An empirical analysis of vulnerability information disclosure impact on patch R&D of software vendors

被引:3
|
作者
Xiong, Qiang [1 ]
Lian, Shuai [1 ]
Zeng, Zhangying [2 ]
He, Runxin [3 ]
Zhu, Binxin [1 ]
Yang, Xinqi [1 ]
机构
[1] Jiangsu Univ, Sch Management, Zhenjiang 212013, Jiangsu, Peoples R China
[2] Jiangsu Univ, Dept Technol & Sci, Zhenjiang, Jiangsu, Peoples R China
[3] Baidu USA LLC, Bordeaux Dr, Sunnyvale, CA USA
关键词
Patch R&D; vulnerability information disclosure; information processing theory; third-party vulnerability sharing platforms; INNOVATION; MARKET;
D O I
10.3233/JIFS-221316
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The vulnerability patch R&D has become an important part of information security governance. An effective collaboration with software vendors in patch R&D is of great significance to reduce the existence time of information security risks. This works aims to explore the relationship between vulnerability information disclosure and patch R&D of software vendors. The data regarding the vulnerability and software vendors is gathered from third-party vulnerability sharing platforms, including (Chinas national information security vulnerability database, CNNVD) and Tianyacha.com. Based on the theory of organizational information processing, linear regression model and Cox proportional risk regression model are built for appropriately addressing the research questions. The results show that the vulnerability disclosure of the third-party sharing platform can improve the patch R&D probability of software vendors. The information processing requirements, such as vulnerability information attention, vulnerability score and whether vulnerabilities are disclosed in advance accelerate the vulnerability patch R&D. The enterprise information processing capability indicators, including the industry dependence of software product customers and the staff size of software vendors accelerate the patch R&D. The number of products affected by the vulnerabilities and the number of software copyrights of software vendors have no significant impact on patch R&D.
引用
收藏
页码:839 / 853
页数:15
相关论文
共 50 条
  • [1] An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure
    Arora, Ashish
    Krishnan, Ramayya
    Telang, Rahul
    Yang, Yubao
    [J]. INFORMATION SYSTEMS RESEARCH, 2010, 21 (01) : 115 - 132
  • [2] Exploring the Clustering of Software Vulnerability Disclosure Notifications Across Software Vendors
    Ruohonen, Jukka
    Holvitie, Johannes
    Hyrynsalmi, Sami
    Leppanen, Ville
    [J]. 2016 IEEE/ACS 13TH INTERNATIONAL CONFERENCE OF COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2016,
  • [3] Patch Release Behaviors of Software Vendors in Response to Vulnerabilities: An Empirical Analysis
    Temizkan, Orcun
    Kumar, Ram L.
    Park, SungJune
    Subramaniam, Chandrasekar
    [J]. JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2012, 28 (04) : 305 - 337
  • [4] An Empirical Analysis of the Impact of R&D on Productivity in EU Countries
    Mykolenko, O.
    Strapchuk, S.
    Kozyreva, O.
    [J]. EUROPEAN FINANCIAL SYSTEMS 2019, 2019, : 377 - 384
  • [5] Coupling Information Disclosure with a Quality Standard in R&D Contests
    Cai, Gaoyang
    Jiao, Qian
    Lu, Jingfeng
    Zheng, Jie
    [J]. JOURNAL OF INDUSTRIAL ECONOMICS, 2024,
  • [6] DETERMINANTS OF R&D COLLABORATION: AN EMPIRICAL ANALYSIS
    Henttonen, Kaisa
    Hurmelinna-Laukkanen, Pia
    [J]. INTERNATIONAL JOURNAL OF INNOVATION MANAGEMENT, 2014, 18 (04)
  • [7] THE IMPACT OF R&D ON THE SINGAPORE ECONOMY: AN EMPIRICAL EVALUATION
    Ho, Yuen Ping
    Wong, Poh Kam
    Toh, Mun Heng
    [J]. SINGAPORE ECONOMIC REVIEW, 2009, 54 (01): : 1 - 20
  • [8] Asymmetric Information and R&D Disclosure: Evidence from Scientific Publications
    Baruffaldi, Stefano
    Simeth, Markus
    Wehrheim, David
    [J]. MANAGEMENT SCIENCE, 2024, 70 (02) : 1052 - 1069
  • [9] Research on the Relationship Between R&D Information Disclosure and Firm Performance
    Li Yuanhui
    Wang Jiali
    [J]. PROCEEDINGS OF THE THIRD INTERNATIONAL SYMPOSIUM - MANAGEMENT, INNOVATION & DEVELOPMENT, BKS ONE & TWO, 2016, : 135 - 140
  • [10] Does information security attack frequency increase with vulnerability disclosure? An empirical analysis
    Ashish Arora
    Anand Nandkumar
    Rahul Telang
    [J]. Information Systems Frontiers, 2006, 8 : 350 - 362