...
首页> 外文期刊>Information systems frontiers >An examination of private intermediaries' roles in software vulnerabilities disclosure
【24h】

An examination of private intermediaries' roles in software vulnerabilities disclosure

机译:审查私人中介在软件漏洞披露中的作用

获取原文
获取原文并翻译 | 示例
           

摘要

Software vulnerability disclosure has generated much interest and debate. Recently some private intermediaries have entered this market. This paper examines the effects of such private intermediaries on optimal timing of disclosure policy made by public intermediaries and vendors' reactions. Our analysis of private intermediaries' role suggests that public intermediary's optimal disclosure time does not change with private intermediary's participation. However, a vendor's patch time increases when the probability of information leakage is low, if not non-existent. In other words, private intermediaries' service decreases a vendor's willingness to deliver quick patches. Empirical evidence with 1493 vulnerability observations from CERT/ CC and other 326 different vulnerability observations from iDefense provided support for our analytical results.
机译:软件漏洞披露引起了极大的兴趣和争论。最近一些私人中介进入了这个市场。本文研究了这种私人中介对公共中介制定的最佳披露时机和卖方反应的影响。我们对私人中介机构作用的分析表明,公共中介机构的最佳披露时间不会随私人中介机构的参与而改变。但是,如果信息泄漏的可能性很小(如果不存在),则厂商的补丁时间会增加。换句话说,私人中介服务降低了供应商交付快速补丁的意愿。来自CERT / CC的1493个漏洞观察以及iDefense的其他326个不同漏洞观察的经验证据为我们的分析结果提供了支持。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号