Showing cs.CRShow all
3 papers · 1 filter
cs.CR2026
Merchants of Vulnerabilities: How Bug Bounty Programs Benefit Software Vendors
Esther Gal-Or, Muhammad Zia Hydari, Rahul Telang
We study how bug bounty programs (BBPs) shape software vendors' security and release choices. We develop a game-theoretic model in which a vendor chooses release timing and severit…
cs.CR2026
Breaking Bad Email Habits: Bounding the Impact of Simulated Phishing Campaigns
Muhammad Zia Hydari, Idris Adjerid, Yingda Lu +1
Simulated phishing campaigns are widely deployed, yet the behavioral data they produce is endogenous: because training is triggered by clicking, the employees receiving interventio…
cs.CR2024
Sound and Fury, Signifying Nothing? Impact of Data Breach Disclosure Laws
Muhammad Zia Hydari, Yangfan Liang, Rahul Telang
Data breach disclosure (DBD) is presumed to improve firms' cybersecurity practices by inducing fear of subsequent revenue loss. This revenue loss, the theory goes, will occur if cu…