{"id":"https://openalex.org/W2040420981","doi":"https://doi.org/10.2753/mis0742-1222280411","title":"Patch Release Behaviors of Software Vendors in Response to Vulnerabilities: An Empirical Analysis","display_name":"Patch Release Behaviors of Software Vendors in Response to Vulnerabilities: An Empirical Analysis","publication_year":2012,"publication_date":"2012-04-01","ids":{"openalex":"https://openalex.org/W2040420981","doi":"https://doi.org/10.2753/mis0742-1222280411","mag":"2040420981"},"language":"en","primary_location":{"id":"doi:10.2753/mis0742-1222280411","is_oa":false,"landing_page_url":"https://doi.org/10.2753/mis0742-1222280411","pdf_url":null,"source":{"id":"https://openalex.org/S9954729","display_name":"Journal of Management Information Systems","issn_l":"0742-1222","issn":["0742-1222","1557-928X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320547","host_organization_name":"Taylor & Francis","host_organization_lineage":["https://openalex.org/P4310320547"],"host_organization_lineage_names":["Taylor & Francis"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Management Information Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5030319229","display_name":"Orcun Temizkan","orcid":null},"institutions":[{"id":"https://openalex.org/I102149020","display_name":"University of North Carolina at Charlotte","ror":"https://ror.org/04dawnj30","country_code":"US","type":"education","lineage":["https://openalex.org/I102149020"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Orcun Temizkan","raw_affiliation_strings":["a Belk College of Business Administration, University of North Carolina-Charlotte","Belk College of Business Administration, University of North Carolina Charlotte"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"a Belk College of Business Administration, University of North Carolina-Charlotte","institution_ids":["https://openalex.org/I102149020"]},{"raw_affiliation_string":"Belk College of Business Administration, University of North Carolina Charlotte","institution_ids":["https://openalex.org/I102149020"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062588428","display_name":"Ram L. Kumar","orcid":"https://orcid.org/0000-0002-6139-3288"},"institutions":[{"id":"https://openalex.org/I102149020","display_name":"University of North Carolina at Charlotte","ror":"https://ror.org/04dawnj30","country_code":"US","type":"education","lineage":["https://openalex.org/I102149020"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ram L. Kumar","raw_affiliation_strings":["a Belk College of Business Administration, University of North Carolina-Charlotte","Belk College of Business Administration, University of North Carolina Charlotte"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"a Belk College of Business Administration, University of North Carolina-Charlotte","institution_ids":["https://openalex.org/I102149020"]},{"raw_affiliation_string":"Belk College of Business Administration, University of North Carolina Charlotte","institution_ids":["https://openalex.org/I102149020"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103104504","display_name":"Sungjune Park","orcid":"https://orcid.org/0000-0001-7482-4553"},"institutions":[{"id":"https://openalex.org/I102149020","display_name":"University of North Carolina at Charlotte","ror":"https://ror.org/04dawnj30","country_code":"US","type":"education","lineage":["https://openalex.org/I102149020"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"SungJune Park","raw_affiliation_strings":["a Belk College of Business Administration, University of North Carolina-Charlotte","Belk College of Business Administration, University of North Carolina Charlotte"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"a Belk College of Business Administration, University of North Carolina-Charlotte","institution_ids":["https://openalex.org/I102149020"]},{"raw_affiliation_string":"Belk College of Business Administration, University of North Carolina Charlotte","institution_ids":["https://openalex.org/I102149020"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5050829570","display_name":"Chandrasekar Subramaniam","orcid":"https://orcid.org/0000-0003-4832-2503"},"institutions":[{"id":"https://openalex.org/I102149020","display_name":"University of North Carolina at Charlotte","ror":"https://ror.org/04dawnj30","country_code":"US","type":"education","lineage":["https://openalex.org/I102149020"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chandrasekar Subramaniam","raw_affiliation_strings":["a Belk College of Business Administration, University of North Carolina-Charlotte","Belk College of Business Administration, University of North Carolina Charlotte"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"a Belk College of Business Administration, University of North Carolina-Charlotte","institution_ids":["https://openalex.org/I102149020"]},{"raw_affiliation_string":"Belk College of Business Administration, University of North Carolina Charlotte","institution_ids":["https://openalex.org/I102149020"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":4.4095,"has_fulltext":false,"cited_by_count":40,"citation_normalized_percentile":{"value":0.94542161,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"28","issue":"4","first_page":"305","last_page":"338"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.994700014591217,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9814000129699707,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/vendor","display_name":"Vendor","score":0.6850036382675171},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6256281733512878},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6213620901107788},{"id":"https://openalex.org/keywords/secure-coding","display_name":"Secure coding","score":0.6031758189201355},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.5266192555427551},{"id":"https://openalex.org/keywords/software-security-assurance","display_name":"Software security assurance","score":0.4676283001899719},{"id":"https://openalex.org/keywords/hacker","display_name":"Hacker","score":0.463666707277298},{"id":"https://openalex.org/keywords/vulnerability-management","display_name":"Vulnerability management","score":0.43773406744003296},{"id":"https://openalex.org/keywords/software-release-life-cycle","display_name":"Software release life cycle","score":0.42644429206848145},{"id":"https://openalex.org/keywords/software-development","display_name":"Software development","score":0.367937833070755},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.3206220865249634},{"id":"https://openalex.org/keywords/software-quality","display_name":"Software quality","score":0.26753073930740356},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2560039162635803},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.24691864848136902},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.17819851636886597},{"id":"https://openalex.org/keywords/vulnerability-assessment","display_name":"Vulnerability assessment","score":0.1377025842666626}],"concepts":[{"id":"https://openalex.org/C2777338717","wikidata":"https://www.wikidata.org/wiki/Q1762621","display_name":"Vendor","level":2,"score":0.6850036382675171},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6256281733512878},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6213620901107788},{"id":"https://openalex.org/C22680326","wikidata":"https://www.wikidata.org/wiki/Q7444867","display_name":"Secure coding","level":5,"score":0.6031758189201355},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.5266192555427551},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.4676283001899719},{"id":"https://openalex.org/C86844869","wikidata":"https://www.wikidata.org/wiki/Q2798820","display_name":"Hacker","level":2,"score":0.463666707277298},{"id":"https://openalex.org/C172776598","wikidata":"https://www.wikidata.org/wiki/Q7943570","display_name":"Vulnerability management","level":4,"score":0.43773406744003296},{"id":"https://openalex.org/C135945739","wikidata":"https://www.wikidata.org/wiki/Q1211457","display_name":"Software release life cycle","level":5,"score":0.42644429206848145},{"id":"https://openalex.org/C529173508","wikidata":"https://www.wikidata.org/wiki/Q638608","display_name":"Software development","level":3,"score":0.367937833070755},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.3206220865249634},{"id":"https://openalex.org/C117447612","wikidata":"https://www.wikidata.org/wiki/Q1412670","display_name":"Software quality","level":4,"score":0.26753073930740356},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2560039162635803},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.24691864848136902},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.17819851636886597},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.1377025842666626},{"id":"https://openalex.org/C542102704","wikidata":"https://www.wikidata.org/wiki/Q183257","display_name":"Psychotherapist","level":1,"score":0.0},{"id":"https://openalex.org/C137176749","wikidata":"https://www.wikidata.org/wiki/Q4105337","display_name":"Psychological resilience","level":2,"score":0.0},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.0},{"id":"https://openalex.org/C162853370","wikidata":"https://www.wikidata.org/wiki/Q39809","display_name":"Marketing","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.2753/mis0742-1222280411","is_oa":false,"landing_page_url":"https://doi.org/10.2753/mis0742-1222280411","pdf_url":null,"source":{"id":"https://openalex.org/S9954729","display_name":"Journal of Management Information Systems","issn_l":"0742-1222","issn":["0742-1222","1557-928X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320547","host_organization_name":"Taylor & Francis","host_organization_lineage":["https://openalex.org/P4310320547"],"host_organization_lineage_names":["Taylor & Francis"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Management Information Systems","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.7799999713897705,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":61,"referenced_works":["https://openalex.org/W169233187","https://openalex.org/W187289906","https://openalex.org/W1482666155","https://openalex.org/W1499324287","https://openalex.org/W1501269936","https://openalex.org/W1505316740","https://openalex.org/W1510316655","https://openalex.org/W1525451939","https://openalex.org/W1571132164","https://openalex.org/W1574051700","https://openalex.org/W1580788756","https://openalex.org/W1583262077","https://openalex.org/W1608919947","https://openalex.org/W1637667347","https://openalex.org/W1978304215","https://openalex.org/W1979820341","https://openalex.org/W1993558273","https://openalex.org/W2003490337","https://openalex.org/W2005755239","https://openalex.org/W2007329840","https://openalex.org/W2007671133","https://openalex.org/W2008706768","https://openalex.org/W2012658469","https://openalex.org/W2018221631","https://openalex.org/W2027792385","https://openalex.org/W2043681863","https://openalex.org/W2044625105","https://openalex.org/W2047603741","https://openalex.org/W2058012887","https://openalex.org/W2058746502","https://openalex.org/W2069396279","https://openalex.org/W2077937403","https://openalex.org/W2085931423","https://openalex.org/W2099656162","https://openalex.org/W2102234277","https://openalex.org/W2108929024","https://openalex.org/W2109914336","https://openalex.org/W2120197657","https://openalex.org/W2121713513","https://openalex.org/W2122383909","https://openalex.org/W2123258673","https://openalex.org/W2123760334","https://openalex.org/W2128614305","https://openalex.org/W2135366128","https://openalex.org/W2136154250","https://openalex.org/W2136557300","https://openalex.org/W2144604715","https://openalex.org/W2145071552","https://openalex.org/W2148273052","https://openalex.org/W2159964852","https://openalex.org/W2162373348","https://openalex.org/W2334123193","https://openalex.org/W2341759796","https://openalex.org/W2521695965","https://openalex.org/W3022734214","https://openalex.org/W3121427625","https://openalex.org/W3123365097","https://openalex.org/W3147894994","https://openalex.org/W3159449094","https://openalex.org/W4242659724","https://openalex.org/W4285719527"],"related_works":["https://openalex.org/W2560421591","https://openalex.org/W2048581125","https://openalex.org/W2499489413","https://openalex.org/W1643546019","https://openalex.org/W3058106096","https://openalex.org/W2406043920","https://openalex.org/W4293696969","https://openalex.org/W2167151567","https://openalex.org/W2415625629","https://openalex.org/W2112063098"],"abstract_inverted_index":{"Software":[0],"vulnerabilities":[1,35,130,143],"have":[2],"become":[3],"a":[4,20,31,41,55],"serious":[5],"concern":[6],"because":[7],"unpatched":[8],"software":[9,23,27,46,85,88,95,124,156,160],"runs":[10],"the":[11,60,90,106,109,119,151],"risk":[12],"of":[13,45,94,108,111,116,123,155,168],"being":[14],"exploited":[15],"by":[16],"hackers.":[17],"There":[18],"is":[19],"need":[21],"for":[22,34],"vendors":[24,96,113,157,185],"to":[25,77,82,200],"make":[26],"patches":[28],"available":[29],"in":[30,36,150,188],"timely":[32],"manner":[33],"their":[37,99],"products.":[38],"We":[39],"develop":[40],"survival":[42],"analysis":[43],"model":[44,75],"vendors'":[47],"patch":[48,91,120,152],"release":[49,92,121,153,163],"behavior":[50,93,122,154,203],"and":[51,70,87,114,166],"test":[52],"it":[53],"using":[54],"data":[56],"set":[57],"compiled":[58],"from":[59],"National":[61],"Vulnerability":[62],"Database,":[63],"United":[64],"States":[65],"Computer":[66],"Emergency":[67],"Readiness":[68],"Team,":[69],"vendor":[71,117,169,202],"Web":[72],"sites.":[73],"This":[74,102],"helps":[76],"understand":[78],"how":[79],"factors":[80],"specific":[81],"vulnerabilities,":[83],"patches,":[84],"vendors,":[86],"affect":[89],"based":[97,158],"on":[98,118,159],"cost":[100],"structure.":[101],"study":[103],"also":[104],"analyzes":[105],"impact":[107,134,138],"presence":[110],"multiple":[112],"type":[115,161,167],"vendors.":[125],"Our":[126,176],"results":[127,177],"indicate":[128],"that":[129,179],"with":[131,144],"high":[132,136,145],"confidentiality":[133],"or":[135],"integrity":[137],"are":[139,174,182],"patched":[140],"faster":[141,187],"than":[142],"availability":[146],"impact.":[147],"Interesting":[148],"differences":[149],"(new":[162],"versus":[164,172],"update)":[165],"(open":[170],"source":[171],"proprietary)":[173],"found.":[175],"illustrate":[178],"when":[180],"there":[181],"legislative":[183],"pressures,":[184],"react":[186],"patching":[189],"vulnerabilities.":[190],"Thus,":[191],"appropriate":[192],"regulations":[193],"can":[194],"be":[195],"an":[196],"important":[197],"policy":[198],"tool":[199],"influence":[201],"toward":[204],"socially":[205],"desirable":[206],"security":[207],"outcomes.":[208]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":4},{"year":2018,"cited_by_count":4},{"year":2017,"cited_by_count":6},{"year":2016,"cited_by_count":5},{"year":2015,"cited_by_count":2},{"year":2014,"cited_by_count":2},{"year":2013,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
