Search results for "Responsible disclosure"

showing 1 items of 1 documents

Vulnerability Black Markets: Empirical Evidence and Scenario Simulation

2009

This paper discusses the manifest characteristics of online Vulnerability Black Markets (VBM), insider actors, interactions and mechanisms, obtained from masked observation. Because VBM transactions are hidden from general view, we trace their precursors as secondary evidence of their development and activity. More general attributes of VBMs and the exploits they discuss are identified. Finally, we introduce a simulation model that captures how vulnerability discoveries may be placed in a dual legal-black market context. We perform simulations and find that if legal markets expose vulnerabilities that go unresolved, the security and quality of software may suffer more than in the absence of…

Responsible disclosureExploitComputer scienceSoftware security assuranceVulnerabilityContext (language use)Vulnerability managementEmpirical evidenceComputer securitycomputer.software_genrecomputerIndustrial organizationInsider2009 42nd Hawaii International Conference on System Sciences
researchProduct