
<mods xmlns="http://www.loc.gov/mods/v3" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-4.xsd">
    
    <titleInfo>
        <title>Ethics in Security Vulnerability Research</title>
    </titleInfo>
    <name type="personal">
        <namePart type="family">Matwyshyn</namePart>
        <namePart type="given">Andrea M.</namePart>
        <role>
            <roleTerm type="text">author</roleTerm>
        </role>
    </name>
    <name type="personal" ID="ac2024">
        <namePart type="family">Cui</namePart>
        <namePart type="given">Ang</namePart>
        <role>
            <roleTerm type="text">author</roleTerm>
        </role>
        <affiliation>Columbia University. Computer Science</affiliation>
    </name>
    <name type="personal" ID="ak2052">
        <namePart type="family">Keromytis</namePart>
        <namePart type="given">Angelos D.</namePart>
        <role>
            <roleTerm type="text">author</roleTerm>
        </role>
        <affiliation>Columbia University. Computer Science</affiliation>
    </name>
    <name type="personal" ID="sjs11">
        <namePart type="family">Stolfo</namePart>
        <namePart type="given">Salvatore</namePart>
        <role>
            <roleTerm type="text">author</roleTerm>
        </role>
        <affiliation>Columbia University. Computer Science</affiliation>
    </name>
    <name type="corporate">
        <namePart>Columbia University. Computer Science</namePart>
        <role>
            <roleTerm type="text">originator</roleTerm>
        </role>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre>Articles</genre>
    
    <originInfo>
        <dateIssued encoding="w3cdtf" keyDate="yes">2010</dateIssued>
    </originInfo>
    
    <language>
        <languageTerm type="text">English</languageTerm>
    </language>
    <abstract>Debate has arisen in the scholarly community, as well as among policymakers and business entities, regarding the role of vulnerability researchers and security practitioners as sentinels of information security adequacy. The exact definition of vulnerability research and who counts as a &quot;vulnerability researcher&quot; is a subject of debate in the academic and business communities. For purposes of this article, we presume that vulnerability researchers are driven by a desire to prevent information security harms and engage in responsible disclosure upon discovery of a security vulnerability. Yet provided that these researchers and practitioners do not themselves engage in conduct that causes harm, their conduct doesn&apos;t necessarily run afoul of ethical and legal considerations. We advocate crafting a code of conduct for vulnerability researchers and practitioners, including the implementation of procedural safeguards to ensure minimization of harm.</abstract>
    <subject>
        <topic>Computer science</topic>
    </subject>
    <relatedItem type="host">
        <titleInfo>
            <title>IEEE Security &amp; Privacy</title>
        </titleInfo>
        <part>
            <detail type="volume">
                <number>8</number>
            </detail>
            <detail type="issue">
                <number>2</number>
            </detail>
            <extent unit="page">
                <start>67</start>
                <end>72</end>
            </extent>
            <date>2010</date>
        </part>
        <identifier type="doi">http://dx.doi.org/10.1109/MSP.2010.67</identifier>
    </relatedItem>
    <identifier type="hdl">http://hdl.handle.net/10022/AC:P:10581</identifier>
    
    <location>
        <physicalLocation authority="marcorg">NNC</physicalLocation>
    </location>
    
    <recordInfo>
        <recordContentSource authority="marcorg">NNC</recordContentSource>
        <recordCreationDate encoding="w3cdtf">2011-06-23 15:09:29 -0400</recordCreationDate>
        <recordChangeDate encoding="w3cdtf">2012-12-29 00:27:28 -0500</recordChangeDate>
        <recordIdentifier>4530</recordIdentifier>
        <languageOfCataloging>
            <languageTerm authority="iso639-2b">eng</languageTerm>
        </languageOfCataloging>
    </recordInfo>
    
</mods>
