信息安全视角下的软件供应链厂商开发策略选择研究
Research on Vendor Development Strategy Selection of Software Supply Chain from the Perspective of Information Security
摘要: 信息安全已成为软件产品的基础,引起了软件厂商和软件用户的广泛关注。本文以信息安全视角为切入点,研究软件供应链厂商的开发策略选择。通过构建对称信息安全环境下的软件供应链厂商开发策略选择博弈模型,得到了不同情形下的软件厂商的相应开发策略。研究发现:(1) 在两家软件厂商都开发闭源软件时,较高的产品间替代率会使得两家软件厂商的软件产品提高并影响软件厂商信息安全投入水平,影响消费者的需求,并进一步增加他们在竞争市场中的利润。(2) 若开源开发策略的回报较高,即使信息安全问题较为严重,软件厂商仍更有可能选择开源的开发模式。(3) 同构开发模式下闭源软件厂商的利润高于异构开发模式下闭源厂商的利润。
Abstract: Information security has become the foundation of software products, which has attracted the wide attention of software manufacturers and software users. This paper studies the development strategy choice of software supply chain manufacturers from the perspective of information security. By constructing a game model of software supply chain vendor development strategy selection under symmetric information security environment, the corresponding development strategies of software vendors under different situations are obtained. The results show that: (1) When both software vendors develop closed-source software, the higher inter-product substitution rate will improve the software products of the two software vendors, affect the information security investment level of software vendors, affect the demand of consumers, and further increase their profits in the competitive market. (2) If the return of open source development strategy is higher, even if the information security problem is more serious, software manufacturers are more likely to choose open source development mode. (3) The profit of closed-source software vendors in homogeneous development mode is higher than that of closed-source software vendors in heterogeneous development mode.
文章引用:孙丹, 朱逸飞. 信息安全视角下的软件供应链厂商开发策略选择研究[J]. 电子商务评论, 2024, 13(4): 4936-4947. https://doi.org/10.12677/ecl.2024.1341722

参考文献

[1] Bretthauer, D. (2001) Open Source Software in Libraries. Library Hi Tech News, 18. [Google Scholar] [CrossRef
[2] Bandyopadhyay, T., Jacob, V.S. and Raghunathan, S. (2005) Information Security Investment Strategies in Supply Chain Firms: Inter-Play between Breach Propagation, Shared Information Assets and Chain Topology. 11th Americas Conference on Information Systems, AMCIS 2005, Omaha, 11-14 August 2005.
[3] Lakhani, K.R. and von Hippel, E. (2004) How Open Source Software Works: “Free” User-to-User Assistance. In: Herstatt, C. and Sander, J.G., Eds., Produktentwicklung mit virtuellen Communities, Gabler Verlag, 303-339. [Google Scholar] [CrossRef
[4] Economides, N. and Katsamakas, E. (2006) Two-Sided Competition of Proprietary vs. Open Source Technology Platforms and the Implications for the Software Industry. Management Science, 52, 1057-1071. [Google Scholar] [CrossRef
[5] Caulkins, J.P., Feichtinger, G., Grass, D., Hartl, R.F., Kort, P.M. and Seidl, A. (2013) When to Make Proprietary Software Open Source. Journal of Economic Dynamics and Control, 37, 1182-1194. [Google Scholar] [CrossRef
[6] Haruvy, E., Sethi, S.P. and Zhou, J. (2008) Open Source Development with a Commercial Complementary Product or Service. Production and Operations Management, 17, 29-43. [Google Scholar] [CrossRef
[7] August, T., Shin, H. and Tunca, T.I. (2013) Licensing and Competition for Services in Open Source Software. Information Systems Research, 24, 1068-1086. [Google Scholar] [CrossRef
[8] Sen, R., Verma, A. and Heim, G.R. (2020) Impact of Cyberattacks by Malicious Hackers on the Competition in Software Markets. Journal of Management Information Systems, 37, 191-216. [Google Scholar] [CrossRef
[9] Kumar, V., Gordon, B.R. and Srinivasan, K. (2011) Competitive Strategy for Open Source Software. Marketing Science, 30, 1066-1078. [Google Scholar] [CrossRef
[10] Casadesus-Masanell, R. and Ghemawat, P. (2006) Dynamic Mixed Duopoly: A Model Motivated by Linux vs. Windows. Management Science, 52, 1072-1084. [Google Scholar] [CrossRef
[11] Cheng, H.K., Liu, Y. and Tang, Q. (2011) The Impact of Network Externalities on the Competition between Open Source and Proprietary Software. Journal of Management Information Systems, 27, 201-230. [Google Scholar] [CrossRef
[12] Kort, P.M. and Zaccour, G. (2011) When Should a Firm Open Its Source Code: A Strategic Analysis. Production and Operations Management, 20, 877-888. [Google Scholar] [CrossRef
[13] Gal-Or, E. and Ghose, A. (2005) The Economic Incentives for Sharing Security Information. Information Systems Research, 16, 186-208. [Google Scholar] [CrossRef
[14] Gao, X. (2020) Open Source or Closed Source? A Competitive Analysis with Software Security. Decision Analysis, 17, 56-73. [Google Scholar] [CrossRef
[15] Hausken, K. (2006) Returns to Information Security Investment: The Effect of Alternative Information Security Breach Functions on Optimal Investment and Sensitivity to Vulnerability. Information Systems Frontiers, 8, 338-349. [Google Scholar] [CrossRef
[16] Gao, X. and Zhong, W. (2015) Economic Incentives in Security Information Sharing: The Effects of Market Structures. Information Technology and Management, 17, 361-377. [Google Scholar] [CrossRef