首页> 外文期刊>Information systems frontiers >Does information security attack frequency increase with vulnerability disclosure? An empirical analysis
【24h】

Does information security attack frequency increase with vulnerability disclosure? An empirical analysis

机译:信息安全攻击的频率会随着漏洞披露的增加而增加吗?实证分析

获取原文
获取原文并翻译 | 示例
           

摘要

Research in information security, risk management and investment has grown in importance over the last few years. However, without reliable estimates on attack probabilities, risk management is difficult to do in practice. Using a novel data set, we provide estimates on attack propensity and how it changes with disclosure and patching of vulnerabilities. Disclosure of software vulnerability has been controversial. On one hand are those who propose full and instant disclosure whether the patch is available or not and on the other hand are those who argue for limited or no disclosure. Which of the two policies is socially optimal depends critically on how attack frequency changes with disclosure and patching. In this paper, we empirically explore the impact of vulnerability information disclosure and availability of patches on attacks targeting the vulnerability. Our results suggest that on an average both secret (non-published) and published (published and not patched) vulnerabilities attract fewer attacks than patched (published and patched) vulnerabilities. When we control for time since publication and patches, we find that patching an already known vulnerability decreases the number of attacks, although attacks gradually increase with time after patch release. Patching an unknown vulnerability, however, causes a spike in attacks, which then gradually decline after patch release. Attacks on secret vulnerabilities slowly increase with time until the vulnerability is published and then attacks rapidly decrease with time after publication.
机译:在过去的几年中,信息安全,风险管理和投资方面的研究变得越来越重要。但是,如果没有可靠的攻击概率估计,则在实践中很难进行风险管理。使用新颖的数据集,我们提供了对攻击倾向以及随着漏洞的披露和修补而发生的变化的估计。披露软件漏洞一直存在争议。一方面,有人建议全面和立即披露补丁是否可用,另一方面,有人则主张限制披露或不披露。两种策略中哪一种在社会上是最佳的,这主要取决于攻击频率如何随披露和修补而变化。在本文中,我们从经验上探索漏洞信息披露和补丁可用性对针对该漏洞的攻击的影响。我们的结果表明,平均而言,秘密(未发布)和已发布(已发布且未打补丁)漏洞比已打补丁(已发布和已打补丁)漏洞吸引的攻击更少。当我们控制发布和补丁发布的时间之后,我们发现对已知漏洞的补丁可以减少攻击的数量,尽管攻击在发布补丁后会随着时间而逐渐增加。但是,修补未知漏洞会导致攻击高峰,然后在发布补丁后逐渐下降。对秘密漏洞的攻击会随着时间的推移而缓慢增加,直到该漏洞发布为止,然后随着时间的推移,攻击会随着时间的推移而迅速减少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号