Loading Events

« All Events

Hybrid Event

Gomez, J. (CSE) – Toward Sustainable and Secure Open Source Software: Discovery, Measurement, and Defense

August 25 @ 11:00 am1:00 pm
Hybrid Event
Abstract digital illustration featuring gears and interconnected technology elements.

In March 2024, a backdoor was discovered in xz Utils, a widely used open source data compression library present in nearly every major Linux distribution. The attack was discovered days before merging into major distributions, and if this had happened, it would have allowed attackers to execute arbitrary code on millions of systems worldwide via SSH.

The success of this backdoor was enabled by two failures. The first was technical: weaknesses in the software supply chain allowed a malicious actor to inject code into a widely trusted release. The second was human: the project’s only maintainer, overwhelmed and burned out after years of maintaining critical infrastructure alone, was the target of a multi-year social engineering campaign, in which a malicious actor built trust under a false identity and gradually obtained commit access to the project. This incident shows that software security failures and sustainability failures are not independent: an overburdened, unsupported maintainer is itself an attack surface.

Academic and scientific open source software (OSS) faces both of these crises simultaneously. Projects that critical infrastructure depends on are maintained by researchers, students, and faculty who contribute in their spare time, without dedicated security training or institutional support. Existing security frameworks including NIST’s SSDF, OWASP’s SCVS, and SLSA were not designed with these communities in mind, and policy efforts such as the EU Cyber Resilience Act have shown that mandates developed without community input risk harming the ecosystems they are meant to protect.

This dissertation addresses the sustainability and security of academic open source software through two parallel empirical research tracks. The sustainability track combines GitHub’s REST API with LLM-based filtering to discover and characterize over 216,000 institutionally affiliated repositories across 32 academic and research institutions, finding that while 84\% include a README, only 23.4% carry a detectable license and fewer than 2% include a Contributing Guide. Building on this dataset, we develop a maturity-staged sustainability framework that classifies projects into four lifecycle stages and generates targeted recommendations for Open Source Program Offices (OSPOs).

The security track examines whether post-9/11 trade security programs offer a workable model for OSS supply-chain policy, finding that effective frameworks require voluntary incentives and direct community engagement rather than top-down mandates. We further evaluate five large language models on the OWASP Benchmark for vulnerability triage, finding that o1-mini reduces false positives by 20% over the Semgrep baseline, demonstrating the potential for automation to reduce the security burden on individual maintainers.

Together, these contributions treat sustainability and security as interconnected problems. A project that cannot sustain itself cannot secure its code, and this dissertation takes steps toward closing both gaps.

 

Event Host: Juanita Gomez, Ph.D. Candidate, Computer Science & Engineering

Advisor: Alvaro Cardenas 

Zoom: https://ucsc.zoom.us/j/91057980344?pwd=XMMjHZVgbbLXfwxKehrTEbat18066o.1

Passcode: 292091

Details

Other

Room Number
E2-399

Venue