{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T12:20:21Z","timestamp":1782994821332,"version":"3.54.5"},"publisher-location":"Berlin, Heidelberg","reference-count":33,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540346401","type":"print"},{"value":"9783540346425","type":"electronic"}],"license":[{"start":{"date-parts":[[2006,1,1]],"date-time":"2006-01-01T00:00:00Z","timestamp":1136073600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006]]},"DOI":"10.1007\/11766155_21","type":"book-chapter","created":{"date-parts":[[2006,5,31]],"date-time":"2006-05-31T15:35:00Z","timestamp":1149089700000},"page":"298-311","source":"Crossref","is-referenced-by-count":43,"title":["A Comparison of Market Approaches to Software Vulnerability Disclosure"],"prefix":"10.1007","author":[{"given":"Rainer","family":"B\u00f6hme","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"21_CR1","doi-asserted-by":"crossref","unstructured":"Arora, A., Telang, R., Xu, H.: Optimal policy for software vulnerability disclosure. In: Workshop on the Economics of Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004), http:\/\/www.dtc.umn.edu\/weis2004\/xu.pdf","DOI":"10.2139\/ssrn.669023"},{"key":"21_CR2","doi-asserted-by":"crossref","unstructured":"Arora, A., Krishnan, R., Telang, R., Yang, Y.: An empirical analysis of vendor response to software vulnerability disclosure. In: Workshop on Information Systems and Economics (WISE), University of California, Irvine, CA (2005)","DOI":"10.2139\/ssrn.786128"},{"key":"21_CR3","unstructured":"Nizovtsev, D., Thursby, M.: Economic incentives to disclose software vulnerabilities. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge, MA (2005), http:\/\/infosecon.net\/workshop\/pdf\/20.pdf"},{"key":"21_CR4","unstructured":"Rescorla, E.: Is finding security holes a good idea? In: Workshop of Economics and Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004), http:\/\/www.dtc.umn.edu\/weis2004\/rescorla.pdf"},{"key":"21_CR5","unstructured":"Anderson, R.J.: Why information security is hard \u2013 An economic perspective (2001), http:\/\/www.cl.cam.ac.uk\/~rja14\/econsec.html"},{"key":"21_CR6","doi-asserted-by":"publisher","first-page":"488","DOI":"10.2307\/1879431","volume":"84","author":"G.A. Akerlof","year":"1970","unstructured":"Akerlof, G.A.: The market for \u2018lemons\u2019: Quality, uncertainty and the market mechanism. Quarterly Journal of Economics\u00a084, 488\u2013500 (1970)","journal-title":"Quarterly Journal of Economics"},{"key":"21_CR7","volume-title":"Information Rules. A Strategic Guide to the Network Economy","author":"C. Shapiro","year":"1998","unstructured":"Shapiro, C., Varian, H.R.: Information Rules. A Strategic Guide to the Network Economy. Harvard Business School Press, Boston (1998)"},{"key":"21_CR8","doi-asserted-by":"publisher","first-page":"1243","DOI":"10.1126\/science.162.3859.1243","volume":"162","author":"G. Hardin","year":"1968","unstructured":"Hardin, G.: The tragedy of the commons. Science\u00a0162, 1243\u20131248 (1968)","journal-title":"Science"},{"key":"21_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"319","DOI":"10.1007\/11555827_19","volume-title":"Computer Security \u2013 ESORICS 2005","author":"F.C. Freiling","year":"2005","unstructured":"Freiling, F.C., Holz, T., Wicherski, G.: Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks. In: de Capitani di Vimercati, S., Syverson, P.F., Gollmann, D., et al. (eds.) ESORICS 2005. LNCS, vol.\u00a03679, pp. 319\u2013335. Springer, Heidelberg (2005)"},{"key":"21_CR10","unstructured":"Varian, H.R.: System reliability and free riding. In: Workshop on Economics and Information Security (WEIS), Berkeley, CA (2002), http:\/\/www.sims.berkeley.edu\/resources\/affiliates\/workshops\/econsecurity\/"},{"key":"21_CR11","unstructured":"Varian, H.R.: Managing online security risks. New York Times (2000), http:\/\/www.nytimes.com\/library\/financial\/columns\/060100econ-scene.html"},{"key":"21_CR12","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1109\/MSECP.2003.1176999","volume":"1","author":"D.J. Ryan","year":"2003","unstructured":"Ryan, D.J., Heckmann, C.: Two views on security software liability. IEEE Security & Privacy\u00a01, 70\u201375 (2003)","journal-title":"IEEE Security & Privacy"},{"key":"21_CR13","unstructured":"Schechter, S.E.: Computer Security Strength & Risk: A Quantitative Approach. PhD thesis, Harvard University, Cambridge, MA (2004)"},{"key":"21_CR14","unstructured":"Camp, J.L., Wolfram, C.: Pricing security. In: Proc. of the CERT Information Survivability Workshop, Boston, MA, pp. 31\u201339 (2000), http:\/\/www.cert.org\/research\/isw\/isw2000\/papers\/54.pdf"},{"key":"21_CR15","volume-title":"An Economic Theory of Democracy","author":"A. Downs","year":"1957","unstructured":"Downs, A.: An Economic Theory of Democracy. Harper and Brothers, New York (1957)"},{"key":"21_CR16","volume-title":"The Citizen and the State: Essays on Regulation.","author":"G.J. Stigler","year":"1975","unstructured":"Stigler, G.J.: The Citizen and the State: Essays on Regulation. University Press, Chicago (1975)"},{"key":"21_CR17","unstructured":"Ozment, A.: Bug auctions: Vulnerability markets reconsidered. In: Workshop of Economics and Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004), http:\/\/www.dtc.umn.edu\/weis2004\/ozment.pdf"},{"key":"21_CR18","unstructured":"B\u00f6hme, R.: Vulnerability markets \u2013 What is the economic value of a zero-day exploit? In: Proc.\u00a0of 22C3: Private Investigations, Berlin, Germany (2005), https:\/\/events.ccc.de\/congress\/2005\/fahrplan\/attachments\/542-Boehme2005_22C3_VulnerabilityMarkets.pdf"},{"key":"21_CR19","doi-asserted-by":"crossref","unstructured":"Kannan, K., Telang, R.: An economic analysis of markets for software vulnerabilities. In: Workshop of Economics and Information Security (WEIS), University of Minnesota, Minneapolis, MN (2004), http:\/\/www.dtc.umn.edu\/weis2004\/kannan-telang.pdf","DOI":"10.1109\/HICSS.2004.1265430"},{"key":"21_CR20","unstructured":"Matsuura, K.: Security tokens and their derivatives. Technical report, Centre for Communications Systems Research (CCSR), University of Cambridge, UK (2001)"},{"key":"21_CR21","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1145\/636772.636774","volume":"46","author":"L.A. Gordon","year":"2003","unstructured":"Gordon, L.A., Loeb, M.P., Sohail, T.: A framework for using insurance for cyber-risk management. Communications of the ACM\u00a046, 81\u201385 (2003)","journal-title":"Communications of the ACM"},{"key":"21_CR22","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"J.P. Kesan","year":"2005","unstructured":"Kesan, J.P., Majuca, R.P., Yurcik, W.J.: The economic case for cyberinsurance. In: Workshop on the Economics of Information Security (WEIS). Harvard University, Cambridge (2005), http:\/\/infosecon.net\/workshop\/pdf\/42.pdf"},{"key":"21_CR23","doi-asserted-by":"crossref","unstructured":"Schneier, B.: Hacking the business climate for network security. IEEE Computer, 87\u201389 (2004)","DOI":"10.1109\/MC.2004.1297316"},{"key":"21_CR24","unstructured":"Yurcik, W., Doss, D.: Cyberinsurance: A market solution to the internet security market failure. In: Workshop on Economics and Information Security (WEIS). Berkeley, CA (2002), http:\/\/www.sims.berkeley.edu\/resources\/affiliates\/workshops\/econsecurity\/"},{"key":"21_CR25","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"R. B\u00f6hme","year":"2005","unstructured":"B\u00f6hme, R.: Cyberinsurance revisited. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge (2005), http:\/\/infosecon.net\/workshop\/pdf\/15.pdf"},{"key":"21_CR26","volume-title":"Proc. of the 35th Hawaii International Conference on System Sciences","author":"M. Ettredge","year":"2002","unstructured":"Ettredge, M., Richardson, V.J.: Assessing the risk in e-commerce. In: Sprague, R.H. (ed.) Proc. of the 35th Hawaii International Conference on System Sciences, Los Alamitos, CA. IEEE Press, Los Alamitos (2002)"},{"key":"21_CR27","doi-asserted-by":"publisher","first-page":"431","DOI":"10.3233\/JCS-2003-11308","volume":"11","author":"K. Campbell","year":"2003","unstructured":"Campbell, K., Gordon, L.A., Loeb, M.P., Zhou, L.: The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security\u00a011, 431\u2013448 (2003)","journal-title":"Journal of Computer Security"},{"key":"21_CR28","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1080\/10864415.2004.11044320","volume":"9","author":"H. Cavusoglu","year":"2004","unstructured":"Cavusoglu, H., Mishra, B., Raghunathan, S.: The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers. International Journal of Electronic Commerce\u00a09, 69\u2013104 (2004)","journal-title":"International Journal of Electronic Commerce"},{"key":"21_CR29","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"R. Telang","year":"2005","unstructured":"Telang, R., Wattal, S.: Impact of software vulnerability announcements on the market value of software vendors \u2013 An empirical investigation. In: Workshop on the Economics of Information Security (WEIS). Harvard University, Cambridge (2005), http:\/\/infosecon.net\/workshop\/pdf\/telang_wattal.pdf"},{"key":"21_CR30","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9780511803475","volume-title":"Choices, Values, and Frames","author":"D. Kahneman","year":"2000","unstructured":"Kahneman, D., Tversky, A.: Choices, Values, and Frames. Cambridge University Press, Cambridge (2000)"},{"key":"21_CR31","unstructured":"Geer, D., et al.: CyberInsecurity \u2013 The cost of monopoly (2003), http:\/\/www.ccianet.org\/papers\/cyberinsecurity.pdf"},{"key":"21_CR32","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"P.Y. Chen","year":"2005","unstructured":"Chen, P.Y., Kataria, G., Krishnan, R.: Software diversity for information security. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge (2005), http:\/\/infosecon.net\/workshop\/pdf\/47.pdf"},{"key":"21_CR33","volume-title":"Workshop on the Economics of Information Security (WEIS)","author":"A. Ozment","year":"2005","unstructured":"Ozment, A.: The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting. In: Workshop on the Economics of Information Security (WEIS), Harvard University, Cambridge (2005), http:\/\/infosecon.net\/workshop\/pdf\/10.pdf"}],"container-title":["Lecture Notes in Computer Science","Emerging Trends in Information and Communication Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11766155_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,7]],"date-time":"2023-05-07T11:40:37Z","timestamp":1683459637000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11766155_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006]]},"ISBN":["9783540346401","9783540346425"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/11766155_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2006]]}}}