padlock

Fortify warns open source is insecure

Business users warned to approach open source with "great caution"

Written by Dave Bailey

Business leaders have been warned by security firm Fortify Software that increased use of open source software within the enterprise should be approached with "great caution".

In a new report, entitled "Open Source Security Study : How Are Open Source Development Communities Embracing Security Best Practices?" Fortify warned that IT chiefs should be extra vigilant when deploying open source software.

"Government and commercial organisations… should use open source applications with great caution," the report concluded.

All software development carries the risk of vulnerabilities in the code, the report noted, but the open source community trails in-house development and commercial rivals when it comes to developing enterprise-class security support, it suggested.

"Today’s enterprises are built and operated by software that comes from a variety of sources - but as we’re seeing more often, can be based on open source," said Roger Thornton, chief technology officer at Fortify.

Fortify based its analysis on a study carried out by application security consultant Larry Suto, in conjunction with Fortify's Security Research Group. Eleven open source Java applications were examined, using Source Code Analysis (the static analyser module in Fortify's recently released Fortify 360 package), including the Geronimo, JBoss and Tomcat application servers, the Struts web application framework and the OpenCMS content management solution.

These applications were then evaluated for the sophistication of their security support, including documentation and availability of support.

Fortifuy concluded that many open source applications provide inadequate access to security expertise, do not adopt a sufficiently rigorous approach to security in the development process, and do not use state-of-the-art tools to test application security.

Tags:

reader comments

related articles

hacker

Gartner predicts great things for security-as-a-service

Analyst firm says cloud-based security services will rocket in popularity over next five years 16 Jul 2008

 

Sun adds to open storage range

Sun promises unparalleled price-performance from new open storage range 10 Jul 2008

Balancing mobility with security is a fine art

IT managers must keep their eye on risks as mobile devices become widespread 19 Jun 2008

Red Hat unveils virtualisation plans

Open source hypervisor and management console enters beta testing 19 Jun 2008

Sun touts open integration platform

Sun unveils Java Caps 6, its open source integration platform 09 Jun 2008

Ubuntu clears path to enterprises

Desktop and server editions of Ubuntu OS are targetted at enterprise users 22 Apr 2008

Enterprises warned on open source security

Poor coding leading to unnecessary risks 22 Jul 2008

Specsavers focuses on automation

Retailer makes further improvements to open source in-store platform 31 Jul 2008

Fortify delivers software lifecycle assurance

New tools to guard software throughout lifecycle 31 Mar 2008

related whitepapers

today's top stories

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Rules of convergence

While moving to a converged communications platform can bring greater efficiency and flexibility to business dealings, there are also potential legal complications related such matters as data retention and disclosure, as Jon Fell explains 18 Nov 2008

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Will poor integration derail smart tickets?

Next year could prove to be make or break for plans to have a nationwide smart ticketing scheme in place in time for the 2012 Games, writes Angelica Mari 13 Nov 2008

Computing podcast: Defra's green leadership; and integrated transport problems

Defra is making headway with its green IT strategy; and experts warn integration issues could derail smart tickets 13 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Has the state of the economy forced to re-evaluate your IT purchasing options?

Has the state of the economy forced to re-evaluate your IT purchasing options?

Are you re-thinking your IT spending?

Previous poll results

Latest audio and video articles

crowd of peopleVideo

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Audio

Computing podcast: Defra's green leadership; and integrated transport problems

Defra is making headway with its green IT strategy; and experts warn integration issues could derail smart tickets 13 Nov 2008

Latest in-depth articles

Woman wearing a headsetFeatures

How to ensure a smooth converged comms transition

Convergence strategies must be planned carefully, implemented gradually, and follow a clear business plan, writes Josie Sephton 18 Nov 2008

Arriva bus driver and mobile ticketing systemAnalysis

Will poor integration derail smart tickets?

Next year could prove to be make or break for plans to have a nationwide smart ticketing scheme in place in time for the 2012 Games, writes Angelica Mari 13 Nov 2008

Advertisement

Primary Navigation