Open-Source Software Security Challenges and Policies for Cloud Enterprises

Sagar Gupta, S. Vadlamudi
{"title":"Open-Source Software Security Challenges and Policies for Cloud Enterprises","authors":"Sagar Gupta, S. Vadlamudi","doi":"10.1109/ICCT56969.2023.10076194","DOIUrl":null,"url":null,"abstract":"Cloud computing stimulated the development of agile software. The new oil is software. More than 70-90% of the software is open-source, and its usage is inevitable. Open source encourages innovation through collaboration, reduces Time-To-Market, and fuels breakthrough technologies from the past few decades. In a way, open source is eating software or driving the Software world. Open source communities involve more contributors /developers, sometimes posing substantial security challenges. Recently, we have witnessed SolarWinds compromising the entire supply chain, Log4j allowing access to execute code with critical zero-day vulnerability remotely. The digital universe paused because these zero-day vulnerabilities exploded as an outcome. In this work, we will highlight challenges and propose an approach to help organisations protect the code base by safely consuming the Open Source.","PeriodicalId":128100,"journal":{"name":"2023 3rd International Conference on Intelligent Communication and Computational Techniques (ICCT)","volume":"24 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 3rd International Conference on Intelligent Communication and Computational Techniques (ICCT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCT56969.2023.10076194","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Cloud computing stimulated the development of agile software. The new oil is software. More than 70-90% of the software is open-source, and its usage is inevitable. Open source encourages innovation through collaboration, reduces Time-To-Market, and fuels breakthrough technologies from the past few decades. In a way, open source is eating software or driving the Software world. Open source communities involve more contributors /developers, sometimes posing substantial security challenges. Recently, we have witnessed SolarWinds compromising the entire supply chain, Log4j allowing access to execute code with critical zero-day vulnerability remotely. The digital universe paused because these zero-day vulnerabilities exploded as an outcome. In this work, we will highlight challenges and propose an approach to help organisations protect the code base by safely consuming the Open Source.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
面向云企业的开源软件安全挑战与策略
云计算刺激了敏捷软件的开发。新的石油是软件。超过70-90%的软件是开源的,它的使用是不可避免的。开源鼓励通过协作进行创新,缩短上市时间,并为过去几十年的突破性技术提供动力。在某种程度上,开源正在吞噬软件或推动软件世界。开源社区涉及更多的贡献者/开发人员,有时会带来重大的安全挑战。最近,我们目睹了SolarWinds破坏了整个供应链,Log4j允许访问远程执行具有关键零日漏洞的代码。数字世界暂停了,因为这些零日漏洞爆发了。在这项工作中,我们将强调挑战,并提出一种方法来帮助组织通过安全使用开源来保护代码库。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
About ICCT '23 A Novel Technique to Detect URL Phishing based on Feature Count Effectiveness of Anti-Spoofing Protocols for Email Authentication Optimal Predictive Maintenance Technique for Manufacturing Semiconductors using Machine Learning Development of Secure IoT Ecosystems for Healthcare
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1