首页> 外文期刊>Decision support systems >Vulnerability disclosure mechanisms: A synthesis and framework for market-based and non-market-based disclosures
【24h】

Vulnerability disclosure mechanisms: A synthesis and framework for market-based and non-market-based disclosures

机译:漏洞披露机制:基于市场和基于非市场披露的合成和框架

获取原文
获取原文并翻译 | 示例
       

摘要

Vulnerability disclosure has been a controversial topic among scholars and practitioners. Most scholars agree on adopting the responsible disclosure practices for vulnerability disclosures, which give firms a protected period to address the vulnerability before public disclosure is made. However, the firms may not fully utilize the protected period resulting in financial and reputational losses. The recent popularity in market-based disclosure methods such as bug bounty programs has provided new methods to control ethical hackers and effectively manage the disclosure timelines. Through a systematic literature review, we investigate and identify various vulnerability disclosure mechanisms and elaborate the disclosure process of each mechanism. We synthesize and compare the antecedents and consequences of the vulnerability disclosure under market- and non-market-based disclosure mechanisms by proposing two research frameworks. Our analysis suggests that incentivizing hackers in market mechanisms change hackers' motivations, leading to behavioral changes and eventually giving firms more control over the disclosure process. Additionally, our research frameworks provide a basis for further theorizing in this area. We also identify several open research questions addressing issues and challenges in the marketbased disclosures. The research has important implications for firms, hackers, policymakers, and researchers in this area.
机译:脆弱性披露是学者和从业者之间的争议课题。大多数学者们同意采用漏洞披露的负责任的披露实践,使公司提供保护期权,以解决公开披露前的漏洞。但是,该公司可能无法充分利用受保护期,​​从而导致金融和声誉损失。最近在基于市场的披露方法中的普及,如Bug Bounty程序提供了新方法来控制道德黑客并有效地管理披露时间表。通过系统的文献综述,我们调查和识别各种脆弱性披露机制,并详细说明了每个机制的公开内容。通过提出两项研究框架,我们综合并比较了脆弱性披露机制下脆弱性披露的前所未受披露的后果。我们的分析表明,在市场机制中激励黑客改变了黑客的动机,导致行为变化,最终使公司更加控制披露过程。此外,我们的研究框架为此区域的进一步理解提供了基础。我们还确定了一些开放的研究问题,解决了市场披露中的问题和挑战。该研究对公司,黑客,政策制定者和研究人员具有重要意义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号