A Comparison of Market Approaches to Software Vulnerability Disclosure
Practical computer (in)security is largely driven by the existence of and knowledge about vulnerabilities, which can be exploited to breach security mechanisms. Although the discussion on details of responsible vulnerability disclosure is controversial, there is a sort of consensus that better infor...
Saved in:
Published in | Emerging Trends in Information and Communication Security pp. 298 - 311 |
---|---|
Main Author | |
Format | Book Chapter |
Language | English |
Published |
Berlin, Heidelberg
Springer Berlin Heidelberg
2006
|
Series | Lecture Notes in Computer Science |
Subjects | |
Online Access | Get full text |
ISBN | 9783540346401 3540346406 |
ISSN | 0302-9743 1611-3349 |
DOI | 10.1007/11766155_21 |
Cover
Summary: | Practical computer (in)security is largely driven by the existence of and knowledge about vulnerabilities, which can be exploited to breach security mechanisms. Although the discussion on details of responsible vulnerability disclosure is controversial, there is a sort of consensus that better information sharing is socially beneficial. In the recent years we observe the emerging of “vulnerability markets” as means to stimulate exchange of information. However, this term subsumes a broad range of different concepts, which are prone to confusion. This paper provides a first attempt to structure the field by (1) proposing a terminology for distinct concepts and (2) defining criteria to allow for a better comparability between different approaches. An application of this framework on four market types shows notable differences between the approaches. |
---|---|
ISBN: | 9783540346401 3540346406 |
ISSN: | 0302-9743 1611-3349 |
DOI: | 10.1007/11766155_21 |