Vulnerability disclosure mechanisms: A synthesis and framework for market-based and non-market-based disclosures
作者:
Highlights:
• A systematic literature review and synthesis of two decades of research on vulnerability disclosure mechanisms.
• A process-based typology of market-based and non-market-based vulnerability disclosure mechanisms.
• Antecedents and consequences of vulnerability disclosure under various mechanisms.
• Theoretical frameworks and comparison of the non-market-based and market-based vulnerability disclosure mechanisms.
• Future research directions and implications for organizations, ethical hackers and platforms.
摘要
Vulnerability disclosure has been a controversial topic among scholars and practitioners. Most scholars agree on adopting the responsible disclosure practices for vulnerability disclosures, which give firms a protected period to address the vulnerability before public disclosure is made. However, the firms may not fully utilize the protected period resulting in financial and reputational losses. The recent popularity in market-based disclosure methods such as bug bounty programs has provided new methods to control ethical hackers and effectively manage the disclosure timelines. Through a systematic literature review, we investigate and identify various vulnerability disclosure mechanisms and elaborate the disclosure process of each mechanism. We synthesize and compare the antecedents and consequences of the vulnerability disclosure under market- and non-market-based disclosure mechanisms by proposing two research frameworks. Our analysis suggests that incentivizing hackers in market mechanisms change hackers' motivations, leading to behavioral changes and eventually giving firms more control over the disclosure process. Additionally, our research frameworks provide a basis for further theorizing in this area. We also identify several open research questions addressing issues and challenges in the market-based disclosures. The research has important implications for firms, hackers, policymakers, and researchers in this area.
论文关键词:Vulnerability disclosure,Bug bounty,Systematic literature review,Vulnerability markets,Information security economics
论文评审过程:Received 19 October 2020, Revised 27 April 2021, Accepted 28 April 2021, Available online 5 May 2021, Version of Record 7 July 2021.
论文官网地址:https://doi.org/10.1016/j.dss.2021.113586