padlock

Fortify warns open source is insecure

Business users warned to approach open source with "great caution"

Written by Dave Bailey

Business leaders have been warned by security firm Fortify Software that increased use of open source software within the enterprise should be approached with "great caution".

In a new report, entitled "Open Source Security Study : How Are Open Source Development Communities Embracing Security Best Practices?" Fortify warned that IT chiefs should be extra vigilant when deploying open source software.

"Government and commercial organisations… should use open source applications with great caution," the report concluded.

All software development carries the risk of vulnerabilities in the code, the report noted, but the open source community trails in-house development and commercial rivals when it comes to developing enterprise-class security support, it suggested.

"Today’s enterprises are built and operated by software that comes from a variety of sources - but as we’re seeing more often, can be based on open source," said Roger Thornton, chief technology officer at Fortify.

Fortify based its analysis on a study carried out by application security consultant Larry Suto, in conjunction with Fortify's Security Research Group. Eleven open source Java applications were examined, using Source Code Analysis (the static analyser module in Fortify's recently released Fortify 360 package), including the Geronimo, JBoss and Tomcat application servers, the Struts web application framework and the OpenCMS content management solution.

These applications were then evaluated for the sophistication of their security support, including documentation and availability of support.

Fortifuy concluded that many open source applications provide inadequate access to security expertise, do not adopt a sufficiently rigorous approach to security in the development process, and do not use state-of-the-art tools to test application security.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

hacker

Gartner predicts great things for security-as-a-service

Analyst firm says cloud-based security services will rocket in popularity over next five years 16 Jul 2008

 

Sun adds to open storage range

Sun promises unparalleled price-performance from new open storage range 10 Jul 2008

Balancing mobility with security is a fine art

IT managers must keep their eye on risks as mobile devices become widespread 19 Jun 2008

Red Hat unveils virtualisation plans

Open source hypervisor and management console enters beta testing 19 Jun 2008

Sun touts open integration platform

Sun unveils Java Caps 6, its open source integration platform 09 Jun 2008

Ubuntu clears path to enterprises

Desktop and server editions of Ubuntu OS are targetted at enterprise users 22 Apr 2008

Shell faces fresh criticism over Niger Delta environmental record

New report urges oil giant to end gas flaring and upgrade ageing infrastructure 16 Feb 2010

Fortify launches online scanning tool

On-demand service promises to help firms spot critical vulnerabilities in software 09 Dec 2009

CDM offset assessors face fresh criticism

WWF-backed report finds companies assessing emission reduction projects are approving projects that are later rejected 29 Jun 2010

related white papers

today's top stories

Financial IT job market recovery continues

Recruitment growth suggests IT budgets are increasing 30 Jul 2010

Satellite broadband touted as digital divide clincher

KA-SAT launch promises 10Mbit/s service for hard-to-reach locations 29 Jul 2010

Ofcom slams ISPs for exaggerated broadband speed claims

New code of practice for ISPs planned by the regulator 27 Jul 2010

Aerohive offers traffic light Wi-Fi monitoring

Firm promises simple 'red, yellow or green' system with Client Health Score tool 27 Jul 2010

Flaw in top wireless security protocol WPA2 uncovered

Disgruntled insiders could hack corporate wireless LAN 26 Jul 2010

Advertisement

How to achieve business and financial-system implementation success
A look at how organisations - regardless of size - can work towards successful business software installations and factors that determine the outcome.

Case study: Specsavers put customer care into focus
How Specsavers captured customer feedback at point of sale and incorporated the results into its CRM system.

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

ICO to lean more heavily on public sector bodies

ICO to lean more heavily on public sector bodies

The ICO has said it will lean more heavily on public sector bodies to secure timely FOI responses, do you think this is:

View poll results

Latest audio and video articles

picture of Jason HartVideo

Ethical hacker reveals the security secrets behind cloud computing

Jason Hart, Senior VP at Cryptocard, shows Computing just how easy it is to illegally gain access to corporate cloud services to wreak havoc and steal money. 29 Jun 2010

gartner logoVideo

Part 1: 2010 trends in SOA and Application Development and Integration

Gartner analyst Paolo Malinverno explores trends in SOA 29 Jun 2010

Latest in-depth articles

Map of 3G coverageComment

The risks of selling off the 800MHz radio spectrum at the wrong price

It's a choice between revenue now or universal broadband later 30 Jul 2010

Luton Borough Council officesAnalysis

Local authority leads the way in digital backup technology

Luton Borough Council tells of the benefits of early adopter of VTL, data deduplication and virtualisation 27 Jul 2010

Primary Navigation