...
首页> 外文期刊>Information Systems Research >An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure
【24h】

An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure

机译:对软件供应商补丁发布行为的实证分析:漏洞披露的影响

获取原文
获取原文并翻译 | 示例
           

摘要

A key aspect of better and more secure software is timely patch release by software vendors for the vulnerabilities in their products. Software vulnerability disclosure, which refers to the publication of vulnerability information, has generated intense debate. An important consideration in this debate is the behavior of software vendors. How quickly do vendors patch vulnerabilities and how does disclosure affect patch release time? This paper compiles a unique data set from the Computer Emergency Response Team/Coordination Center (CERT) and SecurityFocus to answer this question. Our results suggest that disclosure accelerates patch release. The instantaneous probability of releasing the patch rises by nearly two and a half times because of disclosure. Open source vendors release patches more quickly than closed source vendors. Vendors are more responsive to more severe vulnerabilities. We also find that vendors respond more slowly to vulnerabilities not disclosed by CERT. We verify our results by using another publicly available data set and find that results are consistent. We also show how our estimates can aid policy makers in their decision making.
机译:更好和更安全的软件的一个关键方面是软件供应商针对其产品中的漏洞及时发布补丁程序。涉及漏洞信息发布的软件漏洞披露引起了激烈的争论。在这场辩论中,一个重要的考虑因素是软件供应商的行为。供应商修补漏洞的速度有多快?披露如何影响修补程序的发布时间?本文从计算机紧急响应小组/协调中心(CERT)和SecurityFocus收集了唯一的数据集来回答此问题。我们的结果表明,披露可以加快补丁的发布。由于公开,释放补丁的瞬时概率增加了近两倍半。开源供应商发布的补丁程序比封闭供应商发布的补丁更快。供应商对更严重的漏洞更敏感。我们还发现供应商对CERT未披露的漏洞的响应速度较慢。我们通过使用另一个公开可用的数据集来验证我们的结果,并发现结果是一致的。我们还将展示我们的估计如何帮助决策者做出决策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号