Case studies on full disclosure vs. "security through obscurity"

From: Doctor Arcane (docarcane@altavista.net)
Date: 04/30/02


From: docarcane@altavista.net (Doctor Arcane)
Date: 29 Apr 2002 16:31:26 -0700

I'm doing a research paper on the affects of IP laws on computer
security. For a portion of my paper I need to show the merits of full
disclosure. Many in the security community come out in favor of it,
but for my paper I need peer reviewed journal articles or conference
proceedings.

So far I've found "Windows of Vulnerability" and "A Trend Analysis of
Exploitations". A lot of the focus here is on statistic analysis
involving automation of the exploit.

There seems to be a dearth of scholarly info on the subject and an
endless supply of ranting.

Any recommendations would be much appreciated!

-arcane



Relevant Pages