When Are OSS Developers More Likely to Introduce Vulnerable Code Changes? A Case Study.

IFIP Advances in Information and Communication Technology(2014)

引用 3|浏览44
暂无评分
摘要
We analyzed peer code review data of the Android Open Source Project (AOSP) to understand whether code changes that introduce security vulnerabilities, referred to as vulnerable code changes (VCC), occur at certain intervals. Using a systematic manual analysis process, we identified 60 VCCs. Our results suggest that AOSP developers were more likely to write VCCs prior to AOSP releases, while during the post-release period they wrote fewer VCCs.
更多
查看译文
关键词
Open Source,OSS,FOSS,security,vulnerability
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要