2010
DOI: 10.1287/isre.1080.0226
|View full text |Cite
|
Sign up to set email alerts
|

An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure

Abstract: One key aspect of better and more secure software is timely and reliable patching of vulnerabilities by software vendors. Recently, software vulnerability disclosure, which refers to the publication of vulnerability information before a patch to fix the vulnerability has been issued by the software vendor, has generated intense interest and debate. In particular, there have been arguments made both in opposition to and in favor of alternatives such as full and instant disclosure and limited or no disclosure. A… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

7
73
5
1

Year Published

2012
2012
2023
2023

Publication Types

Select...
4
2
2

Relationship

0
8

Authors

Journals

citations
Cited by 114 publications
(91 citation statements)
references
References 21 publications
7
73
5
1
Order By: Relevance
“…In [8], authors show that a vendor with more competitors patches the vulnerabilities more quickly. In [7], they show that the vulnerability disclosure accelerates the patch release. Although their work is based upon a small data set of just 354 vulnerabilities disclosed till 2003, they make similar observation as ours that the closed-source vendors are quicker in patching the disclosed vulnerabilities.…”
Section: B Studies On Disclosure and Patchingmentioning
confidence: 99%
See 1 more Smart Citation
“…In [8], authors show that a vendor with more competitors patches the vulnerabilities more quickly. In [7], they show that the vulnerability disclosure accelerates the patch release. Although their work is based upon a small data set of just 354 vulnerabilities disclosed till 2003, they make similar observation as ours that the closed-source vendors are quicker in patching the disclosed vulnerabilities.…”
Section: B Studies On Disclosure and Patchingmentioning
confidence: 99%
“…The goal of such work is to estimate the number of vulnerabilities in new software products. Another direction of work aims to study the changes in the patching behavior of vendors in response to vulnerability disclosures and the existence of competitors [7], [8]. These studies analyze only small vulnerability data sets and do not cover the behavior of individual vendors.…”
Section: Introductionmentioning
confidence: 99%
“…A risk of conflict with the vendor can be deduced from this and has been confirmed by [31,34,36]. A risk of maintencance leading to resistance and user revolt caused by changed software is also identified [3,22].…”
Section: Reasons For Maintenance Deferral Do Existmentioning
confidence: 72%
“…D'autres études se sont intéréssés à l'utilisation de données réelles afin de caractériser des comportements d'attaquant. Par exemple, dans (Arora et al, 2004), les auteurs étudient l'impact de la publication de la vulnérabilité et de la publication du correctif sur le processus d'attaque. En utilisant un ensemble de 308 vulnérabilités, ils ont proposé un modèle permettant de prédire l'évolution du nombre d'attaques par hôte et par jour.…”
Section: Etat De L'art Sur L'évaluation De La Sécuritéunclassified