• DocumentCode
    1231913
  • Title

    Is finding security holes a good idea?

  • Author

    Rescorla, Eric

  • Volume
    3
  • Issue
    1
  • fYear
    2005
  • Firstpage
    14
  • Lastpage
    19
  • Abstract
    Despite the large amount of effort that goes toward finding and patching security holes, the available data does not show a clear improvement in software quality as a result. This article aims to measure the effect of vulnerability finding. Any attempt to measure this kind of effect is inherently rough, depending as it does on imperfect data and several simplifying assumptions. Because I´m looking for evidence of usefulness, where possible, I bias such assumptions in favor of a positive result - explicitly calling out those assumptions biased in the opposite direction. Thus, the analysis in this article represents the best-case scenario, consistent with the data and my ability to analyze it, for the vulnerability finding´s usefulness
  • Keywords
    security of data; software maintenance; software quality; security holes; software quality; vulnerability finding; Computer security; Costs; Data privacy; Data security; Information security; Large-scale systems; Packaging; Software quality; Solid modeling; blackhat; software patches; vulnerability disclosure; whitehat;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSP.2005.17
  • Filename
    1392694