- Title Information
- Title
- Encouraging Responsible Disclosure of Software Vulnerabilities
- Abstract
-
Vulnerabilities in software are commonplace. They are routinely exploited by bad actors to cause harm and for financial gain. As software is increasingly embedded in daily life, from refrigerators to implanted medical devices to transportation to power management systems, it becomes ever more important to address the problem of rampant software vulnerabilities. One way to improve the situation is wider use of programs for responsible disclosure of software vulnerabilities. Responsible disclosure programs are established by organizations to provide a mechanism for security researchers to disclose vulnerabilities to the entity that developed the product or service. When disclosing responsibly, the researcher typically reveals the vulnerability to the company, but otherwise keeps the vulnerability confidential for a period of time, so that the organization can develop and deploy a software fix for the vulnerability before it becomes publicly known. This paper explores the impediments to responsible disclosure of software vulnerabilities as well as solutions to encourage greater disclosure
- Name
- Name Part
- Prostko, Robert S.
- Role
- Role Term (marcrelator)
(authorityURI="http://id.loc.gov/vocabulary/relators", valueURI="http://id.loc.gov/vocabulary/relators/cre")
- Creator
- Name:
Personal
- Name Part
- Hurley, Deborah
- Role
- Role Term:
Text
- Advisor
- Name:
Personal
- Name Part
- York, David
- Role
- Role Term:
Text
- Advisor
- Name:
Corporate
- Name Part
-
Brown University. School of Professional Studies. Department of Computer Science
- Role
- Role Term:
Text
- Sponsor
- Origin Information
- Copyright Date
- 2019
- Physical Description
- Extent
- 24 p.
- digitalOrigin
- born digital
- Note:
Capstone
- Capstone (EMCS)--Brown University, 2019
- Subject (fast)
(authorityURI="http://id.worldcat.org/fast/872484", valueURI="http://id.worldcat.org/fast/1033711")
- Topic
- Computer security
- Subject (Local)
- Topic
- Vulnerability Disclosure
- Subject (Local)
- Topic
- Software
- Subject (Local)
- Topic
- Critical infrastructure
- Subject (Local)
- Topic
- Hacking
- Subject (Local)
- Topic
- Responsible Disclosure
- Subject (Local)
- Topic
- Hackers
- Subject (Local)
- Topic
- Internet of Things (IoT)
- Subject (Local)
- Topic
- Bug Bounty
- Type of Resource
- text
- Genre
- Critical Challenge Project
- Access Condition:
rights statement
(href="http://rightsstatements.org/vocab/InC/1.0/")
- In Copyright
- Access Condition:
restriction on access
- All rights reserved. Collection is open for research.
- Language
- Language Term (ISO639-2B)
- English
- Record Information
- Record Content Source (marcorg)
- RPB
- Record Creation Date
(encoding="iso8601")
- 20100429
- Identifier:
DOI
- 10.26300/kr9n-mt07