Brown University

Encouraging Responsible Disclosure of Software Vulnerabilities

Description

Abstract:
Vulnerabilities in software are commonplace. They are routinely exploited by bad actors to cause harm and for financial gain. As software is increasingly embedded in daily life, from refrigerators to implanted medical devices to transportation to power management systems, it becomes ever more important to address the problem of rampant software vulnerabilities. One way to improve the situation is wider use of programs for responsible disclosure of software vulnerabilities. Responsible disclosure programs are established by organizations to provide a mechanism for security researchers to disclose vulnerabilities to the entity that developed the product or service. When disclosing responsibly, the researcher typically reveals the vulnerability to the company, but otherwise keeps the vulnerability confidential for a period of time, so that the organization can develop and deploy a software fix for the vulnerability before it becomes publicly known. This paper explores the impediments to responsible disclosure of software vulnerabilities as well as solutions to encourage greater disclosure
Notes:
Capstone (EMCS)--Brown University, 2019

Access Conditions

Rights
In Copyright
Restrictions on Use
All rights reserved. Collection is open for research.

Citation

Prostko, Robert S., "Encouraging Responsible Disclosure of Software Vulnerabilities" (2019). Master of Science in Cybersecurity. Brown Digital Repository. Brown University Library. https://doi.org/10.26300/kr9n-mt07

Relations

Collection:

  • Master of Science in Cybersecurity

    Brown's Master of Science (ScM) in Cybersecurity is a program for professionals designed to cultivate high-demand, industry executives with the unique and critical ability to devise and execute integrated, comprehensive cybersecurity strategies. Students gain immediately applicable knowledge and, through an …
    ...