An Overview of Cyber Security Funding for Open Source Software
Jukka Ruohonen, Gaurav Choudhary, Adam Alami

TL;DR
This paper reviews recent funding initiatives for open source software focused on cybersecurity, analyzing their impact on critical OSS components and connecting infrastructure, sustainability, and regulation aspects.
Contribution
It provides a qualitative analysis of two funding bodies, linking cybersecurity, critical infrastructure, and OSS sustainability, and discusses the rationale behind funding decisions.
Findings
Funding mainly targets supply chains, cryptography libraries, and operating systems.
Critical OSS components are prioritized due to cybersecurity importance.
Funding decisions are influenced by factors beyond cybersecurity and sustainability.
Abstract
Many open source software (OSS) projects need more human resources for maintenance, improvements, and sometimes even their survival. These needs allegedly apply even to vital OSS projects that can be seen as being a part of the world's critical infrastructures. To address this resourcing problem, new funding instruments for OSS projects have been established in recent years. The paper examines two such funding bodies for OSS and the projects they have funded. The focus of both funding bodies is on software security and cyber security in general. Based on qualitative thematic analysis, the results indicate that particularly OSS supply chains, network and cryptography libraries, programming languages, and operating systems and their low-level components have been funded and thus seen as critical in terms of cyber security. In addition to the qualitative results presented, the paper makes…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · FinTech, Crowdfunding, Digital Finance · Scientific Computing and Data Management
