【24h】

Trading exploits online: A preliminary case study

机译:在线交易漏洞利用:初步案例研究

获取原文

摘要

A software defect that exposes a software system to a cyber security attack is known as a software vulnerability. A software security exploit is an engineered software solution that successfully exploits the vulnerability. Exploits are used to break into computer systems, but exploits are currently used also for security testing, security analytics, intrusion detection, consultation, and other legitimate and legal purposes. A well-established market emerged in the 2000s for software vulnerabilities. The current market segments populated by small and medium-sized companies exhibit signals that may eventually lead to a similar industrialization of software exploits. To these ends and against these industry trends, this paper observes the first online market place for trading exploits between buyers and sellers. The paper adopts three different perspectives to study the case. The paper (a) portrays the studied exploit market place against the historical background in the software security industry. A qualitative assessment is made to (b) evaluate the case against the common characteristics of traditional online market places. The qualitative observations are used in the quantitative part (c) for predicting the price of exploits with partial least squares regression. The results show that (i) the case is unique from a historical perspective, although (ii) the online market place characteristics are familiar. The regression estimates also indicate that (iii) the pricing of exploits is only partially dependent on such factors as the targeted platform, the date of disclosure of the exploited vulnerability, and the quality assurance service provided by the market place provider. The results allow to contemplate (iv) practical means for enhancing the market place.
机译:使软件系统遭受网络安全攻击的软件缺陷称为软件漏洞。软件安全漏洞利用是一种成功利用此漏洞的工程软件解决方案。漏洞被用来侵入计算机系统,但是目前漏洞也被用于安全测试,安全分析,入侵检测,咨询以及其他合法和合法目的。 2000年代出现了一个完善的软件漏洞市场。由中小型公司组成的当前细分市场展现出的信号可能最终导致类似的软件利用产业化。为此,针对这些行业趋势,本文观察了买卖双方之间第一个利用交易进行交易的在线市场。本文采用三种不同的观点来研究该案例。论文(a)在软件安全行业的历史背景下描绘了所研究的漏洞利用市场。进行定性评估以(b)根据传统在线市场的共同特征评估案例。定性观察结果用于定量部分(c)中,用于通过偏最小二乘回归预测漏洞利用程序的价格。结果表明,(i)从历史的角度来看,这种情况是独特的,尽管(ii)网上市场特征是熟悉的。回归估计还表明(iii)漏洞利用的价格仅部分取决于目标平台,漏洞利用的披露日期以及市场提供者提供的质量保证服务等因素。结果允许考虑(iv)增强市场地位的实用手段。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号