Title Information
Title
Encouraging Responsible Disclosure of Software Vulnerabilities
Abstract
Vulnerabilities in software are commonplace. They are routinely exploited by bad actors to cause harm and for financial gain. As software is increasingly embedded in daily life, from refrigerators to implanted medical devices to transportation to power management systems, it becomes ever more important to address the problem of rampant software vulnerabilities. One way to improve the situation is wider use of programs for responsible disclosure of software vulnerabilities. Responsible disclosure programs are established by organizations to provide a mechanism for security researchers to disclose vulnerabilities to the entity that developed the product or service. When disclosing responsibly, the researcher typically reveals the vulnerability to the company, but otherwise keeps the vulnerability confidential for a period of time, so that the organization can develop and deploy a software fix for the vulnerability before it becomes publicly known. This paper explores the impediments to responsible disclosure of software vulnerabilities as well as solutions to encourage greater disclosure
Name
Name Part
Prostko, Robert S.
Role
Role Term (marcrelator) (authorityURI="http://id.loc.gov/vocabulary/relators", valueURI="http://id.loc.gov/vocabulary/relators/cre")
Creator
Name: Personal
Name Part
Hurley, Deborah
Role
Role Term: Text
Advisor
Name: Personal
Name Part
York, David
Role
Role Term: Text
Advisor
Name: Corporate
Name Part
Brown University. School of Professional Studies. Department of Computer Science
Role
Role Term: Text
Sponsor
Origin Information
Copyright Date
2019
Physical Description
Extent
24 p.
digitalOrigin
born digital
Note: Capstone
Capstone (EMCS)--Brown University, 2019
Subject (fast) (authorityURI="http://id.worldcat.org/fast/872484", valueURI="http://id.worldcat.org/fast/1033711")
Topic
Computer security
Subject (Local)
Topic
Vulnerability Disclosure
Subject (Local)
Topic
Software
Subject (Local)
Topic
Critical infrastructure
Subject (Local)
Topic
Hacking
Subject (Local)
Topic
Responsible Disclosure
Subject (Local)
Topic
Hackers
Subject (Local)
Topic
Internet of Things (IoT)
Subject (Local)
Topic
Bug Bounty
Type of Resource
text
Genre
Critical Challenge Project
Access Condition: rights statement (href="http://rightsstatements.org/vocab/InC/1.0/")
In Copyright
Access Condition: restriction on access
All rights reserved. Collection is open for research.
Language
Language Term (ISO639-2B)
English
Record Information
Record Content Source (marcorg)
RPB
Record Creation Date (encoding="iso8601")
20100429
Identifier: DOI
10.26300/kr9n-mt07