دورية أكاديمية

Regulatory mechanism of vulnerability disclosure behavior considering security crowd-testing: An evolutionary game analysis.

التفاصيل البيبلوغرافية
العنوان: Regulatory mechanism of vulnerability disclosure behavior considering security crowd-testing: An evolutionary game analysis.
المؤلفون: Liurong Zhao, Xiaoxi Yu, Xinyu Zhou
المصدر: PLoS ONE, Vol 19, Iss 6, p e0304467 (2024)
بيانات النشر: Public Library of Science (PLoS), 2024.
سنة النشر: 2024
المجموعة: LCC:Medicine
LCC:Science
مصطلحات موضوعية: Medicine, Science
الوصف: The security crowd-testing regulatory mechanism is a vital means to promote collaborative vulnerability disclosure. However, existing regulatory mechanisms have not considered multi-agent responsibility boundaries and stakeholders' conflicts of interest, leading to their dysfunction. Distinguishing from previous research on the motivations and constraints of ethical hacks' vulnerability disclosure behaviors from a legal perspective, this paper constructs an evolutionary game model of SRCs, security researchers, and the government from a managerial perspective to propose regulatory mechanisms promoting tripartite collaborative vulnerability disclosure. The results show that the higher the initial willingness of the three parties to choose the collaborative strategy, the faster the system evolves into a stable state. Regarding the government's incentive mechanism, establishing reward and punishment mechanisms based on effective thresholds is essential. However, it is worth noting that the government has an incentive to adopt such mechanisms only if it receives sufficient regulatory benefits. To further facilitate collaborative disclosure, Security Response Centers (SRC) should establish incentive mechanisms including punishment and trust mechanisms. Additionally, publicity and training mechanisms for security researchers should be introduced to reduce their revenue from illegal participation, which promotes the healthy development of security crowd-testing. These findings contribute to improving SRCs' service quality, guiding security researchers' legal participation, enhancing the government's regulatory effectiveness, and ultimately establishing a multi-party collaborative vulnerability disclosure system.
نوع الوثيقة: article
وصف الملف: electronic resource
اللغة: English
تدمد: 1932-6203
Relation: https://doaj.org/toc/1932-6203
DOI: 10.1371/journal.pone.0304467
URL الوصول: https://doaj.org/article/3ddee43ad7824ad4ba7b1ef22fc0c322
رقم الأكسشن: edsdoj.3ddee43ad7824ad4ba7b1ef22fc0c322
قاعدة البيانات: Directory of Open Access Journals
الوصف
تدمد:19326203
DOI:10.1371/journal.pone.0304467