Skip to main navigation Skip to search Skip to main content

Competition and patching of security vulnerabilities: An empirical analysis

  • Duke University
  • Georgia Institute of Technology
  • Carnegie Mellon University

Research output: Contribution to journalArticlepeer-review

38 Scopus citations

Abstract

We empirically estimate the effect of competition on vendor patching of software defects by exploiting variation in number of vendors that share a common flaw or common vulnerabilities. We distinguish between two effects: the direct competition effect when vendors in the same market share a vulnerability, and the indirect effect, which operates through non-rivals that operate in different markets but nonetheless share the same vulnerability. Using time to patch as our measure of quality, we find empirical support for both direct and indirect effects of competition. Our results show that ex-post product quality in software markets is not only conditioned by rivals that operate in the same product market, but by also non-rivals that share the same common flaw.

Original languageEnglish
Pages (from-to)164-177
Number of pages14
JournalInformation Economics and Policy
Volume22
Issue number2
DOIs
StatePublished - May 2010

Keywords

  • Competition
  • Information security
  • Software quality
  • Vulnerabilities

Fingerprint

Dive into the research topics of 'Competition and patching of security vulnerabilities: An empirical analysis'. Together they form a unique fingerprint.

Cite this