Optimal Policies for Security Patch Management
Optimal Policies for Security Patch Management
复制标题
DOI:
10.1287/ijoc.2014.0638
复制
发表时间:
2015-06-01
影响因子:
2.1
通讯作者:
Zhang, Guoying
中科院分区:
文献类型:
--
作者:
Dey, Debabrata;Lahiri, Atanu;Zhang, Guoying
Effective patch management is critical to ensure the security of information systems that modern organizations count on today. Facing numerous patch releases from vendors, an information technology (IT) manager must weigh the costs of frequent patching against the security risks that can arise from delays in patch application. To this end, we develop a rigorous quantitative framework to analyze and compare several patching policies that are of practical interest. Our analyses of pure policies-policies that rely on a single metric such as elapsed time or patch severity level-show that certain policies are never optimal and no single policy may fit all information systems uniformly well. Depending on the context parameters, particularly the setup and business disruption costs for patching, either a time-based approach or an approach based on the cumulative severity level may be effective. To develop a more complete guideline for policy selection, we decipher hybrid policies that combine multiple metrics. Finally, we conduct extensive numerical experiments to verify the robustness of our analytical results. Overall, our paper establishes a comprehensive framework for analyzing various patching policies and furnishes useful insights for IT managers.