KIT | KIT-Bibliothek | Impressum | Datenschutz

“I believe it’s incredibly difficult to fight against this flood of spam”: Towards Enhancing Strategies for Creating Effective Vulnerability Notifications

Hennig, Anne ORCID iD icon 1; Veit, Maxime ORCID iD icon 1; Schmidt-Enke, Leoni 1; Neusser, Fabian ; Herrmann, Dominik ; Mayer, Peter ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)

Abstract:

Identifying the most effective and scalable methods for notifying website owners about compromises or vulnerabilities remains an enduring challenge. Although some success factors have been identified, results regarding effective senders and notification framing are often inconsistent, and the understanding of how recipients perceive vulnerability notifications is still limited. Heading towards a better understanding, we conducted a 3 × 3 randomized controlled notification experiment, examining the impact of three distinct senders and three variations of notification framings for n=581 compromised German websites. Our findings revealed a promising trend: receiving any notification significantly increased remediation compared to the absence of one. Remarkably, the choice of sender and framing played only a minor role in our notification experiment, which underscores the importance of notifying compromised websites and should motivate those who find vulnerabilities to take action. Yet, despite these encouraging results, a staggering 58% of the notified websites failed to remediate. To delve deeper into this phenomenon, we conducted follow-up interviews with 42 website owners who did not remediate their websites. ... mehr


Verlagsausgabe §
DOI: 10.5445/IR/1000185161/pub
Veröffentlicht am 31.10.2025
Preprint §
DOI: 10.5445/IR/1000185161
Veröffentlicht am 26.09.2025
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsmonat/-jahr 01.2026
Sprache Englisch
Identifikator ISSN: 0167-4048, 1872-6208
KITopen-ID: 1000185161
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Computers & security
Verlag Elsevier
Band 160
Seiten Art.-Nr.: 104682
Vorab online veröffentlicht am 21.10.2025
Externe Relationen Abstract/Volltext
Nachgewiesen in Web of Science
Scopus
Dimensions
OpenAlex
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page