计算机系统及各类网络应用中的安全漏洞是网络威胁产生的主要原因,发现安全漏洞后的披露方式会对个人隐私、企业利益甚至国家安全产生深远影响。随着互联网与制造业深度融合发展,工业控制系统漏洞带来的安全风险也日益严重。因此,世界各国对漏洞披露问题高度重视,相继出台一系列法规政策对漏洞披露细节进行约束和规范,同时积极建设漏洞披露平台,面向社会披露漏洞。本文研究了国内外的漏洞披露政策,分析了各漏洞披露平台的特点,并针对我国的漏洞披露政策提出了建议。
<<Security Holes of computer system and web application are main causes of network threat. The disclosure of security holes can have a profound impact on national security,corporate interests and personal privacy and with the deep integration of the Internet and manufacturing industry,the security risks brought by the industrial control system loopholes are also increasingly serious. Nations of the world attach great importance to this. A series of regulatory policies have been introduced to explain the details of the disclosure and large number of vulnerability disclosure platforms are constructed. This paper studies the security holes disclosure policy and analyze the characteristics of each vulnerability disclosure platform. At the same time,it also puts forward some suggestions for the disclosure policy of China.
<<Keywords: | Vulnerability DatabaseSecurity Holes DisclosureVulnerability Sharing PlatformDisclosure Policy |