...
首页> 外文期刊>Journal of management information systems >Patch Release Behaviors of Software Vendors in Response to Vulnerabilities: An Empirical Analysis
【24h】

Patch Release Behaviors of Software Vendors in Response to Vulnerabilities: An Empirical Analysis

机译:响应漏洞的软件供应商的补丁发布行为:实证分析

获取原文
获取原文并翻译 | 示例
           

摘要

Software vulnerabilities have become a serious concern because unpatched software runs the risk of being exploited by hackers. There is a need for software vendors to make software patches available in a timely manner for vulnerabilities in their products. We develop a survival analysis model of software vendors' patch release behavior and test it using a data set compiled from the National Vulnerability Database, United States Computer Emergency Readiness Team, and vendor Web sites. This model helps to understand how factors specific to vulnerabilities, patches, software vendors, and software affect the patch release behavior of software vendors based on their cost structure. This study also analyzes the impact of the presence of multiple vendors and type of vendor on the patch release behavior of software vendors. Our results indicate that vulnerabilities with high confidentiality impact or high integrity impact are patched faster than vulnerabilities with high availability impact. Interesting differences in the patch release behavior of software vendors based on software type (new release versus update) and type of vendor (open source versus proprietary) are found. Our results illustrate that when there are legislative pressures, vendors react faster in patching vulnerabilities. Thus, appropriate regulations can be an important policy tool to influence vendor behavior toward socially desirable security outcomes.
机译:软件漏洞已成为严重的问题,因为未修补的软件冒着被黑客利用的风险。软件供应商需要及时提供软件补丁来修复其产品中的漏洞。我们开发了软件供应商补丁程序发布行为的生存分析模型,并使用从国家漏洞数据库,美国计算机应急准备小组和供应商网站收集的数据集对其进行测试。该模型有助于了解特定于漏洞,补丁,软件供应商和软件的因素如何根据其成本结构影响软件供应商的补丁发布行为。这项研究还分析了多个供应商的存在和供应商类型对软件供应商补丁发布行为的影响。我们的结果表明,具有高机密性或完整性影响的漏洞的修补速度比具有高可用性影响的漏洞的修补速度更快。发现基于软件类型(新版本与更新)和厂商类型(开源与专有)的软件供应商的补丁发行行为之间的有趣差异。我们的结果表明,当有立法压力时,供应商对修补漏洞的反应会更快。因此,适当的法规可以成为一种重要的政策工具,可以影响供应商的行为以实现社会期望的安全结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号