Optimal Security Patch Release Timing under Non-homogeneous Vulnerability-Discovery Processes

Optimal Security Patch Release Timing under Non-homogeneous Vulnerability-Discovery Processes
复制标题

非同质漏洞发现过程下的最佳安全补丁发布时机

DOI:
10.1109/issre.2009.19
复制
发表时间:
2009
期刊:
2009 20th International Symposium on Software Reliability Engineering
影响因子:
--
通讯作者:
T. Dohi
T. Dohi
中科院分区:
--
文献类型:
--
作者:
H. Okamura;M. Tokuzane;T. Dohi

文献摘要

被引文献

相似文献

本文提出了一种具有非同构漏洞发现过程的补丁管理模型,用于寻找最优的安全补丁发布时间。该模型是对Cavusoglu等人(2006,2008)的扩展,采用基于漏洞生命周期模型的非同构漏洞发现过程,并通过成本分析提供软件生命周期内安全补丁发布时间的最佳时间表。通过数值算例表明,最优补丁发布策略变成了一种非周期发布策略,并比较了最优补丁发布策略与周期发布策略下的最小成本。此外,基于公开的漏洞数据,给出了一个真实软件产品的最优安全补丁发布策略。
This paper proposes a patch management model with non-homogeneous vulnerability-discovery processes to find the optimal security patch release times. The proposed model is an extension of Cavusoglu et al.\ (2006, 2008) by applying non-homogeneous vulnerability-discovery processes which are based on a vulnerability life-cycle model, and provides the optimal schedule for security patch release times over a software life cycle by means of cost analysis. In numerical examples, we show that the optimal patch release policy becomes an aperiodic release strategy, and compare the minimum cost under the optimal policy with that under a periodic release strategy. In addition, based on opened vulnerability data, we illustrate the optimal security patch release policy for a real software product.