TUHH Open Research
Hilfe
  • Log In
    or
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publications without fulltext
  4. Secure Software Development in the Era of Fluid Multi-party Open Software and Services
 
Options

Secure Software Development in the Era of Fluid Multi-party Open Software and Services

Publikationstyp
Conference Paper
Publikationsdatum
2021-05
Sprache
English
Author
Pashchenko, Ivan 
Scandariato, Riccardo 
Sabetta, Antonino 
Massacci, Fabio 
Institut
Software Security E-22 
TORE-URI
http://hdl.handle.net/11420/10498
Start Page
91
End Page
95
Citation
ACM/IEEE International Conference on Software Engineering: New Ideas and Emerging Results (ICSE-NIER 2021)
Contribution to Conference
43rd ACM/IEEE International Conference on Software Engineering: New Ideas and Emerging Results, ICSE-NIER 2021 
Publisher DOI
10.1109/ICSE-NIER52604.2021.00027
Scopus ID
2-s2.0-85108007945
Pushed by market forces, software development has become fast-paced. As a consequence, modern development projects are assembled from 3rd-party components. Security & privacy assurance techniques once designed for large, controlled updates over months or years, must now cope with small, continuous changes taking place within a week, and happening in sub-components that are controlled by third-party developers one might not even know they existed. In this paper, we aim to provide an overview of the current software security approaches and evaluate their appropriateness in the face of the changed nature in software development. Software security assurance could benefit by switching from a process-based to an artefact-based approach. Further, security evaluation might need to be more incremental, automated and decentralized. We believe this can be achieved by supporting mechanisms for lightweight and scalable screenings that are applicable to the entire population of software components albeit there might be a price to pay.
Schlagworte
open source software
software security
vision
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback