Economics of Software Vulnerability Disclosure

  • Authors:
  • Ashish Arora;Rahul Telang

  • Affiliations:
  • Carnegie Mellon University;Carnegie Mellon University

  • Venue:
  • IEEE Security and Privacy
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Information security breaches frequently exploit software flaws or vulnerabilities, causing significant economic losses. Considerable debate and disagreement exist about how to disclose vulnerabilities to the public. A theoretical framework helps identify the key data elements needed to develop a sensible way of handling vulnerability disclosure. The authors analyzed two data setsývendor response to disclosure and attack data from honeypotsýwhich are useful for understanding how attackers respond to disclosure.