Security Evaluation and Hardening of Free and Open Source Software (FOSS)

نویسندگان

  • Robert Charpentier
  • Mourad Debbabi
  • Dima Alhadidi
  • Azzam Mourad
  • Nadia Belblidia
  • Amine Boukhtouta
  • Aiman Hanna
  • Rachid Hadjidj
  • Hakim Idrissi Kaitouni
  • Marc-André Laverdière
  • Hai Zhou Ling
  • Syrine Tlili
  • Xiaochun Yang
  • Zhenrong Yang
چکیده

Recently, Free and Open Source Software (FOSS) has emerged as an alternative to Commercial-Off-The-Shelf (COTS) software. Now, FOSS is perceived as a viable long-term solution that deserves careful consideration because of its potential for significant cost savings, improved reliability, and numerous advantages over proprietary software. However, the secure integration of FOSS in IT infrastructures is very challenging and demanding. Methodologies and technical policies must be adapted to reliably compose large FOSS-based software systems. A DRDC Valcartier-Concordia University feasibility study completed in March 2004 concluded that the most promising approach for securing FOSS is to combine advanced design patterns and Aspect-Oriented Programming (AOP). Following the recommendations of this study a three years project have been conducted as a collaboration between Concordia University, DRDC Valcartier, and Bell Canada. This paper aims at presenting the main contributions of this project. It consists of a practical framework with the underlying solid semantic foundations for the security evaluation and hardening of FOSS.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Review of "Perspectives on Free and Open Source Software" edited by Feller J, Fitzgerald B, Hissam SE and Lakhani KR

The volume is structured along 5 parts, some containing cohesive sets of articles, some loosely related ones. The three chapters that make up part 1 report on attempts to explain the FOSS phenomenon from the perspective of the psychology and sociology of its main actors. In particular, these articles try to explain what leads FOSS developers not to sell the software they create, but rather rega...

متن کامل

Evaluating the Potential of Free and Open Source Software in the Developing World

Development organizations and international nongovernmental organizations (NGOs) have been emphasizing the high potential of free and open source software (FOSS) for the less developed countries (LDCs). Cost reduction, less vendor dependency, and increased potential for local capacity development have been their main arguments. In spite of its advantages, FOSS is not widely adopted on the Afric...

متن کامل

Adoption of free and open source software using alternative educational framework in college of applied sciences

The adoption of Free and Open Source Software (FOSS) in educational institutions is increasing day by day. Many countries are insisting the use of FOSS in their government sectors and few are in the process of adopting FOSS strategies. The reasons for adopting FOSS are: total cost ownership, free to make copies and distribution, software legality, reliability, availability, performance, securit...

متن کامل

Risk Management of Free and Open Source Software

PURPOSE This guidance is intended to raise awareness within the financial services industry of risks and risk management practices applicable to the use of free and open source software (FOSS). For the purpose of this guidance, FOSS refers to software that users are allowed to run, study, modify, and redistribute without paying a licensing fee. Access to source code is a pre-requisite to the us...

متن کامل

Risk Management of Free and Open Source Software

PURPOSE This guidance is intended to raise awareness within the financial services industry of risks and risk management practices applicable to the use of free and open source software (FOSS).[See Footnote 1] For the purpose of this guidance, FOSS refers to software that users are allowed to run, study, modify, and redistribute without paying a licensing fee. Access to source code is a pre-req...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • ECEASST

دوره 33  شماره 

صفحات  -

تاریخ انتشار 2010