Does information security attack frequency increase with vulnerability disclosure? An empirical analysis
By Anand Nandkumar, Ashish Arora, Rahul Telang
Information Systems Frontier | November 2006
DOI
http://www.springerlink.com/content/h322x464284337p1/
Citation
Nandkumar, Anand., Arora, Ashish., Telang, Rahul. Does information security attack frequency increase with vulnerability disclosure? An empirical analysis Information Systems Frontier http://www.springerlink.com/content/h322x464284337p1/.
Copyright
Information Systems Frontier, 2006
Share:
Abstract
Research in information security, risk management and investment has grown in importance over the last few years. However, without reliable estimates on attack probabilities, risk management is difficult to do in practice. Using a novel data set, we provide estimates on attack propensity and how it changes with disclosure and patching of vulnerabilities. Disclosure of software vulnerability has been controversial. On one hand are those who propose full and instant disclosure whether the patch is available or not and on the other hand are those who argue for limited or no disclosure. Which of the two policies is socially optimal depends critically on how attack frequency changes with disclosure and patching. In this paper, we empirically explore the impact of vulnerability information disclosure and availability of patches on attacks targeting the vulnerability. Our results suggest that on an average both secret (non-published) and published (published and not patched) vulnerabilities attract fewer attacks than patched (published and patched) vulnerabilities. When we control for time since publication and patches, we find that patching an already known vulnerability decreases the number of attacks, although attacks gradually increase with time after patch release. Patching an unknown vulnerability, however, causes a spike in attacks, which then gradually decline after patch release. Attacks on secret vulnerabilities slowly increase with time until the vulnerability is published and then attacks rapidly decrease with time after publication.

Anand Nandkumar is an Associate Professor of Strategy, Executive Director of SRITNE at the Indian School of Business (ISB), and Associate Dean of the Centre for Learning and Teaching Excellence. He explores industry and firm-level phenomena that influence innovation - the generation of new ideas, and entrepreneurship - distribution and commercialisation of new ideas. His research focuses on high-technology industries such as pharmaceuticals, biotechnology, and software, and it falls in between industrial organisation (IO), economics of technological change, and strategy.

Professor Nandkumar’s current work in the innovation stream examines the effect of stronger intellectual property rights (IPR) on different aspects of innovation, such as the influence of stronger patents on long run incentives for innovation or the influence of stronger patents on the functioning of Markets for Technology (MFT). In the entrepreneurship stream, his current work examines the influence of venture capitalists on entrepreneurial performance.

Professor Nandkumar graduated with a PhD in Public Policy and Management, with a focus in strategy and entrepreneurship from Carnegie Mellon University in 2008. Prior to his PhD, he worked for 3 years with a startup in Silicon Valley, and prior to that, in New York City with one of the world’s largest financial services firms.

True to his expertise, at ISB, Professor Nandkumar teaches Strategic Innovation Management and Strategic Challenges for Innovation-based startups.

Anand Nandkumar
Anand Nandkumar