An Empirical Analysis of Vendor Response to Disclosure Policy
نویسندگان
چکیده
Software vulnerability disclosure has generated intense interest and debate. In particular, there have been arguments made both in opposition to and in favor of alternatives such as full and instant disclosure and limited or no disclosure. An important consideration in this debate is the behavior of the software vendor. Does vulnerability disclosure policy have an effect on patch release behavior of software vendors? This paper compiles a unique data set from CERT/CC and Security Focus databases to answer this question. Our results suggest that early disclosure has significant positive impact on the vendor patching speed. Open source vendors patch more quickly than closed source vendors and severe vulnerabilities are patched faster. We also find that vendors respond slower to vulnerabilities not disclosed by CERT/CC. This might reflect unmeasured differences in the severity and importance of vulnerabilities. It might also reflect the stronger lines of communication between CERT/CC and vendors, and the value of the vulnerability analysis by CERT/CC. We also find that vendors are more responsible after the 9/11 event.
منابع مشابه
An Inventory Model for Deteriorating Items Using Vendor-Managed Inventory Policy
In recent researches, vendor managed inventory (VMI) policy is rarely considered for deteriorating items. This study considered the supply chain partner’s collaboration via a VMI system and provided an EOQ model for a two-level supply chain (single supplier - single retailer) to examine the inventory management proceedings for VMI and non-VMI supply chains. By a new approach in modeling, the ...
متن کاملAn Empirical Analysis of Software Vendors' Patching Behavior: Impact of Vulnerability Disclosure
One key aspect of better and more secure software is timely and reliable patching of vulnerabilities by software vendors. Recently, software vulnerability disclosure, which refers to the publication of vulnerability information before a patch to fix the vulnerability has been issued by the software vendor, has generated intense interest and debate. In particular, there have been arguments made ...
متن کاملAn Integrated Production-Inventory Model with Backorder and Lot for Lot Policy
inventory model, backorder buyer , vendor, lot for lot policy In this paper, an inventory model for two-stage supply chain is investigated. A supply chain with single vendor and single buyer is considered. We assume that shortage as a backorder is allowed for the buyer and the vendor makes the production set up every time the buyer places an order and supplies on a lot for lot basis...
متن کاملEmerging Issues in Responsible Vulnerability Disclosure
Security vulnerability in software is the primary reason for security breaches, and an important challenge for IT professionals is how to manage the disclosure of vulnerability information. The IT security community has proposed several disclosure policies, such as full vendor, immediate public and hybrid, and has debated which of these should be adopted by coordinating agencies such as CERT. O...
متن کاملEPQ model with scrap and backordering under Vendor managed inventory policy
This paper presents the economic production quantity (EPQ) models for the imperfect quality items produced with/without the presence of shortage condition. The models are presented in a two-level supply chain composed of a single manufacturer and a single buyer to investigate the performance of vendormanaged inventory (VMI) policy. The total costs are minimized to obtain the optimal production ...
متن کامل