Software Development |
Integration and Application Infrastructure |
Integrating Data and Content |
Collaboration and Human Interaction |
Intelligent Management |
|||
Business Service Management Orchestration Provisioning Security Storage Go to official IBM Tivoli site About TivoliTivoli Framework is a systems management platform from IBM (previously Tivoli Systems, acquired by IBM in 1995 and moved into IBM's Software Group division).Managing heterogeneous distributed computer systems is a complex task that can involve various operating systems, distributed network services, and system management tasks. Tivoli Management Framework, and the products that can be installed on top of it, simplify the management of distributed systems. Automation packages for IBM Tivoli Orchestrator - IBM orchestration and provisioning solutions address the challenges faced with manual processes and substandard resource utilization. IBM IT service management workflows leverage best practices to automate orchestration and provisioning so you can decrease costs and improve resource utilization and response time. The IBM orchestration and provisioning solution includes pre-built workflows and provides tools for customers to easily incorporate their own best practices into the IBM solution. Using automated workflows can provide substantial cost savings — reducing days of manual processes down to hours of automated execution. Market for Software Vulnerabilities? Think AgainBy KARTHIK NATARAJAN KANNAN - Purdue University, RAHUL TELANG - Carnegie Mellon University - H. John Heinz III School of Public Policy and Management and HAO XU - Carnegie Mellon University - School of Computer Science. Software vulnerabilities and the lack of information security have been receiving a lot of media attention lately as attacks exploiting vulnerabilities cause significant economic damages. Since new software vulnerabilities are emerging everyday, disclosing information about them is a critical area of concern for policy makers. Traditionally, Computer Emergency Response Team (CERT) has been acting as an infomediary between benign identifiers (who report vulnerability information voluntarily) and users of the software. After verifying a reported vulnerability, and obtaining the remediation in the form of a patch from the software vendor, the infomediary - CERT - sends out a public advisory to inform software users about it. Of late, firms such as iDefense have been proposing a different market-based mechanism where the infomediary provides monetary rewards to identifiers for each vulnerability disclosed to it. The infomediary then shares this information with its client base. Using this information, clients can protect themselves against attacks that exploit those specific vulnerabilities. The key question addressed in our paper is whether movement towards such a market-based mechanism for vulnerability disclosure leads to a better social outcome. Generally, an active market-based mechanism is expected to perform better than a passive CERT type mechanism. Surprisingly, we find that a market mechanism underperforms when benign users voluntarily provide vulnerability information. More importantly, we find that monopolist always has an incentive to misuse the vulnerability information such that it almost always reduces the social welfare. We extend our analysis and provide a new meachnism named Federally-Funded Social Planner that always performs better. | |||||||