首页> 外文会议>International conference on information systems >The Effects of Vulnerability Disclosure Policy on the Diffusion of Security Attacks
【24h】

The Effects of Vulnerability Disclosure Policy on the Diffusion of Security Attacks

机译:漏洞披露政策对安全攻击扩散的影响

获取原文

摘要

With the nearly instantaneous spread of information in modern society, policies regarding the disclosure of information about security vulnerabilities have become the focus of significant discussion. The fundamental debate centers on tradeoffs inherent in disclosing information that security professionals need, but that can also be used for nefarious purposes. Our empirical study compares attacks based on software vulnerabilities disclosed through full disclosure and limited disclosure mechanisms. We find that full disclosure accelerates the diffusion of attacks and increases the risk of first attack after the vulnerability is reported. Building off our theoretical insights, we discuss the implications of our findings on information disclosure in more general contexts.
机译:随着信息在现代社会中的瞬间传播,有关安全漏洞信息公开的政策已成为重要讨论的焦点。基本的辩论集中在公开安全专业人员需要的信息时固有的权衡取舍,但这也可以用于邪恶目的。我们的实证研究比较了基于通过完全披露和有限披露机制披露的软件漏洞的攻击。我们发现,全面披露会加速攻击的传播,并在报告漏洞后增加首次攻击的风险。基于我们的理论见解,我们将在更一般的情况下讨论我们的发现对信息披露的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号