An Empirical Study of Security Problem Reports in Linux Distributions

被引:0
|
作者
Anbalagan, Prasanth [1 ]
Vouk, Mladen [1 ]
机构
[1] N Carolina State Univ, Dept Comp Sci, Raleigh, NC 27695 USA
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Existing studies on problem reports in open source projects focus primarily on the analysis of the general category of problem reports, or limit their attention to observations on the number of security problem reports. To evaluate the security of a project, it is necessary to know not only how many security problem reports are logged but also how many are reported and how promptly they are corrected etc. In this paper we study publicly disclosed security problem reports from eight releases of Fedora, nine releases of Ubuntu, four releases of RedHat Enterprise Linux (RHEL) and two releases of Suse Linux distributions, analyse and discuss which type of problem reports and how frequently they are reported, and how promptly they are corrected. Overall, Fedora and Suse show good results with high and medium severity security problem reports resolved without a backlog. On the other hand, RHEL and Ubuntu show less positive results with presence of backlogs.
引用
收藏
页码:482 / 485
页数:4
相关论文
共 50 条
  • [21] Scaling Open Source Communities: An Empirical Study of the Linux Kernel
    Tan, Xin
    Zhou, Minghui
    Fitzgerald, Brian
    2020 ACM/IEEE 42ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2020), 2020, : 1222 - 1234
  • [22] An Empirical Study of Rust-for-Linux: The Success, Dissatisfaction, and Compromise
    Li, Hongyu
    Guo, Liwei
    Yang, Yexuan
    Wang, Shangguang
    Xu, Mengwei
    PROCEEDINGS OF THE 2024 USENIX ANNUAL TECHNICAL CONFERENCE, ATC 2024, 2024, : 425 - 443
  • [23] Reflections on the virtues of modularity: a case study in linux security modules
    Blaich, Andrew
    Thain, Douglas
    Striegel, Aaron
    SOFTWARE-PRACTICE & EXPERIENCE, 2009, 39 (15): : 1235 - 1251
  • [24] Vulnerability management in Linux distributionsAn empirical study on Debian and Fedora
    Jiahuei Lin
    Haoxiang Zhang
    Bram Adams
    Ahmed E. Hassan
    Empirical Software Engineering, 2023, 28
  • [25] Evaluation of Linux SMTP Server Security Aspects - A Case Study
    Khanji, Salam
    Jabir, Raja
    Ahmad, Liza
    Alfandi, Omar
    Said, Huwida
    2016 7TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS (ICICS), 2016, : 252 - 257
  • [26] EMPIRICAL BAYES ESTIMATION PROBLEM WITH NONIDENTICAL COMPONENTS INVOLVING NORMAL DISTRIBUTIONS
    OBRYAN, T
    SUSARLA, V
    COMMUNICATIONS IN STATISTICS, 1975, 4 (11): : 1033 - 1042
  • [27] Linux server security.
    Gordon, RS
    LIBRARY JOURNAL, 2005, 130 (10) : 166 - 166
  • [28] Enhancing ReiserFS security in Linux
    Reiser, HT
    DARPA INFORMATION SURVIVABILITY CONFERENCE AND EXPOSITION, VOL II, PROCEEDINGS, 2003, : 188 - 188
  • [29] Experience Report: Security Vulnerability Profiles of Mission Critical Software: Empirical Analysis of Security Related Bug Reports
    Goseva-Popstojanova, Katerina
    Tyo, Jacob
    2017 IEEE 28TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE), 2017, : 152 - 163
  • [30] Electronic signatures and security issues: An empirical study
    Srivastava, A.
    Computer Law and Security Review, 2009, 25 (05): : 432 - 446