Gateway to Think Tanks
来源类型 | Report |
规范类型 | 报告 |
DOI | https://doi.org/10.7249/RR1751 |
来源ID | RR-1751-RC |
Zero Days, Thousands of Nights: The Life and Times of Zero-Day Vulnerabilities and Their Exploits | |
Lillian Ablon; Andy Bogart | |
发表日期 | 2017-03-09 |
出版年 | 2017 |
语种 | 英语 |
结论 | "Alive" Versus "Dead" Is Too Simplistic
Longevity and Discovery by Others
Time and Costs Involved in Developing Zero-Day Exploits
|
摘要 | Zero-day vulnerabilities — software vulnerabilities for which no patch or fix has been publicly released — and their exploits are useful in cyber operations — whether by criminals, militaries, or governments — as well as in defensive and academic settings. ,This report provides findings from real-world zero-day vulnerability and exploit data that could augment conventional proxy examples and expert opinion, complement current efforts to create a framework for deciding whether to disclose or retain a cache of zero-day vulnerabilities and exploits, inform ongoing policy debates regarding stockpiling and vulnerability disclosure, and add extra context for those examining the implications and resulting liability of attacks and data breaches for U.S. consumers, companies, insurers, and for the civil justice system broadly. ,The authors provide insights about the zero-day vulnerability research and exploit development industry; give information on what proportion of zero-day vulnerabilities are alive (undisclosed), dead (known), or somewhere in between; and establish some baseline metrics regarding the average lifespan of zero-day vulnerabilities, the likelihood of another party discovering a vulnerability within a given time period, and the time and costs involved in developing an exploit for a zero-day vulnerability. |
目录 |
|
主题 | Cyber Warfare ; Cybercrime ; Cybersecurity ; The Internet ; Science ; Technology ; and Innovation Policy |
URL | https://www.rand.org/pubs/research_reports/RR1751.html |
来源智库 | RAND Corporation (United States) |
引用统计 | |
资源类型 | 智库出版物 |
条目标识符 | http://119.78.100.153/handle/2XGU8XDN/523251 |
推荐引用方式 GB/T 7714 | Lillian Ablon,Andy Bogart. Zero Days, Thousands of Nights: The Life and Times of Zero-Day Vulnerabilities and Their Exploits. 2017. |
条目包含的文件 | ||||||
文件名称/大小 | 资源类型 | 版本类型 | 开放类型 | 使用许可 | ||
RAND_RR1751.pdf(1686KB) | 智库出版物 | 限制开放 | CC BY-NC-SA | 浏览 | ||
x1543588899137.jpg.p(3KB) | 智库出版物 | 限制开放 | CC BY-NC-SA | 浏览 |
个性服务 |
推荐该条目 |
保存到收藏夹 |
导出为Endnote文件 |
谷歌学术 |
谷歌学术中相似的文章 |
[Lillian Ablon]的文章 |
[Andy Bogart]的文章 |
百度学术 |
百度学术中相似的文章 |
[Lillian Ablon]的文章 |
[Andy Bogart]的文章 |
必应学术 |
必应学术中相似的文章 |
[Lillian Ablon]的文章 |
[Andy Bogart]的文章 |
相关权益政策 |
暂无数据 |
收藏/分享 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。