Software Security and Liability

نویسندگان

  • Byung-Cho Kim
  • Pei-Yu Chen
  • Tridas Mukhopadhyay
  • Byung Cho Kim
چکیده

The abundance of flawed software has been identified as the main cause of the poor security of computer networks since major viruses and worms have been exploiting the vulnerabilities of such software. As an incentive mechanism for software security quality improvement, software liability has been intensely discussed among computer scientists, jurists, and policy makers for a long time. In this paper, we examine how the liability mechanism affects a monopolistic software vendor’s decision on security quality and market coverage. We then analyze the welfare implications of the liability mechanism. We find that high marginal willingness to pay for the software leads to full market coverage without liability. When liability is imposed, full market coverage obtains only if the expected loss is bounded. We also find that security quality is underprovided without liability while socially optimal level is offered with liability. Interestingly, our results indicate that imposing liability may discourage the monopolist from improving security while it leads to higher consumer surplus. When the marginal willingness to pay is relatively low, the liability mechanism brings higher social surplus. In the presence of information asymmetry between the vendor and the customers, the liability mechanism yields higher security quality and higher consumer surplus.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Who Should be Responsible for Software Security? A Comparative Analysis of Liability Policies in Network Environments

In recent years, vendor liability for software security vulnerabilities has been the center of an important debate in the software community and a topic gaining government attention in legislative committees and hearings. The importance of this question surrounding vendor security liability is amplified when one considers the increasing emergence of “zero-day” attacks where hackers take advanta...

متن کامل

Risk management in the sphere of state economic security provision using professional liability insurance

This study contains a comprehensive scientific analysis of modern problems of risk management in the sphere of state economic security provision using professional liability insurance. The elements of the mechanism for providing economic security are defined, namely: subjects, objects, and instruments of influence. It is stipulated that insurance is the means to provide state economic security....

متن کامل

An Economic Analysis of the Software Market with a Risk-Sharing Contract

Low quality of software has been blamed for poor security of our computer networks as major viruses and worms exploit the vulnerabilities of such software. However, software vendors have no incentive to improve the quality of their products since they are not directly liable for any loss due to poor quality. Software liability has been intensely discussed among computer scientists and jurists f...

متن کامل

An Economic Analysis of Software Market with Risk-Sharing Contract

Poor quality of software has been blamed for poor security of our computer networks in the sense that major viruses and worms exploit the vulnerabilities of such software. However, software vendors have no incentive to improve the quality of their products since they are not directly liable for any loss due to poor quality. Software liability has been intensely discussed among computer scientis...

متن کامل

Confidential Business Information in Jurisprudence and Iranian law

As a result of information technology era and possibility of swift access to information, endorsement of Confidential Business Information (CBI) has found an extraordinary importance; whereas the CBI concept and legal warranty in order to support it thoroughly in Iran is not emphasized in the framework of a specific law. This issue has led to legal problems in the trial with allegation of CBI v...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015