Survey on Vulnerability Awareness of Open Source Software

被引:0
作者
Zhan, Qi [1 ]
Pan, Sheng-Yi [1 ]
Hu, Xing [2 ]
Bao, Ling-Feng [1 ]
Xia, Xin [3 ]
机构
[1] College of Computer Science and Technology, Zhejiang University, Hangzhou,310027, China
[2] School of Software Technology, Zhejiang University, Ningbo,315048, China
[3] Software Engineering Application Technology Lab, Huawei Technologies Co. Ltd., Hangzhou,310053, China
来源
Ruan Jian Xue Bao/Journal of Software | 2024年 / 35卷 / 01期
关键词
Life cycle - Network security - Open systems - Software reliability;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the modern software scale expands, software vulnerabilities bring a great threat to the security and reliability of computer systems and software, causing huge damage to people’s production and life. In recent years, as open source software (OSS) is widely used, the vulnerability issues of OSS have received much attention. Vulnerability awareness techniques can effectively help OSS users to identify vulnerabilities at the early stage for timely defense. Different from the vulnerability detection techniques for traditional software, the transparency and cooperativity of OSS vulnerabilities bring great challenges to vulnerability awareness. Therefore, various techniques are proposed by scholars and developers to perceive potential vulnerabilities and risks in OSS from the code and open source community, so as to find OSS vulnerabilities as early as possible and reduce the losses caused by the vulnerabilities. To boost the development of OSS vulnerability awareness techniques, this study conducts a systematic literature review of existing research works. The study selects 45 high-level papers on open source vulnerability awareness techniques, including code-based, open source community discussion-based, and patch-based vulnerability awareness techniques. The results of these papers are systematically summarized. Especially, this study proposes the category of techniques based on the OSS vulnerability life cycle for the first time according to the most recent publications, which supplements and improves the existing taxonomy of vulnerability awareness techniques. Finally, the study discusses the challenges in the field and predicts future research direction. © 2024 Chinese Academy of Sciences. All rights reserved.
引用
收藏
页码:19 / 37
相关论文
empty
未找到相关数据