Software vulnerability disclosure has generated intense interest and debate. In particular, there have been arguments made both in opposition to and in favor of alternatives such as full and instant disclosure and limited or no disclosure. An important consideration in this debate is the behavior of the software vendor. Does vulnerability disclosure policy have an effect on patch release behavior of software vendors? This paper compiles a unique data set from CERT/CC and Security Focus databases to answer this question. Our results suggest that early disclosure has significant positive impact on the vendor patching speed. Open source vendors patch more quickly than closed source vendors and severe vulnerabilities are patched faster. We also...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
One key aspect of better and more secure software is timely and reliable patching of vulnerabilities...
Information security breaches pose a significant and increasing threat to national security and econ...
Software vulnerabilities represent a serious threat to cybersecurity, most cyberattacks exploit know...
Researchers in the area of information security have mainly been concerned with tools, techniques an...
Software vulnerabilities represent a serious threat to cyber security, most cyber-attacks exploit kn...
In this paper, we use the event study methodology to examine the role that financial markets play in...
With the nearly instantaneous spread of information in modern society, policies regarding the disclo...
Software security is a major concern for vendors, consumers, and regulators since attackers that exp...
Although a lot of work and proposals are currently in place to help mitigate vulnerabilities, but un...
Software security is a major concern for vendors, consumers and regulators. When vulnerabilities are...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
One key aspect of better and more secure software is timely and reliable patching of vulnerabilities...
Information security breaches pose a significant and increasing threat to national security and econ...
Software vulnerabilities represent a serious threat to cybersecurity, most cyberattacks exploit know...
Researchers in the area of information security have mainly been concerned with tools, techniques an...
Software vulnerabilities represent a serious threat to cyber security, most cyber-attacks exploit kn...
In this paper, we use the event study methodology to examine the role that financial markets play in...
With the nearly instantaneous spread of information in modern society, policies regarding the disclo...
Software security is a major concern for vendors, consumers, and regulators since attackers that exp...
Although a lot of work and proposals are currently in place to help mitigate vulnerabilities, but un...
Software security is a major concern for vendors, consumers and regulators. When vulnerabilities are...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...
International audienceAround the debate on software vulnerability disclosure, existing works have mo...