Do They Get With the Program? Measuring Mitigation in a Solicited Vulnerability Notification Program
Yana Angelova, Carlos Gañán, Annebel Smit, Rolf van Wegberg, Michel van Eeten
摘要
Attackers rapidly scan for newly-disclosed vulnerabilities across enterprise networks. In response, defenders have been running similar scans in order to notify the affected enterprise about their exposed attack surface as soon as possible. Such initiatives are becoming more institutionalized, e.g., under the EU's NIS2 directive and CISA's Ransomware Vulnerability Warning Pilot. Research on the effectiveness of vulnerability notifications has found disappointing results, where only a minor fraction of issues were fixed. This was blamed on problems in asset attribution, low trust in the sender, reachability issues, and lacking incentives of the recipient to act. A potential solution to all these problems would be a notification program where companies volunteer to sign up, register their assets, and ensure the right contact details. How much better could such a program perform? We provide the first empirical evaluation of a solicited notification program through a collaboration with a governmental Computer Security Incident Response Team (CSIRT) that offers security notifications to enterprises. We first conduct interviews with nearly half of all participating companies (n = 21) to understand why they signed up and how they act on the notifications. Next, we quantitatively study the remediation effectiveness of the program via survival analysis. We find that 27% of the security issues being resolved within one day of notification, 40% within one week, and 49% within one month. Over the entire three years of the program, the remediation rate is 75%. These findings already show higher remediation effectiveness compared to previous unsolicited experiments. This suggests that solicited notification programs can overcome challenges of reachability, trust, and motivation. We reflect on the limitations of these findings and their implications for the future.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper6
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- Didn't You Hear Me? - Towards More Successful Web Vulnerability NotificationsBen Stock, Giancarlo Pellegrino, Frank Li, Michael Backes 等NDSS 2018 · 被引用 86 次
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten 等S&P 2022 · 被引用 41 次
- Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and SupportMax Maass, Alina Stöver, Henning Pridöhl, Sebastian Bretthauer 等USENIX Security 2021 · 被引用 35 次
- Deployment of Source Address Validation by Network Operators: A Randomized Control TrialQasim Lone, Alisa Frik, Matthew Luckie, Maciej Korczynski 等S&P 2022 · 被引用 16 次
相关 Paper
- Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability NotificationsGiada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo PellegrinoS&P 2026
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns 等USENIX Security 2016 · 被引用 130 次
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 被引用 4 次
- "Tell Them They Are a Responsible Entity, Not a Customer": Understanding Practitioner Challenges in Sector CSIRTsAksel Ethembabaoglu, Natalia I. Kadenko, Yana Angelova, Yury Zhauniarovich 等CHI 2026 · 被引用 1 次
- Speedrunning the Maze: Meeting Regulatory Patching Deadlines in a Large Enterprise EnvironmentGerbrand ten Napel, Michel van Eeten, Simon ParkinS&P 2025
