Optimal Policies for Security Patch Management

Optimal Policies for Security Patch Management
复制标题

DOI:
10.1287/ijoc.2014.0638
复制
发表时间:
2015-06-01
影响因子:
2.1
通讯作者:
Zhang, Guoying
Zhang, Guoying
中科院分区:
计算机科学3区
文献类型:
--
作者:
Dey, Debabrata;Lahiri, Atanu;Zhang, Guoying

文献摘要

被引文献

相似文献

有效的补丁程序管理对于确保现代组织当今所依赖的信息系统的安全性至关重要。面对供应商发布的众多补丁,信息技术(IT)经理必须权衡频繁修补的成本与补丁应用延迟可能导致的安全风险。为此,我们开发了一个严格的定量框架,分析和比较几个修补政策,是实际利益。我们的分析纯政策政策依赖于一个单一的指标,如运行时间或补丁的严重程度表明,某些政策从来没有最佳的,没有一个单一的政策可能适合所有的信息系统一致。根据上下文参数,特别是修补的设置和业务中断成本,基于时间的方法或基于累积严重性级别的方法可能有效。为了制定一个更完整的政策选择的指导方针,我们破译混合政策,结合联合收割机多个指标。最后,我们进行了大量的数值实验,以验证我们的分析结果的鲁棒性。总的来说,我们的论文建立了一个全面的框架,分析各种修补策略和实用的见解,IT管理人员。
Effective patch management is critical to ensure the security of information systems that modern organizations count on today. Facing numerous patch releases from vendors, an information technology (IT) manager must weigh the costs of frequent patching against the security risks that can arise from delays in patch application. To this end, we develop a rigorous quantitative framework to analyze and compare several patching policies that are of practical interest. Our analyses of pure policies-policies that rely on a single metric such as elapsed time or patch severity level-show that certain policies are never optimal and no single policy may fit all information systems uniformly well. Depending on the context parameters, particularly the setup and business disruption costs for patching, either a time-based approach or an approach based on the cumulative severity level may be effective. To develop a more complete guideline for policy selection, we decipher hybrid policies that combine multiple metrics. Finally, we conduct extensive numerical experiments to verify the robustness of our analytical results. Overall, our paper establishes a comprehensive framework for analyzing various patching policies and furnishes useful insights for IT managers.