[{"status":"public","title":"Poster: Computer Security Researchers' Experiences with Vulnerability Disclosures","year":"2025","author":[{"id":"99000","orcid":"0000-0002-0000-5843","first_name":"Harshini","last_name":"Sri Ramulu","full_name":"Sri Ramulu, Harshini"},{"id":"97843","first_name":"Anna Lena","last_name":"Rotthaler","full_name":"Rotthaler, Anna Lena"},{"full_name":"Rossel, Jost","orcid":"0000-0002-3182-4059","first_name":"Jost","last_name":"Rossel","id":"58331"},{"first_name":"Rachel","last_name":"Gonzalez Rodriguez","full_name":"Gonzalez Rodriguez, Rachel"},{"last_name":"Wermke","first_name":"Dominik","full_name":"Wermke, Dominik"},{"last_name":"Fahl","first_name":"Sascha","full_name":"Fahl, Sascha"},{"full_name":"Kohno, Tadayoshi","last_name":"Kohno","first_name":"Tadayoshi"},{"full_name":"Somorovsky, Juraj","orcid":"0000-0002-3593-7720","last_name":"Somorovsky","first_name":"Juraj","id":"83504"},{"first_name":"Yasemin","last_name":"Acar","full_name":"Acar, Yasemin","id":"94636"}],"conference":{"end_date":"2025-10-17","start_date":"2025-10-13"},"publication_status":"published","date_updated":"2025-12-02T08:54:18Z","main_file_link":[{"open_access":"1","url":"https://dl.acm.org/doi/10.1145/3719027.3760723"}],"_id":"62738","publisher":"ACM","language":[{"iso":"eng"}],"user_id":"58331","doi":"10.1145/3719027.3760723","publication":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","citation":{"bibtex":"@inproceedings{Sri Ramulu_Rotthaler_Rossel_Gonzalez Rodriguez_Wermke_Fahl_Kohno_Somorovsky_Acar_2025, title={Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures}, DOI={<a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>}, booktitle={Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Sri Ramulu, Harshini and Rotthaler, Anna Lena and Rossel, Jost and Gonzalez Rodriguez, Rachel and Wermke, Dominik and Fahl, Sascha and Kohno, Tadayoshi and Somorovsky, Juraj and Acar, Yasemin}, year={2025} }","ama":"Sri Ramulu H, Rotthaler AL, Rossel J, et al. Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures. In: <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>. ACM; 2025. doi:<a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>","mla":"Sri Ramulu, Harshini, et al. “Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures.” <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>, ACM, 2025, doi:<a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>.","short":"H. Sri Ramulu, A.L. Rotthaler, J. Rossel, R. Gonzalez Rodriguez, D. Wermke, S. Fahl, T. Kohno, J. Somorovsky, Y. Acar, in: Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, ACM, 2025.","chicago":"Sri Ramulu, Harshini, Anna Lena Rotthaler, Jost Rossel, Rachel Gonzalez Rodriguez, Dominik Wermke, Sascha Fahl, Tadayoshi Kohno, Juraj Somorovsky, and Yasemin Acar. “Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures.” In <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>. ACM, 2025. <a href=\"https://doi.org/10.1145/3719027.3760723\">https://doi.org/10.1145/3719027.3760723</a>.","ieee":"H. Sri Ramulu <i>et al.</i>, “Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures,” 2025, doi: <a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>.","apa":"Sri Ramulu, H., Rotthaler, A. L., Rossel, J., Gonzalez Rodriguez, R., Wermke, D., Fahl, S., Kohno, T., Somorovsky, J., &#38; Acar, Y. (2025). Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures. <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>. <a href=\"https://doi.org/10.1145/3719027.3760723\">https://doi.org/10.1145/3719027.3760723</a>"},"abstract":[{"lang":"eng","text":"Vulnerability disclosures are necessary to improve the security of our digital ecosystem. However, they can also be challenging for researchers: it may be hard to find out who the affected parties even are, or how to contact them. Researchers may be ignored or face adversity when disclosing vulnerabilities. We investigate researchers' experiences with vulnerability disclosures, extract best practices, and make recommendations for researchers, institutions that employ them, industry, and regulators to enable effective vulnerability disclosures."}],"date_created":"2025-12-02T08:48:00Z","type":"conference","keyword":["software vulnerabilities","vulnerability disclosure","security research"],"oa":"1"},{"ddc":["000"],"user_id":"61579","_id":"5647","has_accepted_license":"1","status":"public","oa":"1","citation":{"short":"G. Schryen, in: 15th Americas Conference on Information Systems, 2009.","chicago":"Schryen, Guido. “Security of Open Source and Closed Source Software: An Empirical Comparison of Published Vulnerabilities.” In <i>15th Americas Conference on Information Systems</i>, 2009.","apa":"Schryen, G. (2009). Security of open source and closed source software: An empirical comparison of published vulnerabilities. In <i>15th Americas Conference on Information Systems</i>.","ieee":"G. Schryen, “Security of open source and closed source software: An empirical comparison of published vulnerabilities,” in <i>15th Americas Conference on Information Systems</i>, 2009.","ama":"Schryen G. Security of open source and closed source software: An empirical comparison of published vulnerabilities. In: <i>15th Americas Conference on Information Systems</i>. ; 2009.","bibtex":"@inproceedings{Schryen_2009, title={Security of open source and closed source software: An empirical comparison of published vulnerabilities}, booktitle={15th Americas Conference on Information Systems}, author={Schryen, Guido}, year={2009} }","mla":"Schryen, Guido. “Security of Open Source and Closed Source Software: An Empirical Comparison of Published Vulnerabilities.” <i>15th Americas Conference on Information Systems</i>, 2009."},"file_date_updated":"2018-12-18T13:16:39Z","language":[{"iso":"eng"}],"date_updated":"2022-01-06T07:02:19Z","author":[{"full_name":"Schryen, Guido","first_name":"Guido","last_name":"Schryen","id":"72850"}],"year":"2009","title":"Security of open source and closed source software: An empirical comparison of published vulnerabilities","department":[{"_id":"277"}],"type":"conference","keyword":["Vulnerabilities","security","open source software","closed source software","empirical comparison"],"date_created":"2018-11-14T14:41:24Z","file":[{"creator":"hsiemes","date_created":"2018-12-18T13:16:39Z","date_updated":"2018-12-18T13:16:39Z","relation":"main_file","access_level":"open_access","file_size":483690,"file_name":"Security of Open Source and Closed Source Software An Empirical - AMCIS Version.pdf","content_type":"application/pdf","file_id":"6317"}],"abstract":[{"text":"Reviewing literature on open source and closed source security reveals that the discussion is often determined by biased attitudes toward one of these development styles. The discussion specifically lacks appropriate metrics, methodology and hard data. This paper contributes to solving this problem by analyzing and comparing published vulnerabilities of eight open source software and nine closed source software packages, all of which are widely deployed. Thereby, it provides an extensive empirical analysis of vulnerabilities in terms of mean time between vulnerability disclosures, the development of disclosure over time, and the severity of vulnerabilities, and allows for validating models provided in the literature. The investigation reveals that (a) the mean time between vulnerability disclosures was lower for open source software in half of the cases, while the other cases show no differences, (b) in contrast to literature assumption, 14 out of 17 software packages showed a significant linear or piecewise linear correlation between time and the number of published vulnerabilities, and (c) regarding the severity of vulnerabilities, no significant differences were found between open source and closed source.","lang":"eng"}],"extern":"1","publication":"15th Americas Conference on Information Systems"}]
