Security Risk Indicator for Open Source Software to Measure Software Development Status

Hiroki Kuzuno*, Tomohiko Yano, Kazuki Omo, Jeroen van der Ham, Toshihiro Yamauchi

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

1 Citation (Scopus)
68 Downloads (Pure)

Abstract

Recently, open source software (OSS) has become more mainstream. Therefore, the security of OSS is an important topic in information systems that use OSS. When vulnerabilities are discovered in OSS, it is difficult to fix or address for each information system developer or administrator. Existing security studies propose classifying vulnerabilities, estimating vulnerability risks, and analyzing exploitable vulnerabilities. However, it is still difficult to understand the threat of exploited vulnerabilities, and the development status of OSS used in information system operations. Determining whether vulnerabilities and the OSS development status are security risks is challenging. In this study, we propose a security risk indicator for OSS to address these problems. The proposed method calculates security risk indicators by combining vulnerability information with the development status of OSS. The proposed security risk indicator of OSS is a criterion for security measures during the operation of information systems. In the evaluation, we verified whether the proposed security risk indicator can be used to identify the threats of multiple OSS and the calculation cost of the security risk indicators.

Original languageEnglish
Title of host publicationInformation Security Applications
Subtitle of host publication24th International Conference, WISA 2023, Jeju Island, South Korea, August 23–25, 2023, Revised Selected Papers
EditorsHowon Kim, Jonghee Youn
PublisherSpringer
Pages143-156
Number of pages14
ISBN (Electronic)978-981-99-8024-6
ISBN (Print)978-981-99-8023-9
DOIs
Publication statusPublished - 2024
Event24th International Conference on Information Security Applications, WISA 2023 - Jeju Island, Korea, Republic of
Duration: 23 Aug 202325 Aug 2023
Conference number: 24

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume14402
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference24th International Conference on Information Security Applications, WISA 2023
Abbreviated titleWISA 2023
Country/TerritoryKorea, Republic of
CityJeju Island
Period23/08/2325/08/23

Keywords

  • 2024 OA procedure

Fingerprint

Dive into the research topics of 'Security Risk Indicator for Open Source Software to Measure Software Development Status'. Together they form a unique fingerprint.

Cite this