arrow
返回

Empirical analysis of security vulnerabilities in Python packages

delete2023-03-25
delete18
PRE
AI
M
Mahmoud Alfadel *
D
Diego Elias Costa
E
Emad Shihab
DOI:10.1007/s10664-022-10278-4delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Software ecosystems play an important role in modern software development, providing an open platform of reusable packages that speed up and facilitate development tasks. However, this level of code reusability supported by software ecosystems also makes the discovery of security vulnerabilities much more difficult, as software systems depend on an increasingly high number of packages. Recently, security vulnerabilities in the npm ecosystem, the ecosystem of Node.js packages, have been studied in the literature. As different software ecosystems embody different programming languages and particularities, we argue that it is also important to study other popular programming languages to build stronger empirical evidence about vulnerabilities in software ecosystems. In this paper, we present an empirical study of 1,396 vulnerability reports affecting 698 Python packages in the Python ecosystem (PyPi). In particular, we study the propagation and life span of security vulnerabilities, accounting for how long they take to be discovered and fixed. In addition, vulnerabilities in packages may affect software projects that depend on them (dependent projects), making them vulnerable too. We study a set of 2,224 GitHub Python projects, to better understand the prevalence of vulnerabilities in their dependencies and how fast it takes to update them. Our findings show that the discovered vulnerabilities in Python packages are increasing over time, and they take more than 3 years to be discovered. A large portion of these vulnerabilities (40.86%) are only fixed after being publicly announced, giving ample time for attackers exploitation. Moreover, we find that more than half of the dependent projects rely on at least one vulnerable package, taking a considerably long time (7 months) to update to a non-vulnerable version. We find similarities in some characteristics of vulnerabilities in PyPi and npm and divergences that can be attributed to specific PyPi policies. By leveraging our findings, we provide a series of implications that can help the security of software ecosystems by improving the process of discovering, fixing and managing package vulnerabilities.
Keyword:
Python
PyPi
Packages
Vulnerabilities
Empirical studies

期刊

Empirical Software Engineering 封面图
Empirical Software Engineering
IF:
3.6
论文数:
2.0K
被引数:
5.3K

机构

C
concordia university - canada
学者数:
8.0K
论文数: 8.9K
被引数: 4
U
university of quebec
学者数:
2.0W
论文数: 1.9W
被引数: 19
引用论文

引用论文

The Effects of 12 Weeks Yoga Training on 4-5-Year-Old Preschoolers’ Fitness Components
err2023-04-01
err0
errOAAI
errDung Xuan Phung; Vinh Quang Nguyen; Dai Quang Tran; Truong Ngoc Duong
err分享
err收藏
?-1,4-Glucosidase activity in infertile oligoasthenozoospermic men with and without varicocele
err2007-02-01
err0
errOAAI
errM. M. F. Roaiah; T. Mostafa; D. Salem; A. R. El-Nashar; I. I. Kamel; M. S. El-Kashlan
err分享
err收藏
Short-Term Effects of Cattle Browsing on Tree Sapling Growth in Mountain Wooded Pastures
err2006-06-09
err0
PREAI
errCharlotte Vandenberghe; François Freléchoux; Marie-Agnès Moravie; Fawziah Gadallah; Alexandre Buttler
err分享
err收藏
err分享
err收藏
学者 查看更多内容