Security of Open Source Web Applications

被引:0
|
作者
Walden, James [1 ]
Doyle, Maureen [1 ]
Welch, Grant A. [1 ]
Whelan, Michael [1 ]
机构
[1] No Kentucky Univ, Dept Comp Sci, Highland Hts, KY 41099 USA
关键词
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In an empirical study of fourteen widely used open source PHP web applications, we found that the vulnerability density of the aggregate code base decreased from 8.88 vulnerabilities/KLOC to 3.30 from Summer 2006 to Summer 2008. Individual web applications varied widely, with vulnerability densities ranging from 0 to 121.4 at the beginning of the study. While the total number of security problems decreased, vulnerability density increased in eight of the fourteen applications over the analysis period. We developed a security resources indicator metric, which we found to be strongly correlated (p = 0.67, p < 0.05) with change in vulnerability density over time. Traditional software metrics, such as code size, cyclomatic complexity, nesting complexity, and churn, had significant (p < 0.05) but much smaller correlations (p = 0.31 at best) with vulnerability density. Vulnerability density was measured using the Fortify Source Code Analyzer static analysis tool.
引用
收藏
页码:546 / 554
页数:9
相关论文
共 50 条
  • [1] Web Server Security on Open Source Environments
    Gkoutzelis, Dimitrios X.
    Sardis, Manolis S.
    [J]. NEXT GENERATION SOCIETY: TECHNOLOGICAL AND LEGAL ISSUES, 2010, 26 : 236 - +
  • [2] Open Source Web Applications for Libraries
    McNicol, Sarah
    [J]. NEW LIBRARY WORLD, 2011, 112 (5-6) : 283 - +
  • [3] OPEN SOURCE WEB APPLICATIONS FOR LIBRARIES
    Eden, Bradford Lee
    [J]. JOURNAL OF WEB LIBRARIANSHIP, 2011, 5 (03) : 262 - 263
  • [4] Open Source Web Applications for Libraries
    Kumaran, Maha
    [J]. JOURNAL OF THE CANADIAN HEALTH LIBRARIES ASSOCIATION, 2012, 33 (01): : 31 - 31
  • [5] Open Source Web Applications for Libraries
    Wiley, Deborah Lynne
    [J]. ONLINE, 2011, 35 (02): : 62 - 62
  • [6] Security in Open Source Web Content Management Systems
    Meike, Michael
    Sametinger, Johannes
    Wiesauer, Andreas
    [J]. IEEE SECURITY & PRIVACY, 2009, 7 (04) : 44 - 51
  • [7] Virtual Open-Source Labs for Web Security Education
    Tao, Lixin
    Chen, Li-Chiou
    Lin, Chienting
    [J]. WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, VOLS 1 AND 2, 2010, : 280 - 285
  • [8] Open Source Web Application Security: A Static Analysis Approach
    Alenezi, Mamdouh
    Javed, Yasir
    [J]. 2016 INTERNATIONAL CONFERENCE ON ENGINEERING & MIS (ICEMIS), 2016,
  • [9] Social Networks and Web Security: Implications on Open Source Intelligence
    Ansari, Fahad
    Akhlaq, Monis
    Rauf, A.
    [J]. 2013 2ND NATIONAL CONFERENCE ON INFORMATION ASSURANCE (NCIA), 2013, : 79 - 82
  • [10] Comparative Analysis Of Web Security In Open Source Content Management System
    Patel, Savan K.
    Rathod, V. R.
    Prajapati, Jigna B.
    [J]. 2013 INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND SIGNAL PROCESSING (ISSP), 2013, : 344 - 349