首页> 外文OA文献 >Key factors impacting on response time of software vendors in releasing patches for software vulnerabilities
【2h】

Key factors impacting on response time of software vendors in releasing patches for software vulnerabilities

机译:影响发布软件漏洞补丁的软件供应商响应时间的关键因素

摘要

Software vulnerabilities are a major problem for organizations and society given how pervasive the use of computers and the Internet and networks has become. Computers, the Internet and networks in general are underpinned by operating system software and, increasingly, software applications are integrated with the Internet. In this increasingly complex environment hackers and attackers are more likely to take advantage of software vulnerabilities and exploit operating system software and application software. These software exploitations can result in huge losses to businesses which are highly reliant on computerized systems. Software vendors are responsible for securing these vulnerabilities through software patching. This study examines the effect of the level of criticality of software vulnerabilities, type of software vendor and type of software on the software vendors‘ response time in releasing software patches once software vendors have been informed of vulnerabilities in their software.The main theoretical support for this study is software security disclosure theory and an economic model of software security investment. These theories provide a framework for understanding how open source versus proprietary software vendors respond with patches to software vulnerabilities depending on the level of criticality of the software vulnerability and the type of software.Empirical data was collected from four related software vulnerability databases: SecurityFocus, Open Source Vulnerability Database, National Vulnerability Database and Secunia. These four software vulnerability databases contain archival data about software vulnerabilities which has been rigorously collected and screened. This research focuses on software vulnerabilities that have been recently reported in these software vulnerability databases from 2008 to 2010. To test the hypothesised relationships in the proposed research model, multiple regression analysis is used as the main statistical tool.Analysis of the archival data confirms that software vendors release patches for software vulnerabilities with a medium level of criticality in a shorter response timethan software vulnerabilities with low and high levels of criticality once the vendor has been informed of the software vulnerability. Open source vendors release patches for open source software vulnerabilities 39% quicker than proprietary source vendors release patches for proprietary software. Patches for operating system software vulnerabilities are released 8% slower than patches for application software vulnerabilities.This study contributes to the existing knowledge and theory by investigating how the different levels of criticality of software vulnerabilities, the differences between open and proprietary source software vendors and the difference between operating system software and application software impact on the response time of software vendors in releasing patches once the software vendor is informed of software vulnerabilities. The findings of this study also establish that responsible disclosure is a more effective mechanism than full disclosure for determining the response time of software vendors. This study contributes to practice by providing an enhanced understanding of the software vulnerability landscape and the complex process of software vendors‘ patching behaviour.
机译:鉴于计算机和Internet和网络的使用日趋普及,软件漏洞是组织和社会面临的主要问题。通常,计算机,Internet和网络都由操作系统软件支持,并且越来越多的软件应用程序与Internet集成在一起。在这种日益复杂的环境中,黑客和攻击者更有可能利用软件漏洞并利用操作系统软件和应用程序软件。这些软件利用会给高度依赖计算机系统的企业造成巨大损失。软件供应商有责任通过软件修补来保护这些漏洞。这项研究调查了软件漏洞的严重程度,软件供应商的类型以及软件类型对软件供应商发布软件补丁后发布软件补丁的响应时间的影响。该研究是软件安全公开理论和软件安全投资的经济学模型。这些理论提供了一个框架,可用于理解开源软件和专有软件供应商如何根据软件漏洞的严重程度和软件类型对软件漏洞进行补丁处理。经验数据是从四个相关的软件漏洞数据库中收集的:SecurityFocus,Open源漏洞数据库,国家漏洞数据库和Secunia。这四个软件漏洞数据库包含有关软件漏洞的存档数据,这些数据已经过严格收集和筛选。这项研究的重点是最近在2008年至2010年间在这些软件漏洞数据库中报告的软件漏洞。为了检验所提出研究模型中的假设关系,使用多元回归分析作为主要统计工具。档案数据分析证实了一旦通知了软件漏洞,软件供应商就会以较短的响应时间发布具有中等严重程度的软件漏洞补丁,而响应时间要比具有低和高严重程度的软件漏洞更短。开源供应商发布开放源代码软件漏洞补丁程序比专有源供应商发布专有软件补丁程序快39%。操作系统软件漏洞补丁的发布速度比应用软件漏洞补丁的发布慢8%。本研究通过调查软件漏洞的关键程度不同,开放源代码软件和专有源软件供应商之间的区别以及如何解决这些漏洞,为现有的知识和理论做出了贡献。通知软件供应商软件漏洞后,操作系统软件和应用程序软件之间的差异会影响软件供应商发布补丁的响应时间。这项研究的结果还确定,负责任的披露对于确定软件供应商的响应时间比全面披露更为有效。这项研究通过增强对软件漏洞状况和软件供应商补丁行为的复杂过程的理解,为实践做出了贡献。

著录项

  • 作者

    Arjun K. C.;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号