Determinants of Software Vulnerability Disclosure Timing
Ravi Sen,
Joobin Choobineh and
Subodha Kumar
Production and Operations Management, 2020, vol. 29, issue 11, 2532-2552
Abstract:
The timing of vulnerability disclosures (by vulnerability discoverers) has significant implications for software producers and users. Immediate disclosure (before a patch becomes available) could result in exploits with subsequent harm to installed systems. Therefore, it is important to understand the determinants of this timing. In this study, we investigate the impacts of (i) the perception of the vulnerability discoverer about the software producer, (ii) the type of vulnerable software, and (iii) the severity of the vulnerability, on a vulnerability discoverer's choice of disclosure timing. We collect data from three different sources and control for the vulnerability discoverer's motivations and beliefs. Our results indicate that those who perceive a software producer to be timely in its patch release, reward it by delaying the disclosure. We also find that it is more likely that the disclosure is delayed for open source software and it is less likely that the disclosure is delayed for more severe vulnerabilities. The findings of this study are relevant to software producers in their decision‐making process on resource allocation for software patches and should also help policy‐makers to devise regulations relevant to the timing of disclosures and patch releases. Furthermore, these findings could be relevant to software consumers searching for a particular software product that they would like to use. This study attempts to provide insights into an ongoing discussion in the operations management community regarding how to allocate and divide resources between software development and software maintenance.
Date: 2020
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (4)
Downloads: (external link)
https://doi.org/10.1111/poms.13120
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:bla:popmgt:v:29:y:2020:i:11:p:2532-2552
Ordering information: This journal article can be ordered from
http://onlinelibrary ... 1111/(ISSN)1937-5956
Access Statistics for this article
Production and Operations Management is currently edited by Kalyan Singhal
More articles in Production and Operations Management from Production and Operations Management Society
Bibliographic data for series maintained by Wiley Content Delivery ().