Information Disclosure and the Diffusion of Information Security Attacks

被引:54
|
作者
Mitra, Sabyasachi [1 ]
Ransbotham, Sam [2 ]
机构
[1] Georgia Inst Technol, Atlanta, GA 30332 USA
[2] Boston Coll, Chestnut Hill, MA 02467 USA
基金
美国国家科学基金会;
关键词
information security; information disclosure; software vulnerability; diffusion of innovation; negative innovation; PRODUCT DIFFUSION; VULNERABILITY; TECHNOLOGY; MODEL; SYSTEMS; PATCH; DETERRENCE; INNOVATION; BEHAVIOR; MARKETS;
D O I
10.1287/isre.2015.0587
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
With the nearly instantaneous dissemination of information in the modern era, policies regarding the disclosure of sensitive information have become the focus of significant discussion in several contexts. The fundamental debate centers on trade-offs inherent in disclosing information that society needs, but that can also be used for nefarious purposes. Using information security as a research context, our empirical study examines the adoption of software vulnerabilities by a population of attackers. We compare attacks based on software vulnerabilities disclosed through full-disclosure and limited-disclosure mechanisms. We find that full disclosure accelerates the diffusion of attacks, increases the penetration of attacks within the target population, and increases the risk of first attack after the vulnerability is reported. Interestingly, the effect of full disclosure is greater during periods when there are more overall vulnerabilities reported, indicating that attackers may strategically focus on busy periods when the effort of security professionals is spread across many vulnerabilities. Although the aggregate volume of attacks remains unaffected by full disclosure, attacks occur earlier in the life cycle of the vulnerability. Building off our theoretical insights, we discuss the implications of our findings in more general contexts.
引用
收藏
页码:565 / 584
页数:20
相关论文
共 50 条
  • [1] SDN Security: Information Disclosure and Flow Table Overflow Attacks
    Patwardhan, Aditya
    Jayarama, Deepthi
    Limaye, Nitish
    Vidhale, Shivaji
    Parekh, Zarna
    Harfoush, Khaled
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [2] Information Disclosure as a Means to Security
    Rabinovich, Zinovi
    Jiang, Albert Xin
    Jain, Manish
    Xu, Haifeng
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON AUTONOMOUS AGENTS & MULTIAGENT SYSTEMS (AAMAS'15), 2015, : 645 - 653
  • [3] Information disclosure and security information protection at water utilities
    Herrick, Charles
    Blaha, Frank J.
    [J]. JOURNAL AMERICAN WATER WORKS ASSOCIATION, 2007, 99 (11): : 40 - 42
  • [4] Information Disclosure, Security, and Data Quality
    Zaman, A. N. K.
    Obimbo, Charlie
    Dara, Rozita A.
    [J]. RECENT TRENDS AND FUTURE TECHNOLOGY IN APPLIED INTELLIGENCE, IEA/AIE 2018, 2018, 10868 : 768 - 779
  • [5] Inference Attacks and Information Security in Databases
    Poltavtsev, A. A.
    Khabarov, A. R.
    Selyankin, A. O.
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2020, 54 (08) : 829 - 833
  • [6] Inference Attacks and Information Security in Databases
    A. A. Poltavtsev
    A. R. Khabarov
    A. O. Selyankin
    [J]. Automatic Control and Computer Sciences, 2020, 54 : 829 - 833
  • [7] Protecting sensitive information in the volatile memory from disclosure attacks
    Malliaros, Stefanos
    Ntantogian, Christoforos
    Xenakis, Christos
    [J]. PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 687 - 693
  • [8] Improving Internet Security Through Mandatory Information Disclosure
    Tang, Qian
    Whinston, Andrew B.
    [J]. 2015 48TH HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2015, : 4813 - 4823
  • [9] Research on the Accounting Information Disclosure Problem of the Security Market
    Yan Yanxu
    [J]. PROCEEDINGS OF 2014 INTERNATIONAL SYMPOSIUM - DEVELOPMENT OF MODERN SERVICE INDUSTRY, 2014, : 204 - 208
  • [10] Security Attacks on Information Centric Networking for Healthcare System
    Naik, B. Balaji
    Singh, Dhananjay
    Samaddar, A. B.
    Lee, Hoon-Jae
    [J]. 2017 19TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATIONS TECHNOLOGY (ICACT) - OPENING NEW ERA OF SMART SOCIETY, 2017, : 436 - 441