Open-source security moves to next step

Source code analysis expert Coverity has found and helped fix more than 7,500 security flaws in open-source software, and published a list of the 11 open-source projects working fastest to sort them out.

The work is part of a U.S. government-backed project to harden open-source code.

"We applaud the developers responsible for the 11 open-source projects that have advanced to the second rung of code security and quality," said David Maxwell, open-source strategist for Coverity.

The Open Source Hardening Project, sponsored by the U.S. Department of Homeland Security, uses Coverity's Scan, which grades projects on a "ladder" according to their progress at fixing and preventing flaws.

Eleven projects have been awarded the newly announced status of Rung 2, including those known as Amanda, NTP, OpenPAM, OpenVPN, Overdose, Perl, PHP, Postfix, Python, Samba, and TCL. According to Coverity, this new development means users will be able to "select these open-source applications with even greater confidence."

Several other projects are expected to advance to Rung 2 over the next few months. The Open Source Hardening Project began in January 2006 and was expanded early in 2007 to cover a list of 150 projects.

Coverity uses static source-code analysis to spot errors in code, such as open brackets. Projects on Rung 2 will move on to use the company's "satisfiability" techniques, which use a bit-accurate representation of a software system, translating every relevant software operation into Boolean values (true and false) and Boolean operators (such as and, not, or).

Coverity claims this type of analysis is a first in commercial programming and is able to spot hundreds more bugs than the tools available on Rung 1.

Although the project is clearly improving the security of open-source software, some have expressed concern that coverage of its results may produce bad publicity in the form of headlines about security flaws in open-source software.

Peter Judge of ZDNet UK reported from London.

More from News.com on this story's topics

Government

Create an email alert | RSS feed

Open source

Create an email alert | RSS feed

Security

Create an email alert | RSS feed

See more CNET content tagged:
Coverity, open source, open-source software, project, analysis

Add a Comment (Log in or register) 4 comments (Page 1 of 1)
PHP?
by The_Decider January 12, 2008 12:50 AM PST
That makes this entire testing process suspect.

In terms of security, PHP is horrible. As a programming language it is not much better.

I don't think this is bad publicity for OSS. If anything it is good news. OSS generally takes security seriously and doesn't deny and hide issues and then post fixes only when they have to like many proprietary software companies.
Reply to this comment
While Microsoft stays at Rung 0
by wbenton January 13, 2008 7:31 AM PST
Many things still need to be done... but Microsoft still needs to do many things before they can even think about achieving the status of Rung 1... much less Rung 2.

Walt
Reply to this comment View reply
Powered by Jive Software
RSS Feeds
Add headlines from CNET News.com to your homepage or feedreader.
Google
Yahoo
MSN
More feeds available in our RSS feed index.

Latest tech news headlines

Most Popular Stories
Google's search secret: It gets rid of you
Developer creates copy-paste tech for iPhone
Will Wright on the origins of 'Spore'
Palm Treo Pro: Not digging it
American Airlines launches in-flight Wi-Fi
Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.11%) 12.78 11,430.21
S&P 500 (0.25%) 3.18 1,277.72
NASDAQ (0.00%) 0.00 1,816.15
CNET TECH (-0.11%) -1.71 1,629.09
  Symbol Lookup
advertisement
On TechRepublic: Are you too old for IT?
Advanced
search
Advanced
search
Visit other CBS Interactive sites