Advertisement
Promo

Office applications Toolkit

Security guru wants access to bug databases

Ingrid Marson ZDNet.co.uk

Published: 21 Apr 2005 14:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security expert Ross Anderson has called for empirical research to be conducted into whether open source or closed source software is more secure, and into the impact that development practices such as extreme programming (XP) have on code quality.

Anderson, professor of security engineering at Cambridge University, asked software developers at the ACCU conference in Oxford on Wednesday to allow security researchers to access their records of software bugs.

"One of reasons I came here is to ask if you have any interesting databases on bugs," said Anderson. "The sort of questions we're now able to explore are not just whether open or closed [source] systems are more secure, but also on development methodology — how much better is XP, what happens to quality?"

This historical data would allow researchers to track the development of program code and the discovery of bugs. Anderson believes it would provide insights into the impact of XP and peer review on software quality, and the best approach to security patching. In XP, two developers work together and alternate between writing code and offering feedback on its design and accuracy.

Anderson said that empirical research, similar to the randomised controlled trials used in medicine, is more useful than theoretical research on software development.

"Computer science theory doesn't help solve the really hard problems," said Anderson. "Software is now big enough that we can start using statistical methods to measure outcomes."

One of Anderson's research students, Andy Ozment, has already done research using empirical data on bugs found in the open source operating system OpenBSD between 1997 and 2000. This research found that finding and fixing bugs results in a more secure product, contradicting research by security expert Eric Rescorla. Rescorla argued there is little value to finding security bugs — as many people are slow to patch their systems, and software patches can actually help hackers by drawing their attention to security holes in software.

Companies can be reluctant to make their code and bug databases available to researchers, but Anderson told ZDNet UK there are ways to overcome this. "A research student can analyse data under an NDA and we can negotiate what data can be released publicly," said Anderson.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
101 out of 162 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Discussions

dres dres

o_O

Thursday 10 December 2009, 11:35 AM

1 comment
dres dres

hm...

Thursday 10 December 2009, 11:29 AM

7 comments
dres dres

mmm.....

Thursday 10 December 2009, 11:26 AM

2 comments
dres dres

mmm.....

Thursday 10 December 2009, 11:26 AM

2 comments

Vista Upgrade Blog

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV licence?... More

Post a comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters