loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Proceedings of the 37th Annual Hawaii International Conference on System Sciences (HICSS'04) - Track 7
Big Island, Hawaii
January 05-January 08
ISBN: 0-7695-2056-1
Karthik Kannan, Purdue University
Rahul Telang, Carnegie Mellon University
Hao Xu, Carnegie Mellon University

Software vulnerability identification and their disclosure has been a critical area of concern for policy makers. Traditionally, Computer Emergency Response Team (CERT) has been acting as an infomediary between benign identifiers who report vulnerability information and users of the software. After verifying a reported vulnerability, and obtaining the remediation in the form of a patch from the software vendor, the infomediary — CERT — sends out a public "advisory" to inform software users about it. In the CERT-type mechanism, reporting vulnerabilities is voluntary with no explicit monetary gains to benign identifiers.

Of late, firms such as iDefense have been proposing a different market-based mechanism. In this market-based mechanism, the infomediary rewards identifiers for each vulnerability disclosed to it. The infomediary then shares this information with its clients who are users of this software. Using this information, clients can protect themselves against attacks that exploit those specific vulnerabilities. The key issue addressed in this paper is whether movement towards such a market-based mechanism for vulnerabilities leads to a better social outcome? We study this problem by characterizing the behavior of software users benign and malign identifiers (or hackers).

Citation:
Karthik Kannan, Rahul Telang, Hao Xu, "Economic Analysis of the Market for Software Vulnerability Disclosure," hicss, vol. 7, pp.70180a, Proceedings of the 37th Annual Hawaii International Conference on System Sciences (HICSS'04) - Track 7, 2004
Usage of this product signifies your acceptance of the Terms of Use.