kirancodes.me
To Proof Maintenance & Beyond!

Measuring subversions: security and legal risk in reused software artifacts

Julius Davies

Abstract

A software system often includes a set of library dependencies and other software artifacts necessary for the system's proper operation. However, long-term maintenance problems related to reused software can gradually emerge over the lifetime of the deployed system. In our exploratory study we propose a manual technique to locate documented security and legal problems in a set of reused software artifacts. We evaluate our technique with a case study of 81 Java libraries found in a proprietary e-commerce web application. Using our approach we discovered both a potential legal problem with one library, and a second library that was affected by a known security vulnerability.

BibTeX
@inproceedings{Davies:ICSE11,
  author    = {Julius Davies},
  title     = {Measuring subversions: security and legal risk in reused software artifacts},
  booktitle = {ICSE},
  pages     = {1149--1151},
  publisher = {{ACM}},
  year      = {2011},
}

Related papers