Didn't You Hear Me? - Towards More Successful Web Vulnerability Notifications
Ben Stock, Giancarlo Pellegrino, Frank Li, Michael Backes, Christian Rossow
摘要
After treating the notification of vulnerable parties as mere side-notes in research, the security community has recently put more focus on how to conduct vulnerability disclosure at scale. The first works in this area have shown that while notifications are helpful to a significant fraction of operators, the vast majority of systems remain unpatched. In this paper, we build on these previous works, aiming to understand why the effects are not more significant. To that end, we report on a notification experiment targeting more than 24,000 domains, which allowed us to analyze what technical and human aspects are roadblocks to a successful campaign. As part of this experiment, we explored potential alternative notification channels beyond email, including social media and phone. In addition, we conducted an anonymous survey with the notified operators, investigating their perspectives on our notifications. We show the pitfalls of email-based communications, such as the impact of anti-spam filters, the lack of trust by recipients, and the hesitation in fixing vulnerabilities despite awareness. However, our exploration of alternative communication channels did not suggest a more promising medium. Seeing these results, we pinpoint future directions in improving security notifications. Since the field of vulnerability notification at scale is still in its infancy, our work not only aims at tackling the previously described research questions, but also identifies areas in which further research should be conducted to improve the quality and success of large-scale vulnerability disclosure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper28
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 被引用 70 次
- Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove MiraiOrçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama 等NDSS 2019 · 被引用 57 次
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen 等CCS 2020 · 被引用 54 次
- Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and SupportMax Maass, Alina Stöver, Henning Pridöhl, Sebastian Bretthauer 等USENIX Security 2021 · 被引用 35 次
- Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern WebMarco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara 等USENIX Security 2021 · 被引用 30 次
它引用的顶会 Paper5
- DROWN: Breaking TLS Using SSLv2Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger 等USENIX Security 2016 · 被引用 192 次
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns 等USENIX Security 2016 · 被引用 130 次
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 被引用 114 次
- Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security PolicyJakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. BaileyNDSS 2016 · 被引用 87 次
相关 Paper
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo PellegrinoS&P 2026
- Deployment of Source Address Validation by Network Operators: A Randomized Control TrialQasim Lone, Alisa Frik, Matthew Luckie, Maciej Korczynski 等S&P 2022 · 被引用 16 次
- Do They Get With the Program? Measuring Mitigation in a Solicited Vulnerability Notification ProgramYana Angelova, Carlos Gañán, Annebel Smit, Rolf van Wegberg 等USENIX Security 2026
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 被引用 4 次
- The (Un)usual Suspects - Studying Reasons for Lacking Updates in WordPressMaria Hellenthal, Lena Gotsche, Rafael Mrowczynski, Sarah Kugel 等NDSS 2025
