An Overview of Cyber Security Funding for Open Source Software
Many open source software (OSS) projects need more human re- sources for maintenance, improvements, and sometimes even their survival. This need allegedly applies even to vital OSS projects that can be seen as being a part of the world’s critical infrastructures. To address this resourcing problem, new funding instruments for OSS projects have been established in recent years. The paper examines two such funding bodies for OSS and the projects they have funded. The focus of both funding bodies is on software security and cyber security in general. Based on qualitative thematic analysis, the results indicate that particularly OSS supply chains, network and cryptography libraries, programming languages, and operating systems and their low-level components have been funded and thus seen as critical in terms of cyber security. In addition to the qualitative results presented, the paper makes a contribution by connecting the research branches of critical infrastructure and sustainability of OSS projects. A further contribution is made by connecting the topic examined to recent cyber security regulations. Finally, an important argument is raised that neither cyber security nor sustainability alone can entirely explain the rationales behind the funding decisions made by the two bodies.
Sat 18 AprDisplayed time zone: Brasilia, Distrito Federal, Brazil change
09:00 - 10:30 | |||
09:00 5mDay opening | Workshop Opening EnCyCriS Coralie Esnoul Institute For Energy Technology (IFE) | ||
09:05 15mFull-paper | Towards a Cognitive-Support Tool for Threat Hunters EnCyCriS Alessandra Maciel Paz Milani University of Victoria, Norman Anderson University of Victoria, Margaret-Anne Storey University of Victoria Pre-print | ||
09:20 15mFull-paper | Reflections and Factors in Applying Threat Modelling Tools for Cybersecurity Certification in Critical Infrastructure EnCyCriS Ahmed Amro Norwegian University of Science and Technology (NTNU), Vasileios Gkioulos NTNU, Claudia Lutze Hitachi Rail, Jean-Marie Lauranson Hitachi Rail, Maria I. Maslioukova Catalink, Pavlos Kosmides Catalink, Christina Michailidou Catalink, Pedro-Tito Macías-Roselló Schneider Electric, Evgeny Prokofyev Schneider Electric, Antoliano Davila Schneider Electric, Tanel Kerstna MindChip, Per Myrseth DNV, Meine Van Der Meulen DNV | ||
09:35 15mFull-paper | An Overview of Cyber Security Funding for Open Source Software EnCyCriS Jukka Ruohonen University of Southern Denmark, Gaurav Choudhary Choudhary Technical University of Denmark, Adam Alami University of Southern Denmark | ||
09:50 15mFull-paper | LLM-Assisted AHP for Explainable Cyber Range Evaluation EnCyCriS Vyron Kampourakis Norwegian University of Science and Technology NTNU, Georgios Kavallieratos Norwegian University of Science and Technology NTNU, Georgios Spathoulas Norwegian University of Science and Technology NTNU, Vasileios Gkioulos NTNU, Sokratis Katsikas Norwegian University of Science and Technology (NTNU) | ||
10:05 15mFull-paper | Behind the Quantum Curtain: A practical comparison between SVM and QSVM in OT Anomaly Detection EnCyCriS Alessio Di Santo Università degli Studi dell'Aquila, Nicola Camarda , Walter Tiberti Università degli Studi dell'Aquila, Dajana Cassioli Università degli Studi dell'Aquila | ||
10:20 10mOther | all together : picture EnCyCriS | ||