An Empirical Analysis of Vendor Response to Disclosure Policy

نویسندگان

  • Ashish Arora
  • Ramayya Krishnan
  • Rahul Telang
  • Yubao Yang
چکیده

Software vulnerability disclosure has generated intense interest and debate. In particular, there have been arguments made both in opposition to and in favor of alternatives such as full and instant disclosure and limited or no disclosure. An important consideration in this debate is the behavior of the software vendor. Does vulnerability disclosure policy have an effect on patch release behavior of software vendors? This paper compiles a unique data set from CERT/CC and Security Focus databases to answer this question. Our results suggest that early disclosure has significant positive impact on the vendor patching speed. Open source vendors patch more quickly than closed source vendors and severe vulnerabilities are patched faster. We also find that vendors respond slower to vulnerabilities not disclosed by CERT/CC. This might reflect unmeasured differences in the severity and importance of vulnerabilities. It might also reflect the stronger lines of communication between CERT/CC and vendors, and the value of the vulnerability analysis by CERT/CC. We also find that vendors are more responsible after the 9/11 event.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Inventory Model for Deteriorating Items Using Vendor-Managed Inventory Policy

In recent researches, vendor managed inventory (VMI) policy is rarely considered for deteriorating items.   This study considered the supply chain partner’s collaboration via a VMI system and provided an EOQ model for a two-level supply chain (single supplier - single retailer) to examine the inventory management proceedings for VMI and non-VMI supply chains. By a new approach in modeling, the ...

متن کامل

An Empirical Analysis of Software Vendors' Patching Behavior: Impact of Vulnerability Disclosure

One key aspect of better and more secure software is timely and reliable patching of vulnerabilities by software vendors. Recently, software vulnerability disclosure, which refers to the publication of vulnerability information before a patch to fix the vulnerability has been issued by the software vendor, has generated intense interest and debate. In particular, there have been arguments made ...

متن کامل

An Integrated Production-Inventory Model with Backorder and Lot for Lot Policy

    inventory model,   backorder   buyer ,   vendor,   lot for lot policy In this paper, an inventory model for two-stage supply chain is investigated. A supply chain with single vendor and single buyer is considered. We assume that shortage as a backorder is allowed for the buyer and the vendor makes the production set up every time the buyer places an order and supplies on a lot for lot basis...

متن کامل

Emerging Issues in Responsible Vulnerability Disclosure

Security vulnerability in software is the primary reason for security breaches, and an important challenge for IT professionals is how to manage the disclosure of vulnerability information. The IT security community has proposed several disclosure policies, such as full vendor, immediate public and hybrid, and has debated which of these should be adopted by coordinating agencies such as CERT. O...

متن کامل

EPQ model with scrap and backordering under Vendor managed inventory policy

This paper presents the economic production quantity (EPQ) models for the imperfect quality items produced with/without the presence of shortage condition. The models are presented in a two-level supply chain composed of a single manufacturer and a single buyer to investigate the performance of vendormanaged inventory (VMI) policy. The total costs are minimized to obtain the optimal production ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005