메뉴 건너뛰기




Volumn 28, Issue 4, 2012, Pages 305-338

Patch release behaviors of software vendors in response to vulnerabilities: An empirical analysis

Author keywords

patch quality; patch release time; patch types; software vendor types; software vulnerability characteristics; survival analysis

Indexed keywords

PATCH TYPE; RELEASE TIME; SOFTWARE VENDORS; SOFTWARE VULNERABILITIES; SURVIVAL ANALYSIS;

EID: 84860651147     PISSN: 07421222     EISSN: None     Source Type: Journal    
DOI: 10.2753/MIS0742-1222280411     Document Type: Conference Paper
Times cited : (39)

References (51)
  • 3
    • 0034501876 scopus 로고    scopus 로고
    • Windows of vulnerability: A case study analysis
    • Arbaugh, W.A.; Fithen, W.L.; and McHugh, J. Windows of vulnerability: A case study analysis. Computer, 33, 12 (2000), 52-58.
    • (2000) Computer , vol.33 , Issue.12 , pp. 52-58
    • Arbaugh, W.A.1    Fithen, W.L.2    McHugh, J.3
  • 4
    • 33644916146 scopus 로고    scopus 로고
    • Sell first, fix later: Impact of patching on software quality
    • Arora, A.; Caulkins, J.P.; and Telang, R. Sell first, fix later: Impact of patching on software quality. Management Science, 52, 3 (2006), 465-471.
    • (2006) Management Science , vol.52 , Issue.3 , pp. 465-471
    • Arora, A.1    Caulkins, J.P.2    Telang, R.3
  • 5
    • 33846183559 scopus 로고    scopus 로고
    • Does information security attack frequency increase with vulnerability disclosure? An empirical analysis
    • Arora, A.; Nandkumar, A.; and Telang, R. Does information security attack frequency increase with vulnerability disclosure? An empirical analysis. Information Systems Frontiers, 8, 5 (2006), 350-362.
    • (2006) Information Systems Frontiers , vol.8 , Issue.5 , pp. 350-362
    • Arora, A.1    Nandkumar, A.2    Telang, R.3
  • 6
    • 61849175198 scopus 로고    scopus 로고
    • Optimal policy for software vulnerability disclosure
    • Arora, A.; Telang, R.; and Xu, H. Optimal policy for software vulnerability disclosure. Management Science, 54, 4 (2008), 642-656.
    • (2008) Management Science , vol.54 , Issue.4 , pp. 642-656
    • Arora, A.1    Telang, R.2    Xu, H.3
  • 7
    • 77649179868 scopus 로고    scopus 로고
    • Competition and patching of security vulnerabilities: An empirical analysis
    • Arora, A.; Forman, C.; Nandkumar, A.; and Telang, R. Competition and patching of security vulnerabilities: An empirical analysis. Information Economics and Policy, 22, 2 (2010), 164-177.
    • (2010) Information Economics and Policy , vol.22 , Issue.2 , pp. 164-177
    • Arora, A.1    Forman, C.2    Nandkumar, A.3    Telang, R.4
  • 8
    • 77954250852 scopus 로고    scopus 로고
    • An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure
    • Arora, A.; Krishnan, R.; Telang, R.; and Yang, Y. An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure. Information Systems Research, 21, 1 (2010), 115-132.
    • (2010) Information Systems Research , vol.21 , Issue.1 , pp. 115-132
    • Arora, A.1    Krishnan, R.2    Telang, R.3    Yang, Y.4
  • 10
    • 0034556312 scopus 로고    scopus 로고
    • The moderating effects of structure on volatility and complexity in software enhancement
    • Banker, R.D., and Slaughter, S.A. The moderating effects of structure on volatility and complexity in software enhancement. Information Systems Research, 11, 3 (2000), 219-240.
    • (2000) Information Systems Research , vol.11 , Issue.3 , pp. 219-240
    • Banker, R.D.1    Slaughter, S.A.2
  • 11
    • 33847021395 scopus 로고    scopus 로고
    • Understanding the impact of collaboration software on product design and development
    • Banker, R.D.; Bardhan, I.; and Asdemir, O. Understanding the impact of collaboration software on product design and development. Information Systems Research, 17, 4 (2006), 352-373.
    • (2006) Information Systems Research , vol.17 , Issue.4 , pp. 352-373
    • Banker, R.D.1    Bardhan, I.2    Asdemir, O.3
  • 12
    • 0032050741 scopus 로고    scopus 로고
    • Software development practices, software complexity, and software maintenance performance: A field study
    • Banker, R.D.; Davis, G.B.; and Slaughter, S.A. Software development practices, software complexity, and software maintenance performance: A field study. Management Science, 44, 4 (1998), 433-450.
    • (1998) Management Science , vol.44 , Issue.4 , pp. 433-450
    • Banker, R.D.1    Davis, G.B.2    Slaughter, S.A.3
  • 13
    • 0035580741 scopus 로고    scopus 로고
    • Private politics, corporate social responsibility, and integrated strategy
    • Baron, D.P. Private politics, corporate social responsibility, and integrated strategy. Journal of Economics & Management Strategy, 10, 1 (2001), 7-45.
    • (2001) Journal of Economics & Management Strategy , vol.10 , Issue.1 , pp. 7-45
    • Baron, D.P.1
  • 17
    • 0000758307 scopus 로고
    • A three-dimensional conceptual model of corporate social performance
    • Carroll, A.B. A three-dimensional conceptual model of corporate social performance. Academy of Management Review, 4 (1979), 497-505.
    • (1979) Academy of Management Review , vol.4 , pp. 497-505
    • Carroll, A.B.1
  • 18
    • 33947376004 scopus 로고    scopus 로고
    • Efficiency of vulnerability disclosure mechanisms to disseminate vulnerability knowledge
    • Cavusoglu, H.; Cavusoglu, H.; and Raghunathan, S. Efficiency of vulnerability disclosure mechanisms to disseminate vulnerability knowledge. IEEE Transactions on Software Engineering, 33, 3 (2007), 171-184.
    • (2007) IEEE Transactions on Software Engineering , vol.33 , Issue.3 , pp. 171-184
    • Cavusoglu, H.1    Cavusoglu, H.2    Raghunathan, S.3
  • 22
    • 0034478781 scopus 로고    scopus 로고
    • Coordinating expertise in software development teams
    • Faraj, S., and Sproull, L. Coordinating expertise in software development teams. Management Science, 46, 12 (2000), 1554-1568.
    • (2000) Management Science , vol.46 , Issue.12 , pp. 1554-1568
    • Faraj, S.1    Sproull, L.2
  • 29
    • 0347856275 scopus 로고
    • New York: Institute of Electrical and Electronics Engineers
    • IEEE Standard for Software Maintenance. New York: Institute of Electrical and Electronics Engineers, 1993.
    • (1993) IEEE Standard for Software Maintenance
  • 30
    • 66549101204 scopus 로고    scopus 로고
    • The impact of open source software on the strategic choices of firms developing proprietary software
    • Winter
    • Jaisingh, J.; See-To, E.W.K.; and Tam, K.Y. The impact of open source software on the strategic choices of firms developing proprietary software. Journal of Management Information Systems, 25, 3 (Winter 2008-9), 241-275.
    • (2008) Journal of Management Information Systems , vol.25 , Issue.3 , pp. 241-275
    • Jaisingh, J.1    See-To, E.W.K.2    Tam, K.Y.3
  • 31
    • 58849133506 scopus 로고    scopus 로고
    • Information risk of inadvertent disclosure: An analysis of file-sharing risk in the financial supply chain
    • Fall
    • Johnson, M.E. Information risk of inadvertent disclosure: An analysis of file-sharing risk in the financial supply chain. Journal of Management Information Systems, 25, 2 (Fall 2008), 97-123.
    • (2008) Journal of Management Information Systems , vol.25 , Issue.2 , pp. 97-123
    • Johnson, M.E.1
  • 32
    • 35948938098 scopus 로고    scopus 로고
    • Market reactions to information security breach announcements: An empirical analysis
    • Kannan, K.; Rees, J.; and Sridhar, S. Market reactions to information security breach announcements: An empirical analysis. International Journal of Electronic Commerce, 12, 1 (2007), 69-91.
    • (2007) International Journal of Electronic Commerce , vol.12 , Issue.1 , pp. 69-91
    • Kannan, K.1    Rees, J.2    Sridhar, S.3
  • 33
    • 2342524827 scopus 로고
    • Software complexity and software maintenance: A survey of empirical research
    • Kemerer, C.F. Software complexity and software maintenance: A survey of empirical research. Annals of Software Engineering, 1, 1 (1995), 1-22.
    • (1995) Annals of Software Engineering , vol.1 , Issue.1 , pp. 1-22
    • Kemerer, C.F.1
  • 35
    • 84892372742 scopus 로고
    • The robust inference for the cox proportional hazards model
    • Lin, D.Y., and Wei, L.J. The robust inference for the Cox proportional hazards model. Journal of the American Statistical Association, 84, 408 (1989), 1074-1078.
    • (1989) Journal of the American Statistical Association , vol.84 , Issue.408 , pp. 1074-1078
    • Lin, D.Y.1    Wei, L.J.2
  • 36
    • 84870973846 scopus 로고    scopus 로고
    • Design architecture, developer networks, and performance of open source software projects
    • Atlanta: Association for Information Systems available at
    • Liu, X., and Iyer, B. Design architecture, developer networks, and performance of open source software projects. In Proceedings of the 2007 International Conference on Information Systems. Atlanta: Association for Information Systems, 2007 (available at http://aisel.aisnet .org/icis2007/90/).
    • Proceedings of the 2007 International Conference on Information Systems , vol.2007
    • Liu, X.1    Iyer, B.2
  • 37
    • 34648837018 scopus 로고    scopus 로고
    • Improving the common vulnerability scoring system
    • Mell, P., and Scarfone, K. Improving the common vulnerability scoring system. IET Information Security, 1, 3 (2007), 119-127.
    • (2007) IET Information Security , vol.1 , Issue.3 , pp. 119-127
    • Mell, P.1    Scarfone, K.2
  • 40
    • 0029613841 scopus 로고
    • Importance of events per independent variable in proportional hazards regression analysis ii: Accuracy and precision of regression estimates
    • Peduzzi, P.; Concato, J.; Feinstein, A.R.; and Holford, T.R. Importance of events per independent variable in proportional hazards regression analysis II: Accuracy and precision of regression estimates. Journal of Clinical Epidemiology, 48, 12 (1995), 1503-1510.
    • (1995) Journal of Clinical Epidemiology , vol.48 , Issue.12 , pp. 1503-1510
    • Peduzzi, P.1    Concato, J.2    Feinstein, A.R.3    Holford, T.R.4
  • 42
    • 63349088117 scopus 로고    scopus 로고
    • The deterrent and displacement effects of information security enforcement: International evidence
    • Fall
    • Png, I.P.L.; Wang, C.Y.; and Wang, Q.H. The deterrent and displacement effects of information security enforcement: International evidence. Journal of Management Information Systems, 25, 2 (Fall 2008), 125-144.
    • (2008) Journal of Management Information Systems , vol.25 , Issue.2 , pp. 125-144
    • Png, I.P.L.1    Wang, C.Y.2    Wang, Q.H.3
  • 43
    • 1842478892 scopus 로고    scopus 로고
    • Customer attrition analysis for financial services using proportional hazard models
    • Poel, D.V.D., and Lariviere, B. Customer attrition analysis for financial services using proportional hazard models. European Journal of Operational Research, 157, 1 (2004), 196-217.
    • (2004) European Journal of Operational Research , vol.157 , Issue.1 , pp. 196-217
    • Poel, D.V.D.1    Lariviere, B.2
  • 44
    • 67649548424 scopus 로고    scopus 로고
    • Choice and chance: A conceptual model of paths to information security compromise
    • Ransbotham, S., and Mitra, S. Choice and chance: A conceptual model of paths to information security compromise. Information Systems Research, 20, 1 (2009), 121-139.
    • (2009) Information Systems Research , vol.20 , Issue.1 , pp. 121-139
    • Ransbotham, S.1    Mitra, S.2
  • 47
    • 38349118570 scopus 로고    scopus 로고
    • A strategic analysis of competition between open source and proprietary software
    • Summer
    • Sen, R. A strategic analysis of competition between open source and proprietary software. Journal of Management Information Systems, 24, 1 (Summer 2007), 233-257.
    • (2007) Journal of Management Information Systems , vol.24 , Issue.1 , pp. 233-257
    • Sen, R.1
  • 50
    • 0000856630 scopus 로고
    • Corporate social performance revisited
    • Wood, D.J. Corporate social performance revisited. Academy of Management Review, 16, 4 (1991), 691-718.
    • (1991) Academy of Management Review , vol.16 , Issue.4 , pp. 691-718
    • Wood, D.J.1
  • 51
    • 23744456455 scopus 로고    scopus 로고
    • Complexity of information systems development projects: Conceptualization and measurement development
    • Summer
    • Xia, W., and Lee, G. Complexity of information systems development projects: Conceptualization and measurement development. Journal of Management Information Systems, 22, 1 (Summer 2005), 45-83
    • (2005) Journal of Management Information Systems , vol.22 , Issue.1 , pp. 45-83
    • Xia, W.1    Lee, G.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.