看到什么,说什么?协调加拿大基础设施安全漏洞的披露

Yuan Stevens, S. Tran, Ryan Atkinson
{"title":"看到什么,说什么?协调加拿大基础设施安全漏洞的披露","authors":"Yuan Stevens, S. Tran, Ryan Atkinson","doi":"10.1109/istas52410.2021.9629214","DOIUrl":null,"url":null,"abstract":"Ill-intentioned actors are rapidly developing the means to exploit vulnerabilities in the software and infrastructure of governments around the world. Numerous jurisdictions now facilitate coordinated vulnerability disclosure for such public systems, providing good faith security researchers a predictable and cooperative process to disclose security vulnerabilities for patching before they are exploited. This study identifies that Canada may be falling behind its global peers by failing to implement such reporting procedures. It indicates the need for a straightforward vulnerability disclosure and remediation path involving federal systems, linked to improved legal frameworks and government policies for security vulnerability discovery and disclosure in Canada and beyond.","PeriodicalId":314239,"journal":{"name":"2021 IEEE International Symposium on Technology and Society (ISTAS)","volume":"76 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"See something, say something? Coordinating the disclosure of security vulnerabilities in Canada’s infrastructure\",\"authors\":\"Yuan Stevens, S. Tran, Ryan Atkinson\",\"doi\":\"10.1109/istas52410.2021.9629214\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Ill-intentioned actors are rapidly developing the means to exploit vulnerabilities in the software and infrastructure of governments around the world. Numerous jurisdictions now facilitate coordinated vulnerability disclosure for such public systems, providing good faith security researchers a predictable and cooperative process to disclose security vulnerabilities for patching before they are exploited. This study identifies that Canada may be falling behind its global peers by failing to implement such reporting procedures. It indicates the need for a straightforward vulnerability disclosure and remediation path involving federal systems, linked to improved legal frameworks and government policies for security vulnerability discovery and disclosure in Canada and beyond.\",\"PeriodicalId\":314239,\"journal\":{\"name\":\"2021 IEEE International Symposium on Technology and Society (ISTAS)\",\"volume\":\"76 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-10-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE International Symposium on Technology and Society (ISTAS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/istas52410.2021.9629214\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Symposium on Technology and Society (ISTAS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/istas52410.2021.9629214","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

不怀好意的行为者正在迅速开发利用世界各地政府软件和基础设施漏洞的手段。现在,许多司法管辖区都在促进此类公共系统的协调漏洞披露,为诚信的安全研究人员提供一个可预测的合作过程,以便在漏洞被利用之前披露安全漏洞并进行修补。这项研究表明,加拿大可能因未能实施此类报告程序而落后于全球同行。它表明需要一个直接的漏洞披露和补救路径,涉及联邦系统,并与改进的法律框架和政府政策联系起来,以便在加拿大和其他地区发现和披露安全漏洞。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
See something, say something? Coordinating the disclosure of security vulnerabilities in Canada’s infrastructure
Ill-intentioned actors are rapidly developing the means to exploit vulnerabilities in the software and infrastructure of governments around the world. Numerous jurisdictions now facilitate coordinated vulnerability disclosure for such public systems, providing good faith security researchers a predictable and cooperative process to disclose security vulnerabilities for patching before they are exploited. This study identifies that Canada may be falling behind its global peers by failing to implement such reporting procedures. It indicates the need for a straightforward vulnerability disclosure and remediation path involving federal systems, linked to improved legal frameworks and government policies for security vulnerability discovery and disclosure in Canada and beyond.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信