Management Science
HOME HELP FEEDBACK SUBSCRIPTIONS ARCHIVE SEARCH TABLE OF CONTENTS
 QUICK SEARCH:   [advanced]


     


MANAGEMENT SCIENCE
Vol. 51, No. 5, May 2005, pp. 726-740
DOI: 10.1287/mnsc.1040.0357
This Article
Right arrow Full Text (PDF)
Right arrow References
Right arrow Alert me when this article is cited
Right arrow Alert me if a correction is posted
Services
Right arrow Email this article to a friend
Right arrow Similar articles in this journal
Right arrow Alert me to new issues of the journal
Right arrow Download to citation manager
Right arrow reprints & permissions
Citing Articles
Right arrow Citing Articles via HighWire
Right arrow Citing Articles via Google Scholar
Google Scholar
Right arrow Articles by Kannan, K.
Right arrow Articles by Telang, R.
Right arrow Search for Related Content

Market for Software Vulnerabilities? Think Again

Karthik Kannan, Rahul Telang

Krannert School of Management, Purdue University, West Lafayette, Indiana 47906
H. John Heinz III School of Public Policy and Management, Carnegie Mellon University, Pittsburgh, Pennsylvania 15213

kkarthik{at}mgmt.purdue.edu
rtelang^#x0040;andrew.cmu.edu

Software vulnerability disclosure has become a critical area of concern for policymakers. Traditionally, a Computer Emergency Response Team (CERT) acts as an infomediary between benign identifiers (who voluntarily report vulnerability information) and software users. After verifying a reported vulnerability, CERT sends out a public advisory so that users can safeguard their systems against potential exploits. Lately, firms such as iDefense have been implementing a new market-based approach for vulnerability information. The market-based infomediary provides monetary rewards to identifiers for each vulnerability reported. The infomediary then shares this information with its client base. Using this information, clients protect themselves against potential attacks that exploit those specific vulnerabilities.

The key question addressed in our paper is whether movement toward such a market-based mechanism for vulnerability disclosure leads to a better social outcome. Our analysis demonstrates that an active unregulated market-based mechanism for vulnerabilities almost always underperforms a passive CERT-type mechanism. This counterintuitive result is attributed to the market-based infomediary’s incentive to leak the vulnerability information inappropriately. If a profit-maximizing firm is not allowed to (or chooses not to) leak vulnerability information, we find that social welfare improves. Even a regulated market-based mechanism performs better than a CERT-type one, but only under certain conditions. Finally, we extend our analysis and show that a proposed mechanism—federally funded social planner—always performs better than a market-based mechanism.

Key Words: information security; software vulnerabilities; vulnerability disclosure; game theory; public policy
History: Received: April 13, 2004;


This article has been cited by other articles:


Home page
Information Systems ResearchHome page
S. Ransbotham and S. Mitra
Choice and Chance: A Conceptual Model of Paths to Information Security Compromise
Information Systems Research, March 1, 2009; 20(1): 121 - 139.
[Abstract] [PDF]


Home page
Management ScienceHome page
A. Arora, R. Telang, and H. Xu
Optimal Policy for Software Vulnerability Disclosure
Management Science, April 1, 2008; 54(4): 642 - 656.
[Abstract] [PDF]


Home page
Information Systems ResearchHome page
J. Wang, A. Chaudhury, and H. R. Rao
Research Note--A Value-at-Risk Approach to Information Security Investment
Information Systems Research, March 1, 2008; 19(1): 106 - 120.
[Abstract] [PDF]




HOME HELP FEEDBACK SUBSCRIPTIONS ARCHIVE SEARCH TABLE OF CONTENTS
Copyright © 2005 by INFORMS.