Skip to main content

An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure

Publication ,  Journal Article
Arora, A; Krishnan, R; Telang, R; Yang, Y
Published in: Information Systems Research
January 1, 2010

Akey aspect of better and more secure software is timely patch release by software vendors for the vulnerabilities in their products. Software vulnerability disclosure, which refers to the publication of vulnerability information, has generated intense debate. An important consideration in this debate is the behavior of software vendors. How quickly do vendors patch vulnerabilities and how does disclosure affect patch release time? This paper compiles a unique data set from the Computer Emergency Response Team/Coordination Center (CERT) and SecurityFocus to answer this question. Our results suggest that disclosure accelerates patch release. The instantaneous probability of releasing the patch rises by nearly two and a half times because of disclosure. Open source vendors release patches more quickly than closed source vendors. Vendors are more responsive to more severe vulnerabilities. We also find that vendors respond more slowly to vulnerabilities not disclosed by CERT. We verify our results by using another publicly available data set and find that results are consistent. We also show how our estimates can aid policy makers in their decision making. © 2010 INFORMS.

Duke Scholars

Altmetric Attention Stats
Dimensions Citation Stats

Published In

Information Systems Research

DOI

EISSN

1526-5536

ISSN

1047-7047

Publication Date

January 1, 2010

Volume

21

Issue

1

Start / End Page

115 / 132

Related Subject Headings

  • Information Systems
  • 4609 Information systems
  • 3503 Business systems in context
  • 1505 Marketing
  • 1503 Business and Management
  • 0806 Information Systems
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Arora, A., Krishnan, R., Telang, R., & Yang, Y. (2010). An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure. Information Systems Research, 21(1), 115–132. https://doi.org/10.1287/isre.1080.0226
Arora, A., R. Krishnan, R. Telang, and Y. Yang. “An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure.” Information Systems Research 21, no. 1 (January 1, 2010): 115–32. https://doi.org/10.1287/isre.1080.0226.
Arora A, Krishnan R, Telang R, Yang Y. An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure. Information Systems Research. 2010 Jan 1;21(1):115–32.
Arora, A., et al. “An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure.” Information Systems Research, vol. 21, no. 1, Jan. 2010, pp. 115–32. Scopus, doi:10.1287/isre.1080.0226.
Arora A, Krishnan R, Telang R, Yang Y. An empirical analysis of software vendors' patch release behavior: Impact of vulnerability disclosure. Information Systems Research. 2010 Jan 1;21(1):115–132.

Published In

Information Systems Research

DOI

EISSN

1526-5536

ISSN

1047-7047

Publication Date

January 1, 2010

Volume

21

Issue

1

Start / End Page

115 / 132

Related Subject Headings

  • Information Systems
  • 4609 Information systems
  • 3503 Business systems in context
  • 1505 Marketing
  • 1503 Business and Management
  • 0806 Information Systems