Modeling the Security Ecosystem - The Dynamics of (In)Security

  • Frei S
  • Schatzmann D
  • Plattner B
  • et al.
N/ACitations
Citations of this article
65Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The security of information technology and computer networks is effected by a wide variety of actors and processes which together make up a security ecosystem; here we examine this ecosystem, consolidating many aspects of security that have hitherto been discussed only separately. First, we analyze the roles of the major actors within this ecosystem and the processes they participate in, and the the paths vulnerability data take through the ecosystem and the impact of each of these on security risk. Then, based on a quantitative examination of 27,000 vulnerabilities disclosed over the past decade and taken from publicly available data sources, we quantify the systematic gap between exploit and patch availability. We provide the first examination of the impact and the risks associated with this gap on the ecosystem as a whole. Our analysis provides a metric for the success of the responsible disclosure process. We measure the prevalence of the commercial markets for vulnerability information and highlight the role of security information providers (SIP), which function as the free press of the ecosystem.

Cite

CITATION STYLE

APA

Frei, S., Schatzmann, D., Plattner, B., & Trammell, B. (2010). Modeling the Security Ecosystem - The Dynamics of (In)Security. In Economics of Information Security and Privacy (pp. 79–106). Springer US. https://doi.org/10.1007/978-1-4419-6967-5_6

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free