researchvulnerabilitypatchingbenchmarkingopensource-vs-closedsource

Schryen — Is Open Source Security a Myth?, CACM

Provides an empirical foundation for comparing open and closed source risk, concluding that maintainer/vendor policy is the primary determinant of security posture.

Summary

An empirical study of 17 widely deployed software packages across seven application types found no statistically significant difference in security between open source and closed source development. Analysis of NIST NVD data showed that for 12 of 17 packages, the rate of vulnerability disclosure remains linear over time, contradicting the assumption that community review accelerates the 'shallowing' of bugs. Median lifetimes for foundational vulnerabilities, such as those in OpenBSD, were found to exceed 2.6 years. Most critically, the study proves that patching behavior is driven by individual vendor policy rather than development style: while 17.6% of open source vulnerabilities remained unpatched, 30.4% of closed source ones were also left open, with some vendors (e.g., Microsoft) leaving up to two-thirds of client-side vulnerabilities unaddressed.

Related Checks

VULN_UNFIXED

The study found that 17.6% of open source and 30.4% of closed source vulnerabilities remained unpatched months after disclosure.

Adverse Outcome

persistent exposure to known vulnerabilities that vendors have chosen to ignore for economic reasons

Because

tracking unpatched vulnerabilities directly measures the effectiveness of vendor/maintainer security policies, which the study identifies as the primary driver of risk.

Gaps Analysis

Evidence

The analysis illustrates there is no empirical evidence that the particular type of software development is the primary driver of security. Rather, the particular policies of vendors determine the patching behavior.

Blind Spot

Risk Guard assumes open source signals are unique indicators of risk, but does not benchmark them against closed-source equivalents or consider 'Vendor Policy' as a distinct signal.

Actionable Capability

Risk Guard would be better if it integrated a 'Vendor Response Reputation' score that tracked the maintainer's historical adherence to their own stated patching policies.

← Previous Next →