A mixed methods probe into the direct disclosure of software vulnerabilities

Software vulnerabilities are security-related software bugs. Direct disclosure refers to a practice that is widely used for communicating the confidential information about vulnerabilities between two parties, vulnerability discoverers and software producers. Building on software vulnerability life...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:Computers in human behavior 2020-02, Vol.103, p.161-173
Hauptverfasser: Ruohonen, Jukka, Hyrynsalmi, Sami, Leppänen, Ville
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Software vulnerabilities are security-related software bugs. Direct disclosure refers to a practice that is widely used for communicating the confidential information about vulnerabilities between two parties, vulnerability discoverers and software producers. Building on software vulnerability life cycle analysis, this empirical paper observes the qualitative and quantitative characteristics of direct disclosure practices, focusing particularly on the historical problem related to producers’ reluctance to participate in the practices. According to the results, the problem was still present in the 2000s and early 2010s—and likely is still present today. By presenting this empirical result about the under researched phenomenon of direct disclosure of software vulnerabilities, the paper contributes to the research domain of vulnerability life cycle modeling in general and the subdomain of empirical vulnerability disclosure research in particular. •Direct disclosure refers to a two-party dissemination of vulnerabilities.•Historically many vendors have been reluctant to participate in disclosure.•This paper examines direct disclosure practices in the 2000s and early 2010s.•Both qualitative and quantitative methods are used for the empirical inquiry.•According to the results, the reluctance of vendors has still been widespread.
ISSN:0747-5632
1873-7692
DOI:10.1016/j.chb.2019.09.028