Information security trade-offs and optimal patching policies

Information security trade-offs and optimal patching policies
复制标题

信息安全权衡和最佳补丁策略

DOI:
10.1016/j.ejor.2011.05.050
复制
发表时间:
2012
期刊:
Eur. J. Oper. Res.
影响因子:
--
通讯作者:
Julian M. Williams
Julian M. Williams
中科院分区:
--
文献类型:
--
作者:
C. Ioannidis;D. Pym;Julian M. Williams

文献摘要

被引文献

相似文献

我们开发和模拟一个基本的数学模型的昂贵的部署软件补丁的保密性和可用性之间的权衡存在。该模型结合了系统架构的关键方面,管理人员的喜好,和威胁环境的随机性的表示。使用该模型,我们计算定期和不定期修补的最佳频率,为网络和客户端,为两个示例类型的组织,军事和金融。这些例子的特征在于它们的参数星座。军事组织对成本的敏感度相对较低,倾向于在网络补丁到达时应用它们。应用非常规客户端补丁的成本相对较高,导致这两种类型的组织避免在到达时部署。
We develop and simulate a basic mathematical model of the costly deployment of software patches in the presence of trade-offs between confidentiality and availability. The model incorporates representations of the key aspects of the system architecture, the managers’ preferences, and the stochastic nature of the threat environment. Using the model, we compute the optimal frequencies for regular and irregular patching, for both networks and clients, for two example types of organization, military and financial. Such examples are characterized by their constellations of parameters. Military organizations, being relatively less cost-sensitive, tend to apply network patches upon their arrival. The relatively high cost of applying irregular client patches leads both types of organization to avoid deployment upon arrival.