<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Hyper Contextual Software Security Management for Open Source Software</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Shao-Fang Wen</string-name>
          <email>shao-fang.wen@ntnu.no</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Norwegian Information Security Lab Faculty of Computer Science and Media Technology Norwegian University of Science and Technology</institution>
          ,
          <country country="NO">Norway</country>
        </aff>
      </contrib-group>
      <fpage>83</fpage>
      <lpage>90</lpage>
      <abstract>
        <p>Since the turn of the century, open source software (OSS) has been an active and dynamic research area. OSS development and maintenance are highly distributed processes that involve a multitude of supporting tools and resources. OSS communities use numerous knowledge sources while working on a certain task to help them secure the software products. These not only include security incidents statistics and best practice documents that are published in the open literatures or online communities, but also social networking tools. This often results in additional challenges, as not every OSS project member can correlate particular learned security information with their working context. This position paper outlines the security problems in OSS and describes the use of socio-technical system theory and ontology technologies to capture and model software security knowledge. Our research aims to develop and test a hyper-contextual, knowledge-based environment that stores and process security knowledge to facilitate retrieval in context, and thus allows the non-linearly correlated knowledge between contexts to be identified and transferred between and among OSS developers and users.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Open source software (OSS) has become increasingly important and has attracted
developers from both public and private sectors. Open source model, as a radically new
software development model, begins in the mid-90s. Since then, a good deal of software
created by open source model have been widely adopted and used by various industries.
The 2015 Future of Open Source Survey [
        <xref ref-type="bibr" rid="ref10">11</xref>
        ] reported that, 78% of companies run
operations on open source, and 55% of respondents said open source delivers superior
security [
        <xref ref-type="bibr" rid="ref5">6</xref>
        ]. This reputation can be contributed to community development model in
OSS development and the resulting purview by the “many eyes” of developers
worldwide. Yet, of the 8,000-13,000 vulnerabilities detected annually, about 40% impact
open source software [
        <xref ref-type="bibr" rid="ref9">10</xref>
        ]. These vulnerabilities open some of the most critical OSS
projects to potential exploit: Heartbleed and Logjam (in OpenSSL); Shellshock (in
bash); Venom (in QEMU and OSS hypervisors), and NetUSB (in the Linux kernel).
While both the quantity and severity of vulnerabilities are increasing in OSS, its
development and maintenance present a unique management and software security
challenges.
      </p>
      <p>
        OSS development and maintenance take place in a distributed environment,
involving a multitude of supporting tools and resources, integrated in complex and often
partially defined workflows and processes [
        <xref ref-type="bibr" rid="ref14">15</xref>
        ]. OSS communities use numerous
knowledge sources while working on a certain task to help them secure the software
products. These not only include security incidents statistics and best practices
documents published in the open literatures or online communities, such as Open Web
Application Security Project1 (OWASP), Build Security In2 (BSI) project and Open
Sourced Vulnerability Database3 (OSVDB), but also social networking tools, such as
group mails, dynamic blogs and wiki systems. Software engineers have these security
resources at their disposal, but this also results in a form of information overload. They
have difficulties correlating particular learned vulnerabilities or security information
with their working context [
        <xref ref-type="bibr" rid="ref11">12</xref>
        ]. Identifying security knowledge that are applicable in
a given context can become a major challenge for OSS. The implicit knowledge is often
lost, since it is not captured by today's security management environments. A similar
security case might have been successfully resolved by a different developer using a
solution that other members are unaware of, but if this knowledge is not captured,
stored, and delivered in a context-sensitive manner to the team even the whole
community, it cannot serve as a “cognitive map” for future problem-solving. If we can capture,
combine and apply this ‘ambient’ (contextual) knowledge into coherent chunks,
priming it when software engineers need it, we can bring OSS security to a completely new
level: a hyper-contextual, active software security management environment that can
provide a collective memory for the communication within the communities. We
propose the notion of Hyper Contextual Software Security Management that stores and
processes security knowledge to facilitate retrieval in context, and thus allows the
nonlinearly correlated knowledge between contexts to be identified and transferred
between OSS developers and users.
      </p>
      <p>On the conceptual side, this research is based on socio-technical system theory and
ontology technologies. Software engineering is a multifaceted domain, which stretches
from low-level technical aspects (e.g., source code, operating systems and tools such
as compilers and editors) to organizational and legal concerns (e.g., prescribed process,
1
2
3</p>
      <p>
        Open Web Application Security Project (OWASP) is an online community which creates
freely-available articles, methodologies, documentation, tools, and technologies in the field
of web application security. https://www.owasp.org/
Build Security In (BSI) is a collaborative effort that provides practices, tools, guidelines,
principles, and other resources that software developers, architects, and security practitioners can
use to build security into software in every phase of its development.
https://buildsecurityin.us-cert.gov/
Open Sourced Vulnerability Database (OSVDB) is an independent and open-sourced database
which aims to provide accurate, detailed, and unbiased technical information on security
vulnerabilities. https://blog.osvdb.org/
international standards) to social and cognitive aspects (e.g., communication behavior
and cognitive models) [
        <xref ref-type="bibr" rid="ref4">5</xref>
        ]. Providing adaptive support that addresses the security
concerns is difficult, due to the different representations and interrelationships that exist in
the context of software engineering and knowledge resources. As Scacchi [
        <xref ref-type="bibr" rid="ref12">13</xref>
        ] points
out, the meaning of open source in the socio-technical context is broader than its
technical definition, and includes communities of practice, social practices, technical
cultures, and uses. In this research, we will apply a socio-technical systems perspective
to address the security characteristics in open source phenomenon. Based on the
observed socio-technical context, we examine the main factors that were once
disproportionately considered in software security knowledge. Ontology is then used in
knowledge modeling since it’s a good approach to systematically categorize various
concepts and describe their relationships [
        <xref ref-type="bibr" rid="ref2">3</xref>
        ]. By capturing knowledge from various
perspectives through ontology population, we can build an extensible, distributed
security knowledge base.
      </p>
      <p>Our approach lies in explicitly describing and abstracting the security knowledge
that are needed by OSS developers and also other stakeholders in the communities to
successfully perform their particular tasks. This extensible knowledge model not only
includes existing security standards and guidelines, but also their relevance within a
certain development or maintenance context by using knowledge collection through
investigating the behavior of team members while solving similar security events. This
research strives not to propose the adaptation of a new tool or development process, but
rather examine how existing resources can be integrated to implement the next
generation of software security management environments, which is an important contribution
neglected by current researches.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Research Goal and Research Questions</title>
      <p>The goal of this research work is to develop and test a hyper-contextual, knowledge
–based system that would facilitate open source communities to effectively offer
appropriate secured software products. We seek to examine the hypothesis: Hyper
Contextual Software Security Management can improve security quality of software
product that are developed, delivered and maintained by open source communities.</p>
      <p>To better understand the scope and magnitude of the research goal, four research
studies along with their respective research questions were formulated as follows:</p>
      <sec id="sec-2-1">
        <title>Study-1: Research question 1</title>
        <p>At first it is important to identify and establish the magnitude of the real-world
situation, including current practices (tools, knowledge and other resources) used in OSS
communities. When responding to these requirements, research question 1 is split into
two sub-research questions:</p>
        <p>RQ1 (a): What are the current issues and challenges facing secure software products
that are developed, delivered and maintained by open source communities?</p>
        <p>RQ1 (b): What are the strengths and weaknesses, technical and non-technical, of
software security practices used by open source communities?</p>
      </sec>
      <sec id="sec-2-2">
        <title>Study-2: Research question 2</title>
        <p>After study–1, it is imperative to investigate, identify, and develop software security
knowledge, technical and non-technical, that could appropriately be integrated into the
security knowledge management system. Therefore, the second research question is
formulated as:</p>
        <p>RQ2: What contemporary software security information can be contextualized and
formalized into the proposed software security knowledge management system for
securing software products in OSS communities?</p>
      </sec>
      <sec id="sec-2-3">
        <title>Study-3: Research question 3</title>
        <p>After study-2, which identifies the security characteristics and factors that are
appropriate, it is necessary to develop a system for formalizing and integrating this security
information into an ontological knowledge model. Therefore, the third research
question is formulated as:</p>
        <p>RQ3: How can proposed software security information, technical and non-technical,
be contextualized and formalized into an integrated ontological model to form a
knowledge management system for securing software products in OSS communities?</p>
      </sec>
      <sec id="sec-2-4">
        <title>Study-4: Research question 4</title>
        <p>After study–3, it is necessary to evaluate the proposed system addresses in RQ 3, in
the studied environment. Therefore, the fourth research question is formulated as:</p>
        <p>RQ4: How can the proposed knowledge management system be evaluated to
effectively meet the demands for securing software products in OSS communities?</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. The Socio-Technical Framework</title>
      <p>
        In this research, we will make an interpretive inquiry in the context of OSS
evaluation using a socio-technical framework provided by Stewart Kowalski [
        <xref ref-type="bibr" rid="ref8">9</xref>
        ]. The
sociotechnical framework contains two basic models: a dynamic model of socio-technical
changes, called the socio-technical system (see Figure 3-1), and a static one, called the
security-by-consensus (SBC) model or stack (see Figure 3-2). At the abstract level, the
socio-technical system is divided into two subsystems, social and technical. Within a
given sub-system there are further sub-systems. The former (social) has culture and
structures, and the latter (technical) has methods and machines. From the system
theory/s point of view, inter-dependencies between system levels make a system adjust for
attaining equilibrium. The process is referred to as homeostasis state. For instance, if
new hardware is introduced into one of the technical sub-systems, for instance, the
machine sub-system; the whole system will strive to achieve homeostasis. This suggests
that changes in one sub-system may cause disturbances in other sub-systems and
consequently to the entire system.
      </p>
      <p>Reflecting the static nature of the socio-technical systems, the SBC stack is a
multilevel structure that divides security measures into hierarchical levels of control. The
social sub-system include following security measures: ethical and cultural norms, legal
and contractual documents, administrational and managerial policies, and operational
and procedural guidelines. Similarly, the technical sub-system consists mechanical and
electronic, hardware, operating systems, application systems, and data. Other aspects
are: store, process, collect, and communication.</p>
      <p>
        In the socio-technical framework, each system interacts with other systems rather
than being an isolated system. Internal and external changes—both social and
technical—will affect system security. Therefore, systematic deployment of security
measures is required. In particular, this framework has been applied to evaluate threat
modeling in software supply chain [1], business process re-engineering [
        <xref ref-type="bibr" rid="ref3">4</xref>
        ], and an
information security maturity model [
        <xref ref-type="bibr" rid="ref6">7</xref>
        ]. The application of the socio-technical
framework to software analysis is an appropriate and legitimate way of understanding the
intrinsic context in open source phenomenon. It provides a way to perform system
analysis through a systemic–holistic perspective [
        <xref ref-type="bibr" rid="ref7">8</xref>
        ].
      </p>
    </sec>
    <sec id="sec-4">
      <title>4. Methodology</title>
      <p>
        Since the main goal of this research is to produce an artifact, the design science
appears as an appropriate methodology of our research. Design science research (DSR)
methodology can be conducted when creating innovations and ideas that define
technical capabilities and products through which the development process of artifacts can
be effectively and efficiently accomplished [
        <xref ref-type="bibr" rid="ref1 ref13">2, 14</xref>
        ]. The design science approach
applied for this study is based on work presented by Vaishnavi and Kuechler [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ]. Figure
4-1 represents design science research process model.
Figure 4-1: Design science research process model
      </p>
      <p>
        (Vaishnavi and Kuechler [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ])
      </p>
      <p>Consequently, research studies and their corresponding research questions that are
linked to the DSR process (steps), are connected to research activities as follows:



</p>
      <p>Study–1, RQ 1 (a) (b) links to awareness of the real-world problem step in DSR.
Research activities involves conducting extensive literature review and
casestudies (questionnaires) in the selected OSS communities on various issues
related to software security management for OSS, as well as issues related to
security knowledge learning in the real-world environment.</p>
      <p>Study–2, RQ 2 links to suggestions for a tentative design step in DSR. The study
involved conducting an extensive literature review on various ontological
models, security standards, and best practices. Questionnaires will be prepared,
aimed at gathering OSS stakeholders’ views on proposed security knowledge
model and their respective security requirements control areas, technical and
non-technical.</p>
      <p>Study–3, RQ 3 links to developing the artifact step in DSR. This study will apply
action research strategy to continuously build the artifact and improve its quality
in the context of focused efforts. We repeat the process as a spiral of cycles of
action and research in four main phases: planning, acting, observing and
reflecting.</p>
      <p>Study–4, RQ 4 links to evaluating the proposed system step in DSR. This study
will be conducted in the selected OSS communities. Evaluation methods could
be either practical, theoretical or both. Practical evaluation methods include
tests, experiments and analysis. Theoretical evaluation methods include
observations and descriptions. They involve use of qualitative techniques such as
case-study, field-study, informed argumentation and scenario analyses.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions</title>
      <sec id="sec-5-1">
        <title>DSR Step</title>
        <sec id="sec-5-1-1">
          <title>Awareness of the realworld problem Suggestion for tentative design</title>
        </sec>
        <sec id="sec-5-1-2">
          <title>Developing the artifact</title>
        </sec>
        <sec id="sec-5-1-3">
          <title>Evaluating the artifact</title>
        </sec>
      </sec>
      <sec id="sec-5-2">
        <title>Research Activity</title>
        <sec id="sec-5-2-1">
          <title>Literature review, questionnaires,</title>
          <p>physical observation, interview
Literature review, questionnaires,
physical observation, interview
Action(development), observation,
reflection
Practical evaluation: testing,
experimental and analytical
Theoretical evaluation: case-study,
field-study, and scenario analyses</p>
          <p>Given the increased complexity and importance of open source software in today’s
society and an increased knowledge gap between security information available and
security information used and practiced, our position is that new socio-technical tools
and approaches are needed. My position is that hyper contextual software security
management is a means to help fill this gap by bringing the ability to place information
in an appropriate context and to use knowledge in an ever changing global security
environment.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgement</title>
      <p>The author would like to thank Professor Dr. Stewart Kowalski and Professor Dr.
Rune Hjelsvold of Faculty of Computer Science and Media Technology at Norwegian
University of Science and Technology, who have made contributions to the ideas
described in this paper.
[1] Al Sabbagh, B. and S. Kowalski (2013). "A socio-technical framework for threat
modeling a software supply chain". The 2013 Dewald Roode Workshop on Information
Systems Security Research, October 4-5, 2013, Niagara Falls, New York, USA,
International Federation for Information Processing.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Alan</surname>
            , R. H.,
            <given-names>S. T.</given-names>
          </string-name>
          <string-name>
            <surname>March</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Park</surname>
            and
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Ram</surname>
          </string-name>
          (
          <year>2004</year>
          ).
          <article-title>"Design science in information systems research." MIS quarterly</article-title>
          . volume
          <volume>28</volume>
          , issue 1, pages
          <fpage>75</fpage>
          -
          <lpage>105</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Bäck</surname>
            ,
            <given-names>A</given-names>
          </string-name>
          .,
          <string-name>
            <given-names>S.</given-names>
            <surname>Vainikainen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Södergård</surname>
          </string-name>
          and H.
          <string-name>
            <surname>Juhola</surname>
          </string-name>
          (
          <year>2003</year>
          ).
          <article-title>"Semantic Web Technologies in Knowledge Management"</article-title>
          . ELPUB.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Bider</surname>
            , I. and
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Kowalski</surname>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>A framework for synchronizing human behavior, processes and support systems using a socio-technical approach</article-title>
          . Enterprise,
          <source>BusinessProcess and Information Systems Modeling</source>
          , Springer:
          <fpage>109</fpage>
          -
          <lpage>123</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Brooks</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          (
          <year>1983</year>
          ).
          <article-title>"Towards a theory of the comprehension of computer programs." International journal of man-machine studies</article-title>
          . volume
          <volume>18</volume>
          , issue 6, pages
          <fpage>543</fpage>
          -
          <lpage>554</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Hoepman</surname>
            ,
            <given-names>J.-H.</given-names>
          </string-name>
          and
          <string-name>
            <given-names>B.</given-names>
            <surname>Jacobs</surname>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>"Increased security through open source." Communications of the ACM</article-title>
          . volume
          <volume>50</volume>
          , issue 1, pages
          <fpage>79</fpage>
          -
          <lpage>83</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Karokola</surname>
            , G.,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Kowalski</surname>
          </string-name>
          and L.
          <string-name>
            <surname>Yngström</surname>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>"Towards An Information Security Maturity Model for Secure e-Government Services: A Stakeholders View"</article-title>
          . HAISA.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Karokola</surname>
            ,
            <given-names>G</given-names>
          </string-name>
          . R.,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kowalski</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. J.</given-names>
            <surname>Mwakalinga</surname>
          </string-name>
          and
          <string-name>
            <given-names>V.</given-names>
            <surname>Rukiza</surname>
          </string-name>
          (
          <year>2011</year>
          ).
          <article-title>"Secure eGovernment Adoption: A Case Study of Tanzania"</article-title>
          .
          <source>European Security Conference.</source>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Kowalski</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          (
          <year>1994</year>
          ).
          <article-title>"IT insecurity: a multi-discipline inquiry</article-title>
          ."
          <source>PhD Thesis</source>
          , Department of Computer and System Sciences, University of Stockholm and Royal Institute of Technology, Sweden. ISBN:
          <fpage>91</fpage>
          -
          <lpage>7153</lpage>
          -207-2.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Martin</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Sullo</surname>
          </string-name>
          and
          <string-name>
            <surname>J. Kouns.</surname>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>"OSVDB: open source vulnerability database." Electronic document</article-title>
          . https://blog.osvdb.org/category/vulnerabilitystatistics/.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [11]
          <string-name>
            <surname>NorthBridge</surname>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>"2015 Future of Open Source Survey." Electronic document</article-title>
          . http://www.northbridge.com/open-source
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Oliveira</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Rosenthal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Morin</surname>
          </string-name>
          ,
          <string-name>
            <surname>K.-C. Yeh</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Cappos</surname>
            and
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Zhuang</surname>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>"It's the psychology stupid: how heuristics explain software vulnerabilities and how priming can illuminate developer's blind spots"</article-title>
          .
          <source>Proceedings of the 30th Annual Computer Security Applications Conference</source>
          , ACM.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Scacchi</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          (
          <year>2002</year>
          ).
          <article-title>"Understanding the requirements for developing open source software systems"</article-title>
          .
          <source>IEE Proceedings--Software</source>
          , IET.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Vaishnavi</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          and
          <string-name>
            <given-names>W.</given-names>
            <surname>Kuechler</surname>
          </string-name>
          (
          <year>2004</year>
          ).
          <article-title>"Design research in information systems." Electronic document</article-title>
          . http://desrist.org/design-research-in
          <source>-information-systems/.</source>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Von</surname>
            <given-names>KROGh</given-names>
          </string-name>
          , G. and
          <string-name>
            <given-names>S.</given-names>
            <surname>Spaeth</surname>
          </string-name>
          (
          <year>2007</year>
          ).
          <article-title>"The open source software phenomenon: Characteristics that promote research."</article-title>
          <source>The Journal of Strategic Information Systems</source>
          . volume
          <volume>16</volume>
          , issue 3, pages
          <fpage>236</fpage>
          -
          <lpage>253</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>