An Empirical Analysis of Software Vendors' Patch Release Behavior: Impact of Vulnerability Disclosure
Ashish Arora (), 
Ramayya Krishnan (), 
Rahul Telang and 
Yubao Yang ()
Additional contact information 
Ramayya Krishnan: H. John Heinz III College, Carnegie Mellon University, Pittsburgh, Pennsylvania 15213
Yubao Yang: H. John Heinz III College, Carnegie Mellon University, Pittsburgh, Pennsylvania 15213
Information Systems Research, 2010, vol. 21, issue 1, 115-132
Abstract:
A key aspect of better and more secure software is timely patch release by software vendors for the vulnerabilities in their products. Software vulnerability disclosure, which refers to the publication of vulnerability information, has generated intense debate. An important consideration in this debate is the behavior of software vendors. How quickly do vendors patch vulnerabilities and how does disclosure affect patch release time? This paper compiles a unique data set from the Computer Emergency Response Team/Coordination Center (CERT) and SecurityFocus to answer this question. Our results suggest that disclosure accelerates patch release. The instantaneous probability of releasing the patch rises by nearly two and a half times because of disclosure. Open source vendors release patches more quickly than closed source vendors. Vendors are more responsive to more severe vulnerabilities. We also find that vendors respond more slowly to vulnerabilities not disclosed by CERT. We verify our results by using another publicly available data set and find that results are consistent. We also show how our estimates can aid policy makers in their decision making.
Keywords: security vulnerability; disclosure policy; patch release time; open source vendors; information security; software vendors; hazard model (search for similar items in EconPapers)
Date: 2010
References: View references in EconPapers View complete reference list from CitEc 
Citations: View citations in EconPapers (11) 
Downloads: (external link)
http://dx.doi.org/10.1287/isre.1080.0226 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX 
RIS (EndNote, ProCite, RefMan) 
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:inm:orisre:v:21:y:2010:i:1:p:115-132
Access Statistics for this article
More articles in Information Systems Research  from  INFORMS Contact information at EDIRC.
Bibliographic data for series maintained by Chris Asher ().