...
首页> 外文期刊>The John Marshall journal of computer & information law >Bugs for Sale: Legal and Ethical Proprieties of the Market in Software Vulnerabilities, 28 J. Marshall J. ComputerandInfo. L. 451 (2011)
【24h】

Bugs for Sale: Legal and Ethical Proprieties of the Market in Software Vulnerabilities, 28 J. Marshall J. ComputerandInfo. L. 451 (2011)

机译:待售漏洞:软件漏洞的市场法律和道德规范,28 J. Marshall J. ComputerandInfo。 451(2011)

获取原文
   

获取外文期刊封面封底 >>

       

摘要

The pertinent questions therefore are: first, could software vulnerabilities be obviated simply by ameliorating factors responsible for market failure as canvassed by the literature on the economics of software security, drawing on the strength of the theory of information asymmetry, or are vulnerabilities inevitable irrespective of market dynamics and solutions? Second, to what extent is vulnerabilities research or the surreptitious exploitation of software vulnerabilities by hackers tantamount to trespass, and what are the legal implications, if any? Third, to what extent is the peddling of software vulnerabilities valid or enforceable in law? Fourth, what are the implications of software vulnerabilities research for intellectual property rights? Fifth, what is the moral propriety of the market in software vulnerabilities, or should the beneficial effects of vulnerabilities disclosures trump or exculpate the palpable wrongfulness or ethical concerns underpinning the hacking of information systems? Sixth, if software vulnerabilities were inevitable, how best to manage them to ensure the integrity of digital infrastructures? The paper is divided into seven parts. Part one is the introduction; part two examines the proprieties of information asymmetry and other economic theories inexorably linking software vulnerabilities to market failure; part three discusses vulnerabilities detection research and reviews the boundaries separating professional and malicious hacking; part four discusses the modality and effects of vulnerabilities disclosure; part five analyzes sundry legal issues probing the legality of vulnerabilities research and disclosure, which range from cyber trespass, cyber-crime, intellectual property rights to the recurring question on whether a liability regime could rein in insecure software? Part six discusses the ethical proprieties of vulnerabilities research and market, whilst part seven concludes the discourse by proffering best practices for software vulnerabilities governance.
机译:因此,相关的问题是:首先,可以利用信息不对称理论的优势,通过缓解软件安全经济学文献中所提到的市场失灵的因素来简单地消除软件漏洞,还是可以忽略不计的漏洞?市场动态和解决方案?其次,漏洞研究或黑客对软件漏洞的秘密利用在多大程度上等同于侵入,法律含义是什么(如果有)?第三,对软件漏洞的兜售在法律上有效或可执行的程度如何?第四,软件漏洞研究对知识产权有何影响?第五,软件漏洞的市场道德准则是什么,或者漏洞披露的有利影响应该胜过或排除支撑信息系统黑客行为的明显不法行为或道德问题?第六,如果软件漏洞不可避免,那么如何最好地管理它们以确保数字基础架构的完整性?本文分为七个部分。第一部分是绪论。第二部分考察了信息不对称和其他经济理论是否恰当地将软件漏洞与市场失灵联系起来;第三部分讨论漏洞检测研究,回顾专业和恶意黑客之间的界限。第四部分讨论了漏洞披露的方式和效果。第五部分分析探索漏洞研究和披露合法性的各种法律问题,范围从网络入侵,网络犯罪,知识产权到有关责任制是否可以控制不安全软件的反复出现的问题?第六部分讨论了漏洞研究和市场的道德规范,而第七部分则通过提供软件漏洞治理的最佳实践来总结了本文。

著录项

相似文献

  • 外文文献
  • 中文文献
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号