Sciweavers

ISF
2006

Does information security attack frequency increase with vulnerability disclosure? An empirical analysis

13 years 4 months ago
Does information security attack frequency increase with vulnerability disclosure? An empirical analysis
Abstract Research in information security, risk management and investment has grown in importance over the last few years. However, without reliable estimates on attack probabilities, risk management is difficult to do in practice. Using a novel data set, we provide estimates on attack propensity and how it changes with disclosure and patching of vulnerabilities. Disclosure of software vulnerability has been controversial. On one hand are those who propose full and instant disclosure whether the patch is available or not and on the other hand are those who argue for limited or no disclosure. Which of the two policies is socially optimal depends critically on how attack frequency changes with disclosure and patching. In this paper, we empirically explore the impact of vulnerability information disclosure and availability of patches on attacks targeting the vulnerability. Our results suggest that on an average both secret (non-published) and published (published and not patched) vulnerab...
Ashish Arora, Anand Nandkumar, Rahul Telang
Added 13 Dec 2010
Updated 13 Dec 2010
Type Journal
Year 2006
Where ISF
Authors Ashish Arora, Anand Nandkumar, Rahul Telang
Comments (0)