A1 Vertaisarvioitu alkuperäisartikkeli tieteellisessä lehdessä

A Mixed Methods Probe into the Direct Disclosure of Software Vulnerabilities




TekijätRuohonen Jukka, Hyrynsalmi Sami, Leppänen Ville

KustantajaElsevier

Julkaisuvuosi2020

JournalComputers in Human Behavior

Vuosikerta103

Aloitussivu161

Lopetussivu173

Sivujen määrä13

ISSN0747-5632

eISSN1873-7692

DOIhttps://doi.org/10.1016/j.chb.2019.09.028

Rinnakkaistallenteen osoitehttps://research.utu.fi/converis/portal/detail/Publication/44871605


Tiivistelmä

Software vulnerabilities are security-related software bugs. Direct disclosure refers to a practice that is widely used for communicating the confidential information about vulnerabilities between two parties, vulnerability discoverers and software producers. Building on software vulnerability life cycle analysis, this empirical paper observes the qualitative and quantitative characteristics of direct disclosure practices, focusing particularly on the historical problem related to producers’ reluctance to participate in the practices. According to the results, the problem was still present in the 2000s and early 2010s—and likely is still present today. By presenting this empirical result about the under researched phenomenon of direct disclosure of software vulnerabilities, the paper contributes to the research domain of vulnerability life cycle modeling in general and the subdomain of empirical vulnerability disclosure research in particular.


Ladattava julkaisu

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.





Last updated on 2024-26-11 at 11:05