Item Details
Skip Navigation Links
   ActiveUsers:1427Hits:19704594Skip Navigation Links
Show My Basket
Contact Us
IDSA Web Site
Ask Us
Today's News
HelpExpand Help
Advanced search

In Basket
  Journal Article   Journal Article
 

ID192522
Title ProperBackwards from zero
Other Title InformationHow the U.S. public evaluates the use of zero-day vulnerabilities in cybersecurity
LanguageENG
AuthorMusgrave, Paul ;  Leal, Marcelo M
Summary / Abstract (Note)Zero-day vulnerabilities are software and hardware flaws that are unknown to computer vendors. As powerful means of carrying out cyber intrusions, such vulnerabilities present a dilemma for governments. Actors that develop or procure such vulnerabilities may retain them for future use; alternatively, agencies possessing such vulnerabilities may disclose the flaws to affected vendors so they can be patched, thereby denying vulnerabilities not only to adversaries but also themselves. Previous research has explored the ethics and implications of this dilemma, but no study has investigated public opinion regarding zero-day exploits. We present results from a survey experiment testing whether conditions identified as important in the literature influence respondents’ support for disclosing or stockpiling zero-day vulnerabilities. Our results show that respondents overwhelmingly support disclosure, a conclusion only weakly affected by the likelihood that an adversary will independently discover the vulnerability. Our findings suggest a gap between public preferences and current U.S. policy.
`In' analytical NoteContemporary Security Policy Vol. 44, No.3; Jul 2023: p.437-461
Journal SourceContemporary Security Policy Vol: 44 No 3
Key WordsPublic Opinion ;  Cybersecurity Policy ;  Zero-day vulnerabilities ;  Vulnerabilities equities process


 
 
Media / Other Links  Full Text