A Comparison of Market Approaches to Software Vulnerability Disclosure

Practical computer (in)security is largely driven by the existence of and knowledge about vulnerabilities, which can be exploited to breach security mechanisms. Although the discussion on details of responsible vulnerability disclosure is controversial, there is a sort of consensus that better infor...

Full description

Saved in:
Bibliographic Details
Published inEmerging Trends in Information and Communication Security pp. 298 - 311
Main Author Böhme, Rainer
Format Book Chapter
LanguageEnglish
Published Berlin, Heidelberg Springer Berlin Heidelberg 2006
SeriesLecture Notes in Computer Science
Subjects
Online AccessGet full text
ISBN9783540346401
3540346406
ISSN0302-9743
1611-3349
DOI10.1007/11766155_21

Cover

More Information
Summary:Practical computer (in)security is largely driven by the existence of and knowledge about vulnerabilities, which can be exploited to breach security mechanisms. Although the discussion on details of responsible vulnerability disclosure is controversial, there is a sort of consensus that better information sharing is socially beneficial. In the recent years we observe the emerging of “vulnerability markets” as means to stimulate exchange of information. However, this term subsumes a broad range of different concepts, which are prone to confusion. This paper provides a first attempt to structure the field by (1) proposing a terminology for distinct concepts and (2) defining criteria to allow for a better comparability between different approaches. An application of this framework on four market types shows notable differences between the approaches.
ISBN:9783540346401
3540346406
ISSN:0302-9743
1611-3349
DOI:10.1007/11766155_21