Title :
Economics of software vulnerability disclosure
Author :
Arora, Ashish ; Telang, Rahul
Author_Institution :
Carnegie Mellon Univ., Pittsburgh, PA
Abstract :
Information security breaches frequently exploit software flaws or vulnerabilities, causing significant economic losses. Considerable debate exists about how to disclose such vulnerabilities. A coherent theoretical framework helps identify the key data elements needed to develop a sensible way of handling vulnerability disclosure
Keywords :
economics; security of data; economic losses; information security breaches; software flaws; software vulnerability disclosure; Computer hacking; Computer security; Data security; Delay; HTML; Information analysis; Information security; Protection; Public policy; Software quality; disclosure policy; economic analysis; patching; software vulnerability;
Journal_Title :
Security & Privacy, IEEE
DOI :
10.1109/MSP.2005.12