软件漏洞与利用市场的伦理

Ethics of the software vulnerabilities and exploits market

Information Society · 2016
被引 9
ABS 3

中文导读

本文论证了在专有软件中识别漏洞及开发、销售、购买非零日利用在伦理上合理,但在自由/开源软件中仅限极窄情形;并建议民主政府立法激励企业内部漏洞识别与修复。

Abstract

In this article we establish three claims: (1) When the target software is proprietary, in the absence of other overriding ethical considerations, the identification of a vulnerability and the development, sale, and purchase of non-zero-day exploits are ethically justified; (2) when the target software is Free/Libre/Open Source, the buying and selling of vulnerabilities can be ethically justified only in a very narrow situation, while the sale and purchase of non-zero-day exploits is ethically justified absent of any other overriding information; and (3) democratic governments should promote legislation that either incentivizes corporate in-house vulnerability identification and mitigation programs or requires firms to more fully absorb the societal costs of insecure software.

计算机伦理网络安全软件工程商业伦理