Radianti, Jaziar with Jose Gonzalez and Eliot Rich, "A Quest for a Framework to Improve Software Security: Vulnerability Black Markets Scenario", 2009 July 26-2009 July 30

ua435

There are numerous discussions on possible leverage points in improving software quality and they have been placed in various context--from technical approach, improving user education to economic approach. One of central points of the discussions is on the best policy to handle vulnerability discoveries. Various approaches have been developed: from secret reporting, full-disclosure, responsible disclosure to a market approach. The dominant aspect of the latter is about the Vulnerability Black Market (VBM), which emerged due to the latter development, as an alternative for malicious hackers to sell exploits and malware that take advantage of the flaws in the software. The model in this paper draws on empirical observation on black markets and market-based approach for vulnerability discovery to generate a simple model of VBM. The model results suggest that efficient legal markets may attract malicious hackers to enter the legal markets and may reduce their likelihood to be involved in vulnerability black markets. However, better patching management may mitigate the abuse of software vulnerabilities.

This is the whole item.

Date created
  • 2009 July 26-2009 July 30
Type
Processing Activity License

ITEM CONTEXT

Part of

4818cb531cdd68d6ec6af3f291216fc7

Scope and Contents
Part of

b3584c6b53c3f58e0202549d7d851f84

Scope and Contents
Part of

23d738ba88f8333bc39725f9cb5bd0b8

Scope and Contents
Collection

System Dynamic Society Records

Scope and Contents
Collecting area

Artikel