You are here: silicon.com > Software > Applications

Applications

Does open source pose a security risk?

Businesses warned to exercise "great caution"

Tags: open source, software, business

By Matthew Broersma

Published: 22 July 2008 08:52 GMT

The security practices of open-source IT developers should lead enterprises to think twice before using open-source software, according to a new study.

The study, carried out by application security consultant Larry Suto and sponsored by security tools vendor Fortify, found that a lack of security processes led to a constant or increasing number of security issues in successive open-source releases.

As a result, government and commercial organisations should approach open-source applications with "great caution", carrying out risk analysis and code review before it is used, Fortify said.

The company argued that open-source development simply does not live up to enterprise security standards. Fortify quoted Jennifer Bayuk, an independent security consultant, as saying that open source implies a "hidden cost" due to the necessity of testing for security bugs.

The study is likely to reopen the debate around the relative security of proprietary and open-source software.

Latest photo stories from silicon.com

Photos: Waging war on the web's bad guys

Photos: How to destroy your hard drive

Photos: It's virtual everything in Cisco's future

Photos: Inside a supercomputer lab

Photos: A peek at the future of telemedicine

Photos: 60 years of NHS tech

Independent software vendors (ISVs) selling proprietary software have claimed the open-source development process exposes open-source software to greater security risks, while open-source developers argue that the openness of the process allows for more security flaws to be caught.

The study examined software for developing and serving Java applications, including Geronimo, JBoss, Struts and Tomcat. It found that all or nearly all of the projects examined failed to provide access to an internal security expert, reduce the number of security flaws in successive releases or make use of bug-catching tools such as FindBugs or Fortify's own Java Open Review.

As a result, bugs such as SQL injection and cross-site scripting continue to proliferate, Fortify said.

The study said: "Open-source packages often claim enterprise-class capabilities but are not adopting - or even considering - industry best-security practices. Serious security threats stemming from numerous application vulnerabilities are a direct result of poor or non-existent security processes."

One exception is Mozilla, which in July announced a security initiative and hired security consultant Rich Mogul as an adviser. But more projects need to follow Mozilla's lead or, better yet, follow the lead of proprietary ISVs in improving security practices, Fortify said.

The report said: "Open-source development can benefit from private industry practices - notably those created by financial services organisations and larger independent software vendors."

A May study funded by the US Department of Homeland Security praised improvements in open-source security. A recent survey found that unsupported open source software was one of the top causes of security breaches.

Original article: Open source 'lacks enterprise-grade security' from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Network/Security Consultant

Network/Security Consultant. Our leading client, based in the South West, requires an experienced network security consultant to work on an urgent ...

Software Engineers - Open Source, Virtual Collaboration.

Software Engineers - Open Source, Virtual Collaboration - Virtual C++, Java, .NET, Visual BasicNewport, South Walesup to 37,000+benefitsSoftware ...

Information Security Consultant - FSA Regulations - Data Protec

Information Security Consultant - FSA Regulations - Data Protection - IT Security Information Security Consultant - FSA Regulations - Data Protection ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: