Behind the Curtain: How Shared Hosting Providers Respond to Vulnerability Notifications
Giada Stivala, Rafael Mrowczynski, Maria Hellenthal, Giancarlo Pellegrino

TL;DR
This study investigates how hosting providers process vulnerability notifications, revealing organizational factors and operational challenges that contribute to low remediation rates, with insights from interviews across diverse providers.
Contribution
First detailed analysis of internal processes and organizational influences affecting vulnerability notification effectiveness in hosting providers.
Findings
Most providers handle VNs routinely but face reachability issues.
Strict responsibility boundaries limit remediation efforts.
High volume of compromises and low fees discourage proactive security measures.
Abstract
Large-scale vulnerability notifications (VNs) can help hosting provider organizations (HPOs) identify and remediate security vulnerabilities that attackers can exploit in data breaches or phishing campaigns. Previous VN studies have primarily focused on factors under the control of reporters, such as sender reputation, email formatting, and communication channels. Despite these efforts, remediation rates for vulnerability notifications continue to remain consistently low. This paper presents the first in-depth study of how HPOs process vulnerability notifications internally and what organizational and operational factors influence VN effectiveness. We examine the problem from a different perspective to provide the first detailed understanding of the reasons behind persistently low remediation rates. Instead of manipulating parameters of VN campaigns, we interview hosting providers…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsWeb Application Security Vulnerabilities · Information and Cyber Security · Spam and Phishing Detection
