An Overview of Cyber Security Funding for Open Source Software

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ruohonen, Jukka, Choudhary, Gaurav, Alami, Adam
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916014323662848
author Ruohonen, Jukka
Choudhary, Gaurav
Alami, Adam
author_facet Ruohonen, Jukka
Choudhary, Gaurav
Alami, Adam
contents Many open source software (OSS) projects need more human resources for maintenance, improvements, and sometimes even their survival. These needs allegedly apply even to vital OSS projects that can be seen as being a part of the world's critical infrastructures. To address this resourcing problem, new funding instruments for OSS projects have been established in recent years. The paper examines two such funding bodies for OSS and the projects they have funded. The focus of both funding bodies is on software security and cyber security in general. Based on qualitative thematic analysis, the results indicate that particularly OSS supply chains, network and cryptography libraries, programming languages, and operating systems and their low-level components have been funded and thus seen as critical in terms of cyber security. In addition to the qualitative results presented, the paper makes a contribution by connecting the research branches of critical infrastructure and sustainability of OSS projects. A further contribution is made by connecting the topic examined to recent cyber security regulations. Finally, an important argument is raised that neither cyber security nor project sustainability alone can entirely explain the rationales behind the funding decisions made by the two funding bodies.
format Preprint
id arxiv_https___arxiv_org_abs_2412_05887
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle An Overview of Cyber Security Funding for Open Source Software
Ruohonen, Jukka
Choudhary, Gaurav
Alami, Adam
Cryptography and Security
Computers and Society
Software Engineering
Many open source software (OSS) projects need more human resources for maintenance, improvements, and sometimes even their survival. These needs allegedly apply even to vital OSS projects that can be seen as being a part of the world's critical infrastructures. To address this resourcing problem, new funding instruments for OSS projects have been established in recent years. The paper examines two such funding bodies for OSS and the projects they have funded. The focus of both funding bodies is on software security and cyber security in general. Based on qualitative thematic analysis, the results indicate that particularly OSS supply chains, network and cryptography libraries, programming languages, and operating systems and their low-level components have been funded and thus seen as critical in terms of cyber security. In addition to the qualitative results presented, the paper makes a contribution by connecting the research branches of critical infrastructure and sustainability of OSS projects. A further contribution is made by connecting the topic examined to recent cyber security regulations. Finally, an important argument is raised that neither cyber security nor project sustainability alone can entirely explain the rationales behind the funding decisions made by the two funding bodies.
title An Overview of Cyber Security Funding for Open Source Software
topic Cryptography and Security
Computers and Society
Software Engineering
url https://arxiv.org/abs/2412.05887