论文标题

安全性,可用性和多个信息来源:探索系统管理员的更新行为

Security, Availability, and Multiple Information Sources: Exploring Update Behavior of System Administrators

论文作者

Tiefenau, Christian, Häring, Maximilian, Krombholz, Katharina, von Zezschwitz, Emanuel

论文摘要

专家认为,保持系统最新是一项有力的安全措施。先前的工作发现,用户有时明确避免执行及时更新,例如,由于经验不佳,这对最终用户安全性产生了负面影响。对另一个重要的用户组进行了不太广泛的研究:系统管理员,他们负责保持复杂和异质的系统风景可用和安全。 在本文中,我们试图了解管理人员对公司环境中更新的行为,经验和态度。根据访谈研究的结果,我们开发了一项在线调查,并量化了常见实践和障碍(例如,停机时间或缺乏有关更新的信息)。调查结果表明,即使经验丰富的管理员也很难评估更新的后果。因此,我们认为,更可用的监视和更新过程对于确保其规模安全至关重要。

Experts agree that keeping systems up to date is a powerful security measure. Previous work found that users sometimes explicitly refrain from performing timely updates, e.g., due to bad experiences which has a negative impact on end-user security. Another important user group has been investigated less extensively: system administrators, who are responsible for keeping complex and heterogeneous system landscapes available and secure. In this paper, we sought to understand administrators' behavior, experiences, and attitudes regarding updates in a corporate environment. Based on the results of an interview study, we developed an online survey and quantified common practices and obstacles (e.g., downtime or lack of information about updates). The findings indicate that even experienced administrators struggle with update processes as the consequences of an update are sometimes hard to assess. Therefore, we argue that more usable monitoring and update processes are essential to guarantee IT security at scale.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源