Ethical Implications of Security Vulnerability Research for Critical Infrastructure Protection

  • Nweke L
  • Wolthusen S
N/ACitations
Citations of this article
7Readers
Mendeley users who have this article in their library.

Abstract

Security vulnerability research (SVR) involves searching for security flaws in a system. Such activity is likely to raise ethical concerns which need to be considered. For example, if a security researcher discovers a vulnerability in a critical infrastructure that can be exploited by an attacker; what is the right thing to do? Based on 'duty of care' principle and the fact that a public disclosure would force the critical infrastructure operator to quickly address the issue; going public with the discovery seems to be the right course of action. However, based on 'do not cause harm to others' principle, a public disclosure could badly affect the reputation of the critical infrastructure operator. Also, there is the possibility that the disclosed vulnerability could be exploited by an attacker before the operator is able to resolve the problem. The question would then be: is public disclosure still the right thing to do? This type of situation raises an ethical dilemma because a critical infrastructure is a system that is essential for the maintenance of vital societal functions and any attack against such an infrastructure would have a devastating effect. In this paper, we examine the ethical implications of SVR for critical infrastructure protection using the three normative ethical theories. First, we review the state-of-the-art of ethics in SVR. Then, we investigate how the three different normative ethical frameworks would respond to a hypothetical scenario relating to security vulnerability in a critical infrastructure in order to provide guidance for security researchers involved in SVR. Finally, we present a discussion on how a security researcher would make an ethical decision when confronted with an ethical dilemma. We observe from this study that a security researcher could rely on the three different normative ethical frameworks to reason about the best course of action during SVR for critical infrastructure protection.

Cite

CITATION STYLE

APA

Nweke, L. O., & Wolthusen, S. D. (2020). Ethical Implications of Security Vulnerability Research for Critical Infrastructure Protection. In WI2020 Community Tracks (pp. 331–340). GITO Verlag. https://doi.org/10.30844/wi_2020_z4-paper2

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free