized development and open collaboration in open source projects introduce unique challenges: code submissions from unknown entities, limited personpower for commit or dependency reviews, and bringing new contributors up-to-date in projects' best practices & processes. In 27 in-depth, semi-structured interviews with owners, maintainers, and contributors from a diverse set of open source projects, we investigate their security and trust practices. For this, we explore projects' behind-the-scene processes, provided guidance & policies, as well as incident handling & encountered challenges. We find that our participants' projects are highly diverse both in deployed security measures and trust processes, as well as their underlying motivations. Based on our findings, we discuss implications for the open source software ecosystem and how the research community can better support open source projects in trust and security considerations. Overall, we argue for supporting open source projects in ways that consider their individual strengths and limitations, especially in the case of smaller projects with low contributor numbers and limited access to resources.
引用
收藏
页码:1880 / 1896
页数:17
相关论文
共 50 条
  • [21] An Empirical Study of Adoption of Software Testing in Open Source Projects
    Kochhar, Pavneet Singh
    Bissyande, Tegawende F.
    Lo, David
    Jiang, Lingxiao
    [J]. 2013 13TH INTERNATIONAL CONFERENCE ON QUALITY SOFTWARE (QSIC), 2013, : 103 - 112
  • [22] Trust in world politics: converting 'identity' into a source of security through trust-learning
    Bilgic, Ali
    [J]. AUSTRALIAN JOURNAL OF INTERNATIONAL AFFAIRS, 2014, 68 (01) : 36 - 51
  • [23] Affective Trust as a Predictor of Successful Collaboration in Distributed Software Projects
    Calefato, Fabio
    Lanubile, Filippo
    [J]. 2016 IEEE/ACM 1ST INTERNATIONAL WORKSHOP ON EMOTION AWARENESS IN SOFTWARE ENGINEERING (SEMOTION), 2016, : 3 - 5
  • [24] A Qualitative Study of Open Source Software Development: the OpenEMR Project
    Noll, John
    Beecham, Sarah
    Seichter, Dominik
    [J]. 2011 FIFTH INTERNATIONAL SYMPOSIUM ON EMPIRICAL SOFTWARE ENGINEERING AND MEASUREMENT (ESEM 2011), 2011, : 30 - 39
  • [25] Study of trust model for grid security
    Zhu, DW
    Zhou, ZD
    Liu, Q
    [J]. DCABES 2004, Proceedings, Vols, 1 and 2, 2004, : 1002 - 1005
  • [26] From open-source software to Wikipedia: ‘Backgrounding’ trust by collective monitoring and reputation tracking
    Paul B. de Laat
    [J]. Ethics and Information Technology, 2014, 16 : 157 - 169
  • [27] From open-source software to Wikipedia: 'Backgrounding' trust by collective monitoring and reputation tracking
    de Laat, Paul B.
    [J]. ETHICS AND INFORMATION TECHNOLOGY, 2014, 16 (02) : 157 - 169
  • [28] A Qualitative Study on the Organizational Adoption of Open Source Server Software
    Ven, Kris
    Verelst, Jan
    [J]. INFORMATION SYSTEMS MANAGEMENT, 2012, 29 (03) : 170 - 187
  • [29] An Empirical Study of Security Culture in Open Source Software Communities
    Wen, Shao-Fang
    Kianpour, Mazaher
    Kowalski, Stewart
    [J]. PROCEEDINGS OF THE 2019 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM 2019), 2019, : 863 - 870
  • [30] Analysing the Reliability of Open Source Software Projects
    Aversano, Lerina
    Tortorella, Maria
    [J]. 2015 10TH INTERNATIONAL JOINT CONFERENCE ON SOFTWARE TECHNOLOGIES (ICSOFT), VOL 1, 2015, : 348 - 357