Katie Moussouris: Vulnerability Disclosure and Security Workforce Development

被引:1
|
作者
Blakley, Bob
Cranor, Lorrie
机构
关键词
Compendex;
D O I
10.1109/MSEC.2022.3222043
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Bob Blakley: Welcome everyone to episode four of the IEEE Over the Rainbow podcast. I'm Bob Blakley, and I'm here with my cohost Lorrie Cranor. Our guest today is Katie Moussouris. Katie is the CEO of Luta Security, a company that helps organizations design and operate bug bounty and vulnerability reporting programs. Katie has a background in molecular biology and worked on the Human Genome Project at MIT. While she was at MIT, she became a system administrator, which led her in time to a career in information security. She was a penetration tester for @Stake; after Symantec acquired @Stake, she established the Symantec Vulnerability Research Program. From Symantec, she moved to Microsoft, where she created Microsoft's Vulnerability Research Program in 2008; in 2014, Katie moved to HackerOne, where she served as chief policy officer. In 2016, she left HackerOne to found Luta Security. Katie has done both academic and policy work in vulnerability research and disclosure; she was a driving force in ensuring that the 2013 revision of the Wassenaar Arrangement would exempt software tools used for defense from export controls, and she served as editor of both major ISO/IEC vulnerability standards (ISO/IEC 29147 and ISO/IEC 30111).
引用
收藏
页码:11 / 18
页数:8
相关论文
共 50 条
  • [1] Silver Bullet Talks with Katie Moussouris
    McGraw, Gary
    IEEE SECURITY & PRIVACY, 2015, 13 (04) : 7 - 9
  • [2] A study on Web security incidents in China by analyzing vulnerability disclosure platforms
    Huang, Cheng
    Liu, JiaYong
    Fang, Yong
    Zuo, Zheng
    COMPUTERS & SECURITY, 2016, 58 : 47 - 62
  • [3] Does information security attack frequency increase with vulnerability disclosure? An empirical analysis
    Ashish Arora
    Anand Nandkumar
    Rahul Telang
    Information Systems Frontiers, 2006, 8 : 350 - 362
  • [4] Does information security attack frequency increase with vulnerability disclosure? An empirical analysis
    Arora, Ashish
    Nandkumar, Anand
    Telang, Rahul
    INFORMATION SYSTEMS FRONTIERS, 2006, 8 (05) : 350 - 362
  • [5] Responsible Vulnerability Disclosure in Cryptocurrencies
    Boehme, Rainer
    Eckey, Lisa
    Moore, Tyler
    Narula, Neha
    Ruffing, Tim
    Zohar, Aviv
    COMMUNICATIONS OF THE ACM, 2020, 63 (10) : 62 - 71
  • [6] Vulnerability Disclosure Considered Stressful
    Moura, Giovane C. M.
    Heidemann, John
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2023, 53 (02) : 3 - 10
  • [7] Anticipatory Ethics for Vulnerability Disclosure
    Huskaj, Gazmend
    Wilson, Richard L.
    PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2020), 2020, : 254 - 261
  • [8] New hurdles for vulnerability disclosure
    McKinney, Dave
    IEEE SECURITY & PRIVACY, 2008, 6 (02) : 76 - 78
  • [9] Economics of software vulnerability disclosure
    Arora, A
    Telang, R
    IEEE SECURITY & PRIVACY, 2005, 3 (01) : 20 - 25
  • [10] Efficiency of vulnerability disclosure mechanisms to disseminate vulnerability knowledge
    Cavusoglu, Hasan
    Cavusoglu, Huseyin
    Raghunathan, Srinivasan
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2007, 33 (03) : 171 - 185