Determinants of Software Vulnerability Disclosure Timing

被引:10
|
作者
Sen, Ravi [1 ]
Choobineh, Joobin [1 ]
Kumar, Subodha [2 ]
机构
[1] Texas A&M Univ, Informat & Operat Management, 320S Wehner Bldg,4217 TAMU, College Stn, TX 77843 USA
[2] Temple Univ, Fox Sch Business, 1801 Liacouras Walk,Alter Hall 530, Philadelphia, PA 19122 USA
关键词
vulnerability; vulnerability disclosure; cybersecurity; software; motivation; EMPIRICAL-ANALYSIS; PATCH RELEASE; INFORMATION; SECURITY; MOTIVATION; SERVICE; IMPACT; RATIONALITY; PERFORMANCE; MANAGEMENT;
D O I
10.1111/poms.13120
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The timing of vulnerability disclosures (by vulnerability discoverers) has significant implications for software producers and users. Immediate disclosure (before a patch becomes available) could result in exploits with subsequent harm to installed systems. Therefore, it is important to understand the determinants of this timing. In this study, we investigate the impacts of (i) the perception of the vulnerability discoverer about the software producer, (ii) the type of vulnerable software, and (iii) the severity of the vulnerability, on a vulnerability discoverer's choice of disclosure timing. We collect data from three different sources and control for the vulnerability discoverer's motivations and beliefs. Our results indicate that those who perceive a software producer to be timely in its patch release, reward it by delaying the disclosure. We also find that it is more likely that the disclosure is delayed for open source software and it is less likely that the disclosure is delayed for more severe vulnerabilities. The findings of this study are relevant to software producers in their decision-making process on resource allocation for software patches and should also help policy-makers to devise regulations relevant to the timing of disclosures and patch releases. Furthermore, these findings could be relevant to software consumers searching for a particular software product that they would like to use. This study attempts to provide insights into an ongoing discussion in the operations management community regarding how to allocate and divide resources between software development and software maintenance.
引用
收藏
页码:2532 / 2552
页数:21
相关论文
共 50 条
  • [1] Economics of software vulnerability disclosure
    Arora, A
    Telang, R
    [J]. IEEE SECURITY & PRIVACY, 2005, 3 (01) : 20 - 25
  • [2] Optimal policy for software vulnerability disclosure
    Arora, Ashish
    Telang, Rahul
    Xu, Hao
    [J]. MANAGEMENT SCIENCE, 2008, 54 (04) : 642 - 656
  • [3] A comparison of market approaches to software vulnerability disclosure
    Boehme, Rainer
    [J]. EMERGING TRENDS IN INFORMATION AND COMMUNICATION SECURITY, PROCEEDINGS, 2006, 3995 : 298 - 311
  • [4] Exploring the Clustering of Software Vulnerability Disclosure Notifications Across Software Vendors
    Ruohonen, Jukka
    Holvitie, Johannes
    Hyrynsalmi, Sami
    Leppanen, Ville
    [J]. 2016 IEEE/ACS 13TH INTERNATIONAL CONFERENCE OF COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2016,
  • [5] An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure
    Arora, Ashish
    Krishnan, Ramayya
    Telang, Rahul
    Yang, Yubao
    [J]. INFORMATION SYSTEMS RESEARCH, 2010, 21 (01) : 115 - 132
  • [6] An empirical analysis of vulnerability information disclosure impact on patch R&D of software vendors
    Xiong, Qiang
    Lian, Shuai
    Zeng, Zhangying
    He, Runxin
    Zhu, Binxin
    Yang, Xinqi
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 44 (01) : 839 - 853
  • [7] Responsible Vulnerability Disclosure in Cryptocurrencies
    Boehme, Rainer
    Eckey, Lisa
    Moore, Tyler
    Narula, Neha
    Ruffing, Tim
    Zohar, Aviv
    [J]. COMMUNICATIONS OF THE ACM, 2020, 63 (10) : 62 - 71
  • [8] Vulnerability Disclosure Considered Stressful
    Moura, Giovane C. M.
    Heidemann, John
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2023, 53 (02) : 3 - 10
  • [9] Anticipatory Ethics for Vulnerability Disclosure
    Huskaj, Gazmend
    Wilson, Richard L.
    [J]. PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2020), 2020, : 254 - 261
  • [10] New hurdles for vulnerability disclosure
    McKinney, Dave
    [J]. IEEE SECURITY & PRIVACY, 2008, 6 (02) : 76 - 78