Backwards from zero: How the U.S. public evaluates the use of zero-day vulnerabilities in cybersecurity.

Zero-day vulnerabilities are software and hardware flaws that are unknown to computer vendors. As powerful means of carrying out cyber intrusions, such vulnerabilities present a dilemma for governments. Actors that develop or procure such vulnerabilities may retain them for future use; alternatively...

Descripción completa

Detalles Bibliográficos
Publicado en:Contemporary Security Policy Vol. 44; no. 3; pp. 437 - 462
Autores principales: Leal, Marcelo M., Musgrave, Paul
Formato: Artículo
Publicado: Taylor & Francis Ltd Jul2023
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=164355724&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 164355724
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        13523260
        RHJ
      jtl: Contemporary Security Policy
      issn: 13523260
      maglogo: Y
    pubinfo:
      dt: Jul2023
      vid: 44
      iid: 3
      pid: 377
      pub: Taylor & Francis Ltd
    artinfo:
      ui:
        164355724
        10.1080/13523260.2023.2216112
      ppf: 437
      ppct: 25
      formats:
      tig:
        atl: Backwards from zero: How the U.S. public evaluates the use of zero-day vulnerabilities in cybersecurity.
      aug:
        au:
          Leal, Marcelo M.
          Musgrave, Paul
        affil: Department of Political Science and Legal Studies, University of Massachusetts, Amherst, MA, USA
      su:
        Internet security
        Computer security vulnerabilities
        Public opinion
        Dilemma
      sug:
        subj:
          Internet security
          Computer security vulnerabilities
          Public opinion
          Dilemma
      keyword:
        cybersecurity policy
        public opinion
        vulnerabilities equities process
        Zero-day vulnerabilities
      ab: Zero-day vulnerabilities are software and hardware flaws that are unknown to computer vendors. As powerful means of carrying out cyber intrusions, such vulnerabilities present a dilemma for governments. Actors that develop or procure such vulnerabilities may retain them for future use; alternatively, agencies possessing such vulnerabilities may disclose the flaws to affected vendors so they can be patched, thereby denying vulnerabilities not only to adversaries but also themselves. Previous research has explored the ethics and implications of this dilemma, but no study has investigated public opinion regarding zero-day exploits. We present results from a survey experiment testing whether conditions identified as important in the literature influence respondents' support for disclosing or stockpiling zero-day vulnerabilities. Our results show that respondents overwhelmingly support disclosure, a conclusion only weakly affected by the likelihood that an adversary will independently discover the vulnerability. Our findings suggest a gap between public preferences and current U.S. policy.
      pubtype: Academic Journal
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2023
    holdings:
      @attributes:
        islocal: N