A Mixed Methods Probe into the Direct Disclosure of Software Vulnerabilities

dc.contributor.authorRuohonen Jukka
dc.contributor.authorHyrynsalmi Sami
dc.contributor.authorLeppänen Ville
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.contributor.organization-code2610302
dc.converis.publication-id44871605
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/44871605
dc.date.accessioned2022-10-28T12:46:00Z
dc.date.available2022-10-28T12:46:00Z
dc.description.abstract<p>Software vulnerabilities are security-related software bugs. Direct disclosure refers to a practice that is widely used for communicating the confidential information about vulnerabilities between two parties, vulnerability discoverers and software producers. Building on software vulnerability life cycle analysis, this empirical paper observes the qualitative and quantitative characteristics of direct disclosure practices, focusing particularly on the historical problem related to producers’ reluctance to participate in the practices. According to the results, the problem was still present in the 2000s and early 2010s—and likely is still present today. By presenting this empirical result about the under researched phenomenon of direct disclosure of software vulnerabilities, the paper contributes to the research domain of vulnerability life cycle modeling in general and the subdomain of empirical vulnerability disclosure research in particular.<br></p>
dc.format.pagerange161
dc.format.pagerange173
dc.identifier.eissn1873-7692
dc.identifier.jour-issn0747-5632
dc.identifier.olddbid178805
dc.identifier.oldhandle10024/161899
dc.identifier.urihttps://www.utupub.fi/handle/11111/36359
dc.identifier.urnURN:NBN:fi-fe2021042826005
dc.language.isoen
dc.okm.affiliatedauthorRuohonen, Jukka
dc.okm.affiliatedauthorHyrynsalmi, Sami
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA1 ScientificArticle
dc.publisherElsevier
dc.publisher.countryUnited Kingdomen_GB
dc.publisher.countryBritanniafi_FI
dc.publisher.country-codeGB
dc.relation.doi10.1016/j.chb.2019.09.028
dc.relation.ispartofjournalComputers in Human Behavior
dc.relation.volume103
dc.source.identifierhttps://www.utupub.fi/handle/10024/161899
dc.titleA Mixed Methods Probe into the Direct Disclosure of Software Vulnerabilities
dc.year.issued2020

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
vulndirectdisc.pdf
Size:
825.62 KB
Format:
Adobe Portable Document Format
Description:
Final draft