Open source 'lacks enterprise-grade security'

By Matthew Broersma, ZDNet UK
Tuesday, July 22, 2008 07:00 AM

The security practices of open source IT developers should lead enterprises to think twice before using open source software, according to a new study sponsored by security tools vendor Fortify.

The study, carried out by application security consultant Larry Suto, found that a lack of security processes led to a constant or increasing number of security issues in successive open source releases.

As a result, government and commercial organizations should approach open source applications with "great caution", carrying out risk analysis and code review before it is used, Fortify said.

The company argued that open source development simply does not live up to enterprise security standards. Fortify quoted Jennifer Bayuk, an independent security consultant, as saying that open source implies a "hidden cost" due to the necessity of testing for security bugs.

The study is likely to reopen the debate around the relative security of proprietary and open source software.

Independent software vendors (ISVs) selling proprietary software have claimed that the open source development process exposes open source software to greater security risks, while open source developers argue that the openness of the process allows for more security flaws to be caught.

The study examined software for developing and serving Java applications, including Geronimo, JBoss, Struts and Tomcat. It found that all or nearly all of the projects examined failed to provide access to an internal security expert, reduce the number of security flaws in successive releases or make use of bug-catching tools such as FindBugs or Fortify's own Java Open Review (JOR).

As a result, bugs such as SQL injection and cross-site scripting (XSS) continue to proliferate, Fortify said.

"Open source packages often claim enterprise-class capabilities but are not adopting--or even considering--industry best-security practices," the study said. "Serious security threats stemming from numerous application vulnerabilities are a direct result of poor or non-existent security processes."

One exception is Mozilla, which in July announced a security initiative and hired security consultant Rich Mogul as an adviser. But more projects need to follow Mozilla's lead or, better yet, follow the lead of proprietary ISVs in improving security practices, Fortify said.

"Open source development can benefit from private industry practices--notably those created by financial services organizations and larger independent software vendors," the report said.

Not everyone agrees that security should be the priority Fortify takes it to be. Last week Linux creator Linus Torvalds criticized the makers of the OpenBSD operating system as part of a critique of what he said was self-centered behavior in the IT security industry.

The row erupted in the Gmane mailing list after a developer for the PaX Team, which patches the Linux kernel, accused Torvalds and other top Linux kernel developers of "covering up [the] security impact of bugs" by not clearly labeling them as security flaws. Torvalds wrote that disclosing the bug itself was enough, without having to label each individual security flaw. He added that taking the bugs to the "security circus" level only glorified the wrong kind of behavior.

A May study funded by the U.S. Department of Homeland Security praised improvements in open source security. A recent survey found that unsupported open source software was one of the top causes of security breaches.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Well, It is getting better all the time
The tides are changing in this aspect. Enterprise security and open source have not been good bedfellows in the past but developers are starting to make it a priority. I came across this site a while back (web link) and they are working on a cross platform application for specifically for enterprise security. Did I mention that it is open source :) I can't wait to see open source go toe to toe with the big boys in this market. Remeber Jboss? Is there any doubt it is enterprise now?
Posted by Sam Adams on Tuesday, August 12 2008 03:32 AM

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Secure ASP.NET sites with Membership API

Web Development

Beginning with ASP.NET 2.0, the Membership API was added to simplify adding security to a Web application. Find out how to use the Membership API with a SQL Server backend.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. adobe
  2. app
  3. apple
  4. apps
  5. beta
  6. browser
  7. business
  8. chrome
  9. deal
  10. down
  11. firefox
  12. google
  13. license
  14. linux
  15. microsoft
  16. mobile
  17. mozilla
  18. open
  19. oracle
  20. over
  21. sap
  22. server
  23. software
  24. source
  25. support
  26. users
  27. virtualization
  28. vmware
  29. web
  30. windows

ZDNet Asia Top Tech 50 to recognize Asia's potential

Blog thumbnail

The ZDNet Asia Top Tech 50 awards are back, and we're once again seeking nominations to identify the industry's best-performing tech companies.

The marketplace is crowded with players clamoring for..... by Eileen Yu

Read more »