Journal of Information Processing
Online ISSN : 1882-6652
ISSN-L : 1882-6652
 
Visualization Method for Open Source Software Risk Related to Vulnerability and Developmental Status Considering Dependencies
Tomohiko Yano, Hiroki Kuzuno
著者情報
ジャーナル フリー

2024 年 32 巻 p. 767-778

詳細
抄録

In recent years, Open-source software (OSS) has become a mainstream technology essential to information systems. However, its secure application requires a comprehensive understanding of its various security risks. One of them is vulnerability risk. A vulnerability risk involves the discovery of a new vulnerability in the OSS in use, which must be immediately addressed by security administrators, such as software updates. On the other hand, developmental risks involve OSS that are not in active development. If the development of an OSS is stalled, an alternative OSS should be considered because newly identified vulnerabilities may not be fixed. Therefore, a specialized method is required to analyze vulnerability and developmental risks of OSS, while accounting for their dependencies. This paper proposes a method that identifies such security risks of OSS by extracting, linking, and visualizing the vulnerabilities, development status, and dependency information. The proposed method enables security administrators to check visualization results, identify OSS with security risks, and consider appropriate countermeasures. We experimentally evaluate the adequacy of the visualizations for the purpose of the identification of security risks, and calculate the processing time required to visualize the risks.

著者関連情報
© 2024 by the Information Processing Society of Japan
前の記事 次の記事
feedback
Top