MétaCan
Menu
Back to cohort
Record W3207066014

See Something, Say Something: Coordinating the Disclosure of Security Vulnerabilities in Canada

2021· article· en· W3207066014 on OpenAlexaffabout
Yuan Stevens, Stephanie Tran, Ryan Atkinson, Sam Andrey

Bibliographic record

VenueSSRN Electronic Journal · 2021
Typearticle
Languageen
FieldComputer Science
TopicCybercrime and Law Enforcement Studies
Canadian institutionsToronto Metropolitan University
Fundersnot available
KeywordsVulnerability (computing)Full disclosureBusinessContext (archaeology)ExploitGovernment (linguistics)HarmComputer securityLegislationInternet privacyPublic relationsPolitical scienceLawComputer science
DOInot available

Abstract

fetched live from OpenAlex

Ill-intentioned actors are rapidly developing the technological means to exploit vulnerabilities in the web assets, software, hardware, and networked infrastructure of governments around the world. Numerous jurisdictions have adopted the policy approach of facilitating coordinated vulnerability disclosure (CVD) as one means to better secure the public sector’s systems, through which external security researchers are provided a predictable and cooperative process to disclose security flaws for patching before they are exploited. Canada is falling behind its peers and allies in adopting such an approach. A global scan of vulnerability disclosure policy approaches indicates that 60 percent of G20 member countries provide distinct and clear disclosure processes for vulnerabilities involving government systems, with many providing clarity regarding the disclosure process and expectations for security researchers regarding communication and acceptable activity. The Netherlands and the US are particularly leading the way when it comes to providing comprehensive policy and pragmatic solutions for external vulnerability disclosure, acting as a learning model for Canada. Both countries have also begun to provide explicit legal clarification regarding acceptable security research activity, particularly in the context of coordinated vulnerability disclosure. In Canada, there exists no legal or policy framework regarding security research and vulnerability disclosure done in good faith; that is, done with the intent and in such a way to repair the vulnerability while causing minimal harm. Absent this framework, discovering and disclosing vulnerabilities may result in a security researcher facing liability under the Criminal Code, as well as potentially the Copyright Act, if exemptions do not apply. Whistleblower legislation in Canada generally would also not apply to vulnerability disclosure except in very limited, specific instances. Further, Canada’s Centre for Cyber Security — and its parent agency the Communications Security Establishment — currently have practices and policies that may discourage people from disclosing vulnerabilities and, on top of this, are also opaque about how such vulnerabilities are handled. The cumulative effect of this approach in Canada means that there is no straightforward or transparent path for a person wishing to responsibly disclose a security vulnerability found in the computer systems used by the Government of Canada — resulting in possible non-disclosure, public disclosure before remediation, or otherwise enabling the use of security vulnerabilities by attackers in ways that could jeopardize the security of Canada’s computer systems and the people that they serve. In light of these findings, we advocate for the following three policy solutions in Canada to remedy these gaps: 1. Canada needs a policy framework for good faith vulnerability discovery and disclosure; 2. Canada should carefully implement coordinated vulnerability disclosure procedures for the federal government’s computer systems, and draw on emerging best practices as it does so; and 3. Vulnerabilities disclosed to the government from external actors should be kept separate from the government’s handling of vulnerabilities uncovered internally in the course of Canada’s defensive and offensive intelligence efforts.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame machine prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.

metaresearch head score (Codex)0.016
metaresearch head score (Gemma)0.047
Version: metacan-v3-hybrid-931329e0061cValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Not applicable · Consensus signal: Not applicable
GenreCandidate signal: Empirical · Consensus signal: Empirical
Teacher disagreement score0.744
Threshold uncertainty score0.863

Distilled classifier scores by category (both heads)

CategoryCodexGemma
Metaresearch0.0160.047
Meta-epidemiology (narrow)0.0000.001
Meta-epidemiology (broad)0.0000.001
Bibliometrics0.0030.006
Science and technology studies0.0340.008
Scholarly communication0.0150.004
Open science0.0050.010
Research integrity0.0050.006
Insufficient payload (model declined to judge)0.0030.000

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.008
GPT teacher head0.227
Teacher spread0.219 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designNot applicable
Domainnot available
GenreEmpirical

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations0
Published2021
Admission routes2
Has abstractyes

Explore more

Same venueSSRN Electronic JournalSame topicCybercrime and Law Enforcement StudiesFrench-language works237,207