Sharing of Vulnerability Information among Companies: A Survey of Swedish CompaniesShow others and affiliations
2019 (English)In: 45th Euromicro Conference on Software Engineering and Advanced Applications, Institute of Electrical and Electronics Engineers (IEEE), 2019, p. 284-291, article id 8906689Conference paper, Published paper (Refereed)
Abstract [en]
Software products are rarely developed from scratch and vulnerabilities in such products might reside in parts that are either open source software or provided by another organization. Hence, the total cybersecurity of a product often depends on cooperation, explicit or implicit, between several organizations. We study the attitudes and practices of companies in software ecosystems towards sharing vulnerability information. Furthermore, we compare these practices to contemporary cybersecurity recommendations. This is performed through a questionnaire-based qualitative survey. The questionnaire is divided into two parts: The providers' perspective and the acquirers' perspective. The results show that companies are willing to share information with each other regarding vulnerabilities. Sharing is not considered to be harmful neither to the cybersecurity nor their business, even though a majority of the respondents consider vulnerability information sensitive. However, the companies, despite being open to sharing, are less inclined to proactively sharing vulnerability information. Furthermore, the providers do not perceive that there is a large interest in vulnerability information from their customers. Hence, the companies' overall attitude to sharing vulnerability information is passive but open. In contrast, contemporary cybersecurity guidelines recommend active disclosure and sharing among actors in an ecosystem.
Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2019. p. 284-291, article id 8906689
Series
Proceedings of the EUROMICRO Conference, ISSN 1089-6503, E-ISSN 2376-9505
Keywords [en]
Open source software, Surveys, Cybersecurity, Vulnerabilities
National Category
Software Engineering
Research subject
Software Engineering
Identifiers
URN: urn:nbn:se:bth-21205DOI: 10.1109/SEAA.2019.00051ISBN: 9781728132853 (print)OAI: oai:DiVA.org:bth-21205DiVA, id: diva2:1535195
Conference
45th Euromicro Conference on Software Engineering and Advanced Applications, SEAA 2019, Kallithea, Chalkidiki, Greece, 28 August through 30 August
Funder
Vinnova, 2016-00603, 2018-03965Swedish Civil Contingencies Agency, 2015-69862021-03-082021-03-082023-04-03Bibliographically approved
In thesis