NETWORK SECURITY: VULNERABILITIES AND DISCLOSURE POLICY

Warning: is_dir(): open_basedir restriction in effect. File(/libraries) is not within the allowed path(s): (/home/web1050:/usr/share/php) in libraries_get_libraries() (line 176 of /home/web1050/public_html/sites/all/modules/contrib/libraries/libraries.module).

Software security is a major concern for vendors, consumers and regulators. When vulnerabilities are discovered after the software has been sold to consumers, the firms face a dilemma. A policy of disclosing vulnerabilities and issuing updates protects only consumers who install updates, while the disclosure itself facilitates reverse engineering of the vulnerability by hackers. The paper considers a firm that sells software which is subject to potential security breaches and derives the conditions under which a firm would disclose vulnerabilities. It examines the effect of a regulatory policy that requires mandatory disclosure of vulnerabilities and a ‘bug bounty’ program.