Comparative Investigation of Vulnerabilities in Open Source and Proprietary Software: An Exploratory Study

نویسندگان

  • Nitin Walia
  • Balaji Rajagopalan
  • Hemant K. Jain
چکیده

The success of products like Apache and Linux has propelled increased awareness and adoption of open source software (OSS). Despite increased adoption of OSS products, questions about their security and reliability remain. Using four popular OSS and proprietary products as an initial sample, we examine the vulnerability patterns in OSS and proprietary products. Our analysis suggests that for both proprietary and open source products, in general, severe vulnerabilities are identified relatively late in the product’s life and continue to emerge months after the software release. In particular, contrary to expectations, detection of vulnerabilities is no faster in open source (OS) than proprietary products. However, open source products had lower count of vulnerabilities at all levels of severity compared to proprietary products. We propose a conceptual framework to explain the variations in vulnerabilities between the OS and proprietary products. Our insights from the study have implications for research and practice.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Vulnerabilities and Patches of Open Source Software: An Empirical Study

Software selection is an important consideration in managing the information security function. Open source software is touted by proponents as being robust to many of the security problems that seem to plague proprietary software. This study empirically investigates specific security characteristics of open source and proprietary operating system software. Software vulnerability data spanning ...

متن کامل

Software Vulnerabilities: Open Source versus Proprietary Software Security

This study seeks to empirically investigate specific security characteristics of both open source software and proprietary software. Operating system software vulnerability data spanning several years are collected and analyzed to determine if significant differences exist in terms of inter-arrival times of published vulnerabilities and patch releases. Open source software is only marginally qu...

متن کامل

Vulnerabilities and Risk Management of Open Source Software: An Empirical Study

Software selection is an important consideration in risk management for information security. Additionally, the underlying robustness and security of a technology under consideration has become increasingly important in total cost of ownership and other calculations of business value. Open source software is often touted as being robust to many of the problems that seem to plague proprietary so...

متن کامل

Factors Influencing Adoption of Open Source Software - An Exploratory Study

Open Source Software (OSS), an example of an IS innovation, provides an alternative to proprietary software for organizations. Despite its free availability, OSS has not been universally adopted. While IS innovation has been extensively studied, there is a dearth of research literature on the adoption of OSS. Using a multi-site case study research method and a well known framework on the adopti...

متن کامل

Comparing the relative importance of evaluation criteria in proprietary and open-source enterprise application software selection - a conjoint study of ERP and Office systems

Until recently, organizations willing to acquire application systems have had no choice but to adopt proprietary software. With the advent of open-source software (OSS), a new model for developing and distributing software has entered the stage. OSS has evolved from a generally horizontal infrastructure towards more highly visible applications in vertical domains, giving information systems (IS...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006