No One Drinks From the Firehose: How Organizations Filter and Prioritize Vulnerability Information
Stephanie de Smale, Rik van Dijk, Xander Bouwman, Jeroen van der Ham, Michel van Eeten
摘要
The number of published software vulnerabilities is increasing every year. How do organizations stay in control of their attack surface despite their limited staff resources? Prior work has analyzed the overall software vulnerability ecosystem as well as patching processes within organizations, but not how these two are connected.We investigate this missing link through semi-structured interviews with 22 organizations in critical infrastructure and government services. We analyze where in these organizations the responsibility is allocated to collect and triage information about software vulnerabilities, and find that none of our respondents is acquiring such information comprehensively, not even in a reduced and aggregated form like the National Vulnerability Database (NVD). This means that information on known vulnerabilities will be missed, even in critical infrastructure organizations. We observe that organizations apply implicit and explicit coping mechanisms to reduce their intake of vulnerability information, and identify three trade-offs in these strategies: independence, pro-activeness and formalization.Although our respondents’ behavior is in conflict with the widely accepted security advice to collect comprehensive vulnerability information about active systems, no respondents recall having experienced a security incident that was associated with missing information on a known software vulnerability. This suggests that, given scarce resources, reducing the intake of vulnerability information by up to 95% can be considered a rational strategy. Our findings raise questions about the allocation of responsibility and accountability for finding vulnerable systems, as well as suggest changing expectations around collecting vulnerability information.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Unveiling the Hunter-Gatherers: Exploring Threat Hunting Practices and Challenges in Cyber DefensePriyanka Badva, Kopo M. Ramokapane, Eleonora Pantano, Awais RashidUSENIX Security 2024 · 被引用 13 次
- Not as easy as just update: Survey of System Administrators and Patching BehavioursAdam D. G. Jenkins, Linsen Liu, Maria K. Wolters, Kami VanieaCHI 2024 · 被引用 10 次
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 被引用 4 次
- Actively Understanding the Dynamics and Risks of the Threat Intelligence EcosystemTillson Galloway, Omar Alrawi, Allen Chang, Athanasios Avgetidis 等NDSS 2026 · 被引用 2 次
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 被引用 1 次
它引用的顶会 Paper5
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 被引用 116 次
- Mind Your Own Business: A Longitudinal Study of Threats and Vulnerabilities in EnterprisesPlaton Kotzias, Leyla Bilge, Pierre-Antoine Vervier, Juan CaballeroNDSS 2019 · 被引用 43 次
- From Patching Delays to Infection Symptoms: Using Risk Profiles for an Early Discovery of Vulnerabilities Exploited in the WildChaowei Xiao, Armin Sarabi, Yang Liu, Bo Li 等USENIX Security 2018 · 被引用 31 次
- A different cup of TI? The added value of commercial threat intelligenceXander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr 等USENIX Security 2020
相关 Paper
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu 等USENIX Security 2018 · 被引用 138 次
- Speedrunning the Maze: Meeting Regulatory Patching Deadlines in a Large Enterprise EnvironmentGerbrand ten Napel, Michel van Eeten, Simon ParkinS&P 2025
- VulLibGen: Generating Names of Vulnerability-Affected Packages via a Large Language ModelTianyu Chen, Lin Li, Liuchuan Zhu, Zongyang Li 等ACL 2024 · 被引用 5 次
- Vision: Identifying Affected Library Versions for Open Source Software VulnerabilitiesSusheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao 等ASE 2024 · 被引用 1 次
- A Grounded Theory Based Approach to Characterize Software Attack SurfacesSara Moshtari, Ahmet Okutan, Mehdi MirakhorliICSE 2022 · 被引用 7 次
