Security, Availability, and Multiple Information Sources: Exploring Update Behavior of System Administrators

Security, Availability, and Multiple Information Sources: Exploring Update Behavior of System Administrators
复制标题

安全性、可用性和多个信息源:探索系统管理员的更新行为

DOI:
--
复制
发表时间:
2020
期刊:
SOUPS @ USENIX Security Symposium
影响因子:
--
通讯作者:
E. V. Zezschwitz
E. V. Zezschwitz
中科院分区:
--
文献类型:
--
作者:
Christian Tiefenau;Maximilian Häring;Katharina Krombholz;E. V. Zezschwitz

文献摘要

被引文献

相似文献

专家们一致认为,让系统保持最新是一种强大的 安全措施。以前的工作发现,用户有时 明确避免执行及时更新,例如 到对最终用户有负面影响的不良体验 保安。另一个重要的用户群体已经被调查 范围较小:系统管理员,他们负责 用于维护复杂和不同类型的系统环境 可用且安全。 在这篇文章中,我们试图了解管理员在企业环境中关于更新的行为、经验和态度。根据采访的结果 研究中,我们开发了一个在线调查,并量化了常见的 做法和障碍(例如,停机或缺乏信息 关于更新)。研究结果表明,即使是经历了 管理员在更新过程中苦苦挣扎,因为更新的后果有时很难评估。因此, 我们认为,更多可用的监控和更新p
Experts agree that keeping systems up to date is a powerful security measure. Previous work found that users sometimes explicitly refrain from performing timely updates, e.g., due to bad experiences which has a negative impact on end-user security. Another important user group has been investigated less extensively: system administrators, who are responsible for keeping complex and heterogeneous system landscapes available and secure. In this paper, we sought to understand administrators’ behavior, experiences, and attitudes regarding updates in a corporate environment. Based on the results of an interview study, we developed an online survey and quantified common practices and obstacles (e.g., downtime or lack of information about updates). The findings indicate that even experienced administrators struggle with update processes as the consequences of an update are sometimes hard to assess. Therefore, we argue that more usable monitoring and update p