메뉴 건너뛰기




Volumn 3995 LNCS, Issue , 2006, Pages 298-311

A comparison of market approaches to software vulnerability disclosure

Author keywords

[No Author keywords available]

Indexed keywords

COMPUTER SOFTWARE; DATA HANDLING; DATA TRANSFER; INFORMATION TECHNOLOGY; SECURITY OF DATA; SECURITY SYSTEMS;

EID: 33746613622     PISSN: 03029743     EISSN: 16113349     Source Type: Book Series    
DOI: 10.1007/11766155_21     Document Type: Conference Paper
Times cited : (45)

References (33)
  • 1
    • 33746582171 scopus 로고    scopus 로고
    • Optimal policy for software vulnerability disclosure
    • University of Minnesota, Minneapolis, MN
    • Arora, A., Telaiig, R., Xu, H.: Optimal policy for software vulnerability disclosure. In: Workshop on the Economics of Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004) http://www.dtc.umn.edu/weis2004/xu.pdf.
    • (2004) Workshop on the Economics of Information Security (WEIS)
    • Arora, A.1    Telaiig, R.2    Xu, H.3
  • 2
  • 3
    • 35548991265 scopus 로고    scopus 로고
    • Economic incentives to disclose software vulnerabilities
    • Harvard University, Cambridge, MA
    • Nizovtsev, D., Thursby, M.: Economic incentives to disclose software vulnerabilities. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge, MA (2005) http://infosecon.net/workshop/pdf/20.pdf.
    • (2005) Workshop on the Economics of Information Security (WEIS)
    • Nizovtsev, D.1    Thursby, M.2
  • 4
    • 33646142572 scopus 로고    scopus 로고
    • Is finding security holes a good idea?
    • University of Minnesota, Minneapolis, MN
    • Rescorla, E.: Is finding security holes a good idea? In: Workshop of Economics and Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004) http://www.dtc.umn.edu/weis2004/rescorla.pdf.
    • (2004) Workshop of Economics and Information Security (WEIS)
    • Rescorla, E.1
  • 6
    • 85005305538 scopus 로고
    • The market for 'lemons': Quality, uncertainty and the market mechanism
    • Akerlof, G.A.: The market for 'lemons': Quality, uncertainty and the market mechanism. Quarterly Journal of Economics 84 (1970) 488-500
    • (1970) Quarterly Journal of Economics , vol.84 , pp. 488-500
    • Akerlof, G.A.1
  • 8
    • 0014413249 scopus 로고
    • The tragedy of the commons
    • Hardin, G.: The tragedy of the commons. Science 162 (1968) 1243-1248
    • (1968) Science , vol.162 , pp. 1243-1248
    • Hardin, G.1
  • 9
    • 33646054897 scopus 로고    scopus 로고
    • Botnet tracking: Exploring a root-cause methodology to prevent distributed denial-of-service attacks
    • S. de Capitani di Vimercati et al., ed.: LNCS 3679, Berlin Heidelberg, Springer Verlag
    • Freiling, F., Holz, T., Wicherski, G.: Botnet tracking: Exploring a root-cause methodology to prevent distributed denial-of-service attacks. In S. de Capitani di Vimercati et al., ed.: Proc. of ESORICS. LNCS 3679, Berlin Heidelberg, Springer Verlag (2005) 319-335
    • (2005) Proc. of ESORICS , pp. 319-335
    • Freiling, F.1    Holz, T.2    Wicherski, G.3
  • 10
    • 33750715221 scopus 로고    scopus 로고
    • System reliability and free riding
    • Berkeley, CA
    • Varian, H.R.: System reliability and free riding. In: Workshop on Economics and Information Security (WEIS), Berkeley, CA (2002) http://www.sims.berkeley.edu/resources/affiliates/workshops/econsecurity/.
    • (2002) Workshop on Economics and Information Security (WEIS)
    • Varian, H.R.1
  • 11
    • 0344792106 scopus 로고    scopus 로고
    • Managing online security risks
    • Varian, H.R.: Managing online security risks. New York Times (2000) http://www.nytimes.com/library/financial/columns/060100econ-scene.html.
    • (2000) New York Times
    • Varian, H.R.1
  • 12
    • 3042744350 scopus 로고    scopus 로고
    • Two views on security software liability
    • Ryan, D.J., Heckmann, C.: Two views on security software liability. IEEE Security & Privacy 1 (2003) 70-75
    • (2003) IEEE Security & Privacy , vol.1 , pp. 70-75
    • Ryan, D.J.1    Heckmann, C.2
  • 17
    • 38149139761 scopus 로고    scopus 로고
    • Bug auctions: Vulnerability markets reconsidered
    • University of Minnesota, Minneapolis, MN
    • Ozment, A.: Bug auctions: Vulnerability markets reconsidered. In: Workshop of Economics and Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004) http://www.dtc.umn.edu/weis2004/ozment.pdf.
    • (2004) Workshop of Economics and Information Security (WEIS)
    • Ozment, A.1
  • 18
    • 84991041356 scopus 로고    scopus 로고
    • Vulnerability markets - What is the economic value of a zero-day exploit?
    • Berlin, Germany
    • Böhme, R.: Vulnerability markets - What is the economic value of a zero-day exploit? In: Proc. of 22C3: Private Investigations, Berlin, Germany (2005) https://events.ccc.de/congress/2005/fahrplan/attachments/542-Boehme2005.22C3. VulnerabilityMarkets.pdf.
    • (2005) Proc. of 22C3: Private Investigations
    • Böhme, R.1
  • 19
    • 84921360568 scopus 로고    scopus 로고
    • An economic analysis of markets for software vulnerabilities
    • University of Minnesota, Minneapolis, MN
    • Kannan, K., Telang, R.: An economic analysis of markets for software vulnerabilities. In: Workshop of Economics and Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004) http://www.dtc.umn.edu/weis2004/kannan-telang.pdf.
    • (2004) Workshop of Economics and Information Security (WEIS)
    • Kannan, K.1    Telang, R.2
  • 20
    • 33746608318 scopus 로고    scopus 로고
    • Security tokens and their derivatives
    • Centre for Communications Systems Research (CCSR), University of Cambridge, UK
    • Matsuura, K.: Security tokens and their derivatives. Technical report, Centre for Communications Systems Research (CCSR), University of Cambridge, UK (2001)
    • (2001) Technical Report
    • Matsuura, K.1
  • 21
    • 4243121902 scopus 로고    scopus 로고
    • A framework for using insurance for cyberrisk management
    • Gordon, L.A., Loeb, M.P., Sohail, T.: A framework for using insurance for cyberrisk management. Communications of the ACM 46 (2003) 81-85
    • (2003) Communications of the ACM , vol.46 , pp. 81-85
    • Gordon, L.A.1    Loeb, M.P.2    Sohail, T.3
  • 23
    • 1942468085 scopus 로고    scopus 로고
    • Hacking the business climate for network security
    • Schneier, B.: Hacking the business climate for network security. IEEE Computer (2004) 87-89
    • (2004) IEEE Computer , pp. 87-89
    • Schneier, B.1
  • 24
    • 84941158228 scopus 로고    scopus 로고
    • Cyberinsurance: A market solution to the internet security market failure
    • Berkeley, CA
    • Yurcik, W., Doss, D.: Cyberinsurance: A market solution to the internet security market failure. In: Workshop on Economics and Information Security (WEIS), Berkeley, CA (2002) http://www.sims.berkeley.edu/resources/affiliates/workshops/econsecurity/.
    • (2002) Workshop on Economics and Information Security (WEIS)
    • Yurcik, W.1    Doss, D.2
  • 27
    • 0037599474 scopus 로고    scopus 로고
    • The economic cost of publicly announced information security breaches: Empirical evidence from the stock market
    • Campbell, K., Gordon, L.A., Loeb, M.P., Zhou, L.: The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security 11 (2003) 431-448
    • (2003) Journal of Computer Security , vol.11 , pp. 431-448
    • Campbell, K.1    Gordon, L.A.2    Loeb, M.P.3    Zhou, L.4
  • 28
    • 7444242205 scopus 로고    scopus 로고
    • The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers
    • Cavusoglu, H., Mishra, B., Raghunathan, S.: The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers. International Journal of Electronic Commerce 9 (2004) 69-104
    • (2004) International Journal of Electronic Commerce , vol.9 , pp. 69-104
    • Cavusoglu, H.1    Mishra, B.2    Raghunathan, S.3
  • 29
    • 58049152987 scopus 로고    scopus 로고
    • Impact of software vulnerability announcements on the market value of software vendors - An empirical investigation
    • Harvard University, Cambridge, MA
    • Telang, R., Wattal, S.: Impact of software vulnerability announcements on the market value of software vendors - An empirical investigation. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge, MA (2005) http://infosecon.net/workshop/pdf/telang_wattal.pdf.
    • (2005) Workshop on the Economics of Information Security (WEIS)
    • Telang, R.1    Wattal, S.2
  • 33
    • 67650336989 scopus 로고    scopus 로고
    • The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting
    • Harvard University, Cambridge, MA
    • Ozment, A.: The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge, MA (2005) http://infosecon.net/workshop/pdf/10.pdf.
    • (2005) Workshop on the Economics of Information Security (WEIS)
    • Ozment, A.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.