Journal of Information Security Research ›› 2021, Vol. 7 ›› Issue (3): 215-224.

Previous Articles     Next Articles

Research on International Disclosure Policy of Security Vulnerabilities

  

  • Received:2021-03-09 Online:2021-03-05 Published:2021-03-17

安全漏洞国际披露政策研究

时翌飞1,冯景瑜1,黄鹤翔2,曹旭栋3,王鹤4,张玉清5   

  1. 1. 西安邮电大学
    2. 西安电子科技大学/中国科学院大学 国家计算机网络入侵防范中心
    3. 中国科学院大学 国家计算机网络入侵防范中心
    4. 西安电子科技大学
    5. 中国科学院大学
  • 通讯作者: 时翌飞
  • 作者简介:时翌飞(1996-),男,陕西西安,硕士,网络安全; syf19961002@outlook.com 冯景瑜(1984-),男,甘肃陇南,副教授,博士,物联网安全与网络攻防;fengjy@xupt.edu.cn 黄鹤翔(1997-),男,河南洛阳,硕士,网络安全;huanghx@nipc.org.cn 曹旭栋(1997-),男,陕西渭南,硕士,网络安全;caoxd@nipc.org.cn 王 鹤(1987-),女,河南安阳,副教授,博士,网络安全;hewang@xidian.edu.cn *张玉清(1966-),男,陕西宝鸡,教授/博士生导师,网络与系统安全。zhangyq@nipc.org.cn

Abstract: With the increasing complexity of information systems and computer networks, the number of security vulnerabilities has grown rapidly. Active disclosure of security vulnerabilities can effectively reduce the cost of security vulnerabilities information collection, help relevant organizations to be aware of security threats in a timely manner, and at the same time solve the problem of information islands through mutual exchanges and cooperation between organizations and even countries, and improve the ability to respond to security threats. At present, the disclosure of security vulnerabilities has become an important means to mitigate potential security threats, reduce risk exposure, and help organizations actively repair security vulnerabilities. First, it introduces the concept and mainstream norms of cybersecurity vulnerability disclosure policies. Second, it investigates and compares the current international security vulnerability disclosure policies of various countries, and then focuses on the analysis of the US Vulnerabilities Equities Policy. Analyzed the relationship between various organizations involved in the disclosure of security vulnerabilities, summarized the current implementation status and challenges of the security vulnerability disclosure policy, and finally put forward some suggestions for establishing a standardized security vulnerability disclosure policy in my country.

Key words: security vulnerability, vulnerability disclosure, coordination vulnerability disclosure, national policy, security vulnerabilities equities policy

摘要: 随着信息系统和计算机网络复杂性的提升,安全漏洞的数量增长迅速。通过积极的安全漏洞披露,可有效降低安全漏洞信息搜集成本,帮助有关组织及时知晓安全威胁,同时通过各组织乃至国家间相互交流合作解决信息孤岛问题,提升应对安全威胁的能力。目前安全漏洞披露已成为缓解潜在安全威胁、减小风险暴露、帮助组织积极修补安全漏洞的重要手段。首先介绍了网络安全漏洞披露政策的概念和主流规范,其次,调研和对比了目前国际范围内各国的安全漏洞披露政策,接着重点剖析了美国安全漏洞公平裁决程序。分析了安全漏洞披露中涉及到的各组织机构间关系,总结了目前安全漏洞披露政策的实施状态和面临的挑战,最后为我国建立规范的安全漏洞披露政策提出一些建议。

关键词: 安全漏洞, 漏洞披露, 协同披露, 国家政策, 安全漏洞公平裁决