An Empirical Study of Security Problem Reports in Linux Distributions

被引:0
|
作者
Anbalagan, Prasanth [1 ]
Vouk, Mladen [1 ]
机构
[1] N Carolina State Univ, Dept Comp Sci, Raleigh, NC 27695 USA
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Existing studies on problem reports in open source projects focus primarily on the analysis of the general category of problem reports, or limit their attention to observations on the number of security problem reports. To evaluate the security of a project, it is necessary to know not only how many security problem reports are logged but also how many are reported and how promptly they are corrected etc. In this paper we study publicly disclosed security problem reports from eight releases of Fedora, nine releases of Ubuntu, four releases of RedHat Enterprise Linux (RHEL) and two releases of Suse Linux distributions, analyse and discuss which type of problem reports and how frequently they are reported, and how promptly they are corrected. Overall, Fedora and Suse show good results with high and medium severity security problem reports resolved without a backlog. On the other hand, RHEL and Ubuntu show less positive results with presence of backlogs.
引用
收藏
页码:482 / 485
页数:4
相关论文
共 50 条
  • [41] An Empirical Study on the Quality of Entropy Sources in Linux Random Number Generator
    Du, Mingshu
    Ma, Yuan
    Lv, Na
    Chen, Tianyu
    Jia, Shijie
    Zheng, Fangyu
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 559 - 564
  • [42] An Empirical Study of Fault Triggers in the Linux Operating System: An Evolutionary Perspective
    Xiao, Guanping
    Zheng, Zheng
    Yin, Beibei
    Trivedi, Kishor S.
    Du, Xiaoting
    Cai, Kai-Yuan
    IEEE TRANSACTIONS ON RELIABILITY, 2019, 68 (04) : 1356 - 1383
  • [43] Five Linux Distributions With Tools for Audit
    Moyle, Ed
    ISACA Journal, 2018, 2 : 52 - 55
  • [44] The Android Update Problem: An Empirical Study
    Mahmoudi, Mehran
    Nadi, Sarah
    2018 IEEE/ACM 15TH INTERNATIONAL CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR), 2018, : 220 - 230
  • [45] Study of empirical learning for an involved problem
    1600, Morgan Kaufmann Publ Inc, San Mateo, CA, USA (01):
  • [46] An Empirical Study on Hidden Tag Problem
    Li, Rui
    Ding, Han
    Li, Shaoping
    Wang, Xing
    Liu, Hui
    Zhao, Jizhong
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2015,
  • [47] Goodness of Fit Test for Truncated Distributions, the Empirical Study
    Echaust, Krzysztof
    Lach, Agnieszka
    MATHEMATICAL METHODS IN ECONOMICS (MME 2017), 2017, : 149 - 154
  • [48] Study on Diffusion of Protection/Mitigation against Memory Corruption Attack in Linux Distributions
    Saito, Takamichi
    Miyazaki, Hiroyuki
    Baba, Takaaki
    Sumida, Yoshifumi
    Hori, Yosuke
    2015 9TH INTERNATIONAL CONFERENCE ON INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING IMIS 2015, 2015, : 525 - 530
  • [49] COMMUNICATING THROUGH FINANCIAL REPORTS - AN EMPIRICAL-STUDY
    MCINTYRE, EV
    JOURNAL OF BUSINESS COMMUNICATION, 1975, 12 (03): : 9 - 15
  • [50] An Empirical Study of the Effects of Expert Knowledge on Bug Reports
    Huo, Da
    Ding, Tao
    McMillan, Collin
    Gethers, Malcom
    2014 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME), 2014, : 1 - 10