A comparison of market approaches to software vulnerability disclosure

被引:0
|
作者
Boehme, Rainer [1 ]
机构
[1] Tech Univ Dresden, Inst Syst Architecture, D-01062 Dresden, Germany
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Practical computer (in)security is largely driven by the existence of and knowledge about vulnerabilities, which can be exploited to breach security mechanisms. Although the discussion on details of responsible vulnerability disclosure is controversial, there is a sort of consensus that better information sharing is socially beneficial. In the recent years we observe the emerging of "vulnerability markets" as means to stimulate exchange of information. However, this term subsumes a broad range of different concepts, which are prone to confusion. This paper provides a first attempt to structure the field by (1) proposing a terminology for distinct concepts and (2) defining criteria to allow for a better comparability between different approaches. An application of this framework on four market types shows notable differences between the approaches.
引用
收藏
页码:298 / 311
页数:14
相关论文
共 50 条
  • [1] Economics of software vulnerability disclosure
    Arora, A
    Telang, R
    [J]. IEEE SECURITY & PRIVACY, 2005, 3 (01) : 20 - 25
  • [2] Determinants of Software Vulnerability Disclosure Timing
    Sen, Ravi
    Choobineh, Joobin
    Kumar, Subodha
    [J]. PRODUCTION AND OPERATIONS MANAGEMENT, 2020, 29 (11) : 2532 - 2552
  • [3] Optimal policy for software vulnerability disclosure
    Arora, Ashish
    Telang, Rahul
    Xu, Hao
    [J]. MANAGEMENT SCIENCE, 2008, 54 (04) : 642 - 656
  • [4] Exploring the Clustering of Software Vulnerability Disclosure Notifications Across Software Vendors
    Ruohonen, Jukka
    Holvitie, Johannes
    Hyrynsalmi, Sami
    Leppanen, Ville
    [J]. 2016 IEEE/ACS 13TH INTERNATIONAL CONFERENCE OF COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2016,
  • [5] The rise of software vulnerability: Taxonomy of software vulnerabilities detection and machine learning approaches
    Hanif, Hazim
    Nasir, Mohd Hairul Nizam Md
    Ab Razak, Mohd Faizal
    Firdaus, Ahmad
    Anuar, Nor Badrul
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 179
  • [6] An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure
    Arora, Ashish
    Krishnan, Ramayya
    Telang, Rahul
    Yang, Yubao
    [J]. INFORMATION SYSTEMS RESEARCH, 2010, 21 (01) : 115 - 132
  • [7] Vulnerability disclosure mechanisms: A synthesis and framework for market-based and non-market-based disclosures
    Ahmed, Ali
    Deokar, Amit
    Lee, Ho Cheung Brian
    [J]. DECISION SUPPORT SYSTEMS, 2021, 148
  • [8] Software vulnerability design and approaches for securing SCADA control systems
    Cagalaban, Giovanni
    Song, Jae-Gu
    Jung, Sungmo
    Kim, Seok Soo
    [J]. International Journal of Smart Home, 2009, 3 (01): : 49 - 56
  • [9] Three approaches to labor-market vulnerability and political preferences
    Marx, Paul
    Picot, Georg
    [J]. POLITICAL SCIENCE RESEARCH AND METHODS, 2020, 8 (02) : 356 - 361
  • [10] Comparison between disclosure and non-disclosure approaches for trisomy 21 screening tests
    Herman, A
    Dreazen, E
    Tovbin, J
    Weinraub, Z
    Bukovsky, Y
    Maymon, R
    [J]. HUMAN REPRODUCTION, 2002, 17 (05) : 1358 - 1362