Vis enkel innførsel

dc.contributor.authorWen, Shao-Fang
dc.contributor.authorKianpour, Mazaher
dc.contributor.authorKatt, Basel
dc.date.accessioned2020-01-10T13:42:13Z
dc.date.available2020-01-10T13:42:13Z
dc.date.created2018-10-21T09:42:02Z
dc.date.issued2019
dc.identifier.isbn978-3-030-12942-2
dc.identifier.urihttp://hdl.handle.net/11250/2635742
dc.description.abstractOpen source software (OSS) communities are groups of individuals, technical or non-technical, interacting with collaborating peers in online communities of practices to develop OSS, solve particular software problems and exchange ideas. People join OSS communities with a different level of programming skills and experience and might lack formal, college-level software security training. There remains a lot of confusion in participants’ mind as to what is secured code and what the project wants. Another problem is that the huge amount of available software security information nowadays has resulted in a form of information overload to software engineers, who usually finish studying it with no clue about how to apply those principles properly to their own applications. This leads to a knowledge gap between knowledge available and knowledge required to build secure applications in the context of software projects. Given the increased importance and complexity of OSS in today’s world, lacking proper security knowledge to handle vulnerabilities in OSS development will result in breaches that are more serious in the future. The goal of this research work is to fill the knowledge gap by providing an artifact that would facilitate the effective security-knowledge transferring and learning in the context of OSS development. In this work-in-progress paper, we present our ongoing research work following design science research methodology on the domain problem identification and the development of the artifact.nb_NO
dc.language.isoengnb_NO
dc.publisherSpringer Verlagnb_NO
dc.relation.ispartofInnovative Security Solutions for Information Technology and Communications. SECITC 2018
dc.titleSecurity Knowledge Management in Open Source Software Communitiesnb_NO
dc.typeChapternb_NO
dc.description.versionacceptedVersionnb_NO
dc.source.pagenumber53-70nb_NO
dc.identifier.doi10.1007/978-3-030-12942-2_6
dc.identifier.cristin1621983
dc.description.localcodeThis is a post-peer-review, pre-copyedit version of an article. Locked until 6.2.2020 due to copyright restrictions. The final authenticated version is available online at: https://doi.org/10.1007/978-3-030-12942-2_6nb_NO
cristin.unitcode194,63,30,0
cristin.unitnameInstitutt for informasjonssikkerhet og kommunikasjonsteknologi
cristin.ispublishedtrue
cristin.fulltextpostprint
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel