Aug 28 – 30, 2026
Asia/Kolkata timezone

Risk aware Open Source Software Contribution

Aug 29, 2026, 10:20 AM
20m
Room 2

Room 2

Talk (20 min) Security

Speaker

Mr S. Venkatesan

Description

Abstract: The use of Open Source Software in cybersecurity is increasing because its source code is transparent and can be reviewed by the public. Anyone can propose contributions to many open source projects, however, these contributions are reviewed and validated by the project maintainers before being incorporated into the official codebase. The open source softwares is used by individuals as well as the small, medium and large scale organizations. The security bug in a software will affect every user and increase the risk to the confidentiality, integrity, and availability of their systems and data. Therefore, this becomes the easiest attack vector for the attacker to compromise millions of users in a single attack or update instead of attempting to compromise every user individually. An attack may involve unauthorized modification of the software or the submission of malicious or vulnerable code as a contribution. Although all code contributions are reviewed and verified before being incorporated into the official codebase, there is still a possibility that malicious code or subtle vulnerabilities may escape detection and be included in the software. There are incidents where contributors intentionally or unknowingly left the software with bugs. The impact of such a scenario can be significant because open source software is widely used. Therefore, contributors should understand the potential impact of their changes and contribute to open source projects responsibly and ethically to mitigate the security risk. Also, when using LLM for the code generation, contributors need to analyse the code in detail to identify security vulnerabilities, logical errors, and other defects, reducing the burden on project maintainers and improving the overall security of the software

Any other info we should know?

Schedule on Aug 29 in the morning

Session author's bio

I am a faculty member at IIIT Allahabad with research interests in cybersecurity, particularly network security and secure software systems. My work focuses on understanding emerging security challenges in modern computing environments, including risks associated with open source software and secure software development practices. I am interested in promoting responsible and ethical software contribution, software assurance, and cybersecurity awareness through teaching and research. My goal is to bridge theoretical concepts with practical approaches that help build secure, reliable, and resilient software systems.

Level of Difficulty Intermediate
Please confirm that there are included headshots of all speakers in their profiles Yes
Agree to Privacy Policy and Notice I agree
In Person Attendance In-person

Presentation materials

There are no materials yet.