Home
Home
    • Blog
    • Clinic
    • Contact
    • Download
    • Video
    • Login

Poll

Favourite console text editor in Ubuntu:

Archives

July 2009
SunMonTueWedThuFriSat
2829301234
567891011
12131415161718
19202122232425
2627282930311

LXer -- Linux and Open Source News

  • PostgreSQL 8.4 Improves Database Management, Security
  • Linux based Solar-powered networking anywhere
  • PostgreSQL 8.4 now available
  • Reserve Your Space on the Australian Stage
  • GPLv3 Celebrates Two Years, GPLv2 Still in Front
more

Linux Today

  • The Kernel Newbie Corner: Your First Loadable Kernel Module
  • Red Hat inks cloud partnership with Amazon
  • PostgreSQL 8.4
  • 10 Awesome Features of Krunner in KDE 4
  • Changing the World, One Penguin at a Time
more

Linux Insider

  • Is Dell Building an Android PDA?
  • Wikipedia and the Kidnapped Reporter: Censor or Savior?
  • The Business Case for Virtual Business, Part 2
  • Conspiracy Theories and the 'Smoking Gun'
  • What I Need to Help Sell Linux
more

Study: OSS Communities Are Often Slackers in Security

Submitted by k4tz on Tue, 07/22/2008 - 11:34
  • Linux
  • Linux World
  • Open Source
  • Security
  • Software

Enterprises using certain kinds of open source software may be exposing themselves to serious security risks, according to a study from Fortify Software. The study, which focused primarily on non-commercially supported OSS, found many packages have no ground rules for reporting bugs and do not adequately inform users about how to use the applications safely.

The most widely used open source Latest News about open source software packages for the enterprise Rackspace now offers green hosting solutions at the same cost without sacrificing performance. Make the eco-friendly choice. are exposing users to significant and unnecessary business risks, according to an open source security Free Trial. Security Software As A Service From Webroot. study from security firm Fortify Software.

The study, released Monday, concludes that open source software (OSS) development communities have yet to adopt a secure development process and often leave dangerous vulnerabilities unaddressed. Additionally, the study found that nearly all OSS communities fail to provide users access to security expertise to help fix these vulnerabilities and security risks.

The survey, sponsored by Fortify and completed by application security consultant Larry Suto, examined 11 of the most common Java Latest News about Java open source packages.

"The findings startled us. We found numerous vulnerabilities in the open source packages tested. Communities lack a process for testing security. When enterprise users adopt these software packages, they get substantial risk," Jacob West, manager of security for the research group at Fortify, told LinuxInsider.

Testing Parameters

Fortify decided to conduct the security test for several reasons. The use of open source software in enterprise is expanding rapidly. The company sees strong adoption of numerous core packages, and its customers were pushing to know about inherent risks associated with their choices, said West.

In order to evaluate the security expertise offered to users and to measure the secure development processes in place in OSS communities, Fortify interacted with open source maintainers and examined documented open source security practices. The company downloaded multiple versions of each package and scanned them for vulnerabilities using Fortify SCA (the company's static analyzer). In addition, testers performed manual scannings on security-sensitive areas of code.

The security testing focused primarily on non-commercially supported open source packages, West said.

Biggest Faults

Two major concerns topped Fortify's list of findings. These are consistent with community-developed software and are not typically found with commercial open source products.

One is the absence of any procedures for reporting bugs or security flaws. The other is the lack of any secure guidelines on how to use the software safely.

"Open source software is an Achilles' heel in today's corporate enterprises and should be a significant concern for CIOs who depend on open source software to run their business," said Howard Schmidt, former cyber-security adviser to the White House. "This is an endemic issue that starts in the open source community, and while open source software faces the same vulnerabilities as commercial or in-house developed software, there just aren't the mechanisms in place to influence a secure development process."

No Offense

Fortify officials hope the open source community will respond positively to the findings.

"We're not trying to indict communities for something they do not have the money to fix," said West. "We have no real concerns about a negative reaction to the study findings."

At the same time, enterprise users of open source software need to understand the risks involved, according to the company. They have to pay the price to make sure what they use is secure, West added.

Adoption Concerns

The security weakness Fortify spotlights should serve as a wake-up call for the open source industry, as the growth of open source in industry is continuing at a steady pace, West noted.

"Its growth is unstoppable," he said. "Trying to stop it would be like standing in front of a tidal wave."

Recent industry reports support that growth trend. Research firm Gartner (NYSE: IT) Latest News about Gartner reported that by 2011, 80 percent of commercial software will include elements of open source technology. A report from Forrester Research noted that for over 88 percent of respondents, security of open source software was an important concern.

Proactive Steps

As a result of the survey, Fortify recommends that enterprises should follow the example of financial services companies in applying risk and coding analysis techniques to their open source software, West said. In addition, enterprises should raise security awareness within open source development communities and emphasize the importance of preventing vulnerabilities upstream.

Enterprise security teams should also perform assessments to understand where their open source deployments and components stand from a security standpoint, according to the firm. To that end, Fortify's Java Open Review provides audited versions of several open source packages.

"Most open source communities do not follow enterprise-level change control standards," says Jennifer Bayuk, independent security consultant and former CISO of Bear Stearns. "There is a hidden cost for the enterprise in using open source because they have to test and patch for security bugs they don't anticipate."

 

Source: http://www.linuxinsider.com/rsstory/63875.html

  • Add new comment

Recent blog posts

  • Questions about installing Ubuntu on HP Mini 1000 netbook
  • Epson NX400 driver in Ubuntu
  • Installing Ubuntu Jaunty on HP DV2 laptop
  • How to Install latest version of Midori [Browser] on Ubuntu
  • Download PCLinuxOS 2009.2
  • Download Sabayon Linux 4.2 "GNOME"
  • Map Windows Shares Permanently on Ubuntu with GVFS
  • Ubuntu 9.04 (Jaunty) and Acer Aspire One AOD150-iBb
  • Using Linux Ubuntu on HP HDX 16t Laptop
  • Run a particular program but prevent it from accessing the Internet
more

Linux World

  • Microsoft's Secret Weapon isn't FUD, it's Inertia
  • Will Google Wave revolutionise free software collaboration?
  • Is Android the key to the GNU/Linux desktop? Really?
  • USN-785-1: ipsec-tools vulnerabilities
  • Call it Netbook, Smartbook, or “Low-cost small notebook PC” - It is Great for Linux
  • The Week of the Linux Desktop
  • USN-781-2: Gaim vulnerabilities
  • USN-781-1: Pidgin vulnerabilities
  • USN-780-1: CUPS vulnerability
Archive Syndicate content

Recent comments

  • 1) # ./mkrawdev.sh ./mkrawdev.sh: line 6: ошибка синтаксиса окол
    8 weeks 1 day ago
  • 1) # ./mkrawdev.sh ./mkrawdev.sh: line 6: ошибка синтаксиса окол
    8 weeks 1 day ago
  • Aries Register is the best choice in Europe.
    17 weeks 6 days ago
  • Re: wireless
    20 weeks 3 days ago
  • wireless
    20 weeks 6 days ago
  • Re: Setting up wvdial to support Three
    24 weeks 6 days ago
  • Setting up wvdial to support Three
    26 weeks 1 day ago
  • не проходит built + raw device
    33 weeks 6 days ago
  • Re: Knol is not a Wikipedia clone
    38 weeks 2 days ago
  • Re: THANK YOU SOOOOO MUCH!!!
    38 weeks 2 days ago
All contents copyright © 2008, Dhuha Net. All rights reserved
Ubuntudoctor® is a member of the Dhuha Network. Privacy Policy
RoopleTheme